File: //usr/local/apache/domlogs/sbf-consultancy.com.error.log
[Sat Jul 25 16:24:52.653582 2026] [:error] [pid 1287:tid 140169210459904] [client 20.203.209.227:47673] [client 20.203.209.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amTHNAAinyFWeA3f0rZ-tAAABE8"]
[Sat Jul 25 16:24:52.679245 2026] [:error] [pid 1287:tid 140169210459904] [client 20.203.209.227:47673] [client 20.203.209.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amTHNAAinyFWeA3f0rZ-tAAABE8"]
[Sat Jul 25 16:24:52.679540 2026] [:error] [pid 1287:tid 140169210459904] [client 20.203.209.227:47673] [client 20.203.209.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amTHNAAinyFWeA3f0rZ-tAAABE8"]
[Sat Jul 25 16:37:28.592267 2026] [:error] [pid 1506:tid 140169407416064] [client 3.217.141.132:60859] [client 3.217.141.132] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTKKC3IyKke5GRSFVrBuQAABUA"]
[Sat Jul 25 16:37:28.595626 2026] [:error] [pid 1506:tid 140169407416064] [client 3.217.141.132:60859] [client 3.217.141.132] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTKKC3IyKke5GRSFVrBuQAABUA"]
[Sat Jul 25 16:59:04.936870 2026] [:error] [pid 1481:tid 140169151710976] [client 162.141.167.36:42592] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTPOI5TdhIOmiRS1p3fcwAABRY"]
[Sat Jul 25 16:59:04.937937 2026] [:error] [pid 1481:tid 140169151710976] [client 162.141.167.36:42592] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTPOI5TdhIOmiRS1p3fcwAABRY"]
[Sat Jul 25 16:59:06.223389 2026] [:error] [pid 1506:tid 140169277601536] [client 162.141.167.36:42660] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTPOi3IyKke5GRSFVrQ4gAABUc"]
[Sat Jul 25 16:59:06.224074 2026] [:error] [pid 1506:tid 140169277601536] [client 162.141.167.36:42660] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTPOi3IyKke5GRSFVrQ4gAABUc"]
[Sat Jul 25 16:59:07.547579 2026] [:error] [pid 1506:tid 140169399023360] [client 162.141.167.36:42660] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTPOy3IyKke5GRSFVrQ5QAABUE"]
[Sat Jul 25 16:59:07.548837 2026] [:error] [pid 1506:tid 140169399023360] [client 162.141.167.36:42660] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTPOy3IyKke5GRSFVrQ5QAABUE"]
[Sat Jul 25 16:59:08.048431 2026] [:error] [pid 1506:tid 140169373845248] [client 162.141.167.36:42660] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amTPPC3IyKke5GRSFVrQ5gAABUQ"]
[Sat Jul 25 16:59:08.049540 2026] [:error] [pid 1506:tid 140169373845248] [client 162.141.167.36:42660] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amTPPC3IyKke5GRSFVrQ5gAABUQ"]
[Sat Jul 25 16:59:08.050103 2026] [:error] [pid 1506:tid 140169373845248] [client 162.141.167.36:42660] [client 162.141.167.36] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amTPPC3IyKke5GRSFVrQ5gAABUQ"]
[Sat Jul 25 16:59:08.754902 2026] [:error] [pid 1506:tid 140169390630656] [client 162.141.167.36:42660] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/assets/index-o-9Bhaif.js"] [unique_id "amTPPC3IyKke5GRSFVrQ6AAABUI"]
[Sat Jul 25 16:59:08.755979 2026] [:error] [pid 1506:tid 140169390630656] [client 162.141.167.36:42660] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/assets/index-o-9Bhaif.js"] [unique_id "amTPPC3IyKke5GRSFVrQ6AAABUI"]
[Sat Jul 25 16:59:09.291002 2026] [:error] [pid 1506:tid 140169235638016] [client 162.141.167.36:59828] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amTPPS3IyKke5GRSFVrQ6QAABUw"]
[Sat Jul 25 16:59:09.292184 2026] [:error] [pid 1506:tid 140169235638016] [client 162.141.167.36:59828] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amTPPS3IyKke5GRSFVrQ6QAABUw"]
[Sat Jul 25 16:59:09.407056 2026] [:error] [pid 1506:tid 140169193674496] [client 162.141.167.36:59828] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amTPPS3IyKke5GRSFVrQ6wAABVE"]
[Sat Jul 25 16:59:09.408123 2026] [:error] [pid 1506:tid 140169193674496] [client 162.141.167.36:59828] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amTPPS3IyKke5GRSFVrQ6wAABVE"]
[Sat Jul 25 16:59:09.408724 2026] [:error] [pid 1506:tid 140169193674496] [client 162.141.167.36:59828] [client 162.141.167.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amTPPS3IyKke5GRSFVrQ6wAABVE"]
[Sat Jul 25 16:59:09.537778 2026] [:error] [pid 1506:tid 140169218852608] [client 162.141.167.36:59828] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env"] [unique_id "amTPPS3IyKke5GRSFVrQ7AAABU4"]
[Sat Jul 25 16:59:09.538719 2026] [:error] [pid 1506:tid 140169218852608] [client 162.141.167.36:59828] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env"] [unique_id "amTPPS3IyKke5GRSFVrQ7AAABU4"]
[Sat Jul 25 16:59:09.579767 2026] [:error] [pid 1506:tid 140169382237952] [client 162.141.167.36:59758] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amTPPS3IyKke5GRSFVrQ7QAABUM"]
[Sat Jul 25 16:59:09.580659 2026] [:error] [pid 1506:tid 140169382237952] [client 162.141.167.36:59758] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amTPPS3IyKke5GRSFVrQ7QAABUM"]
[Sat Jul 25 16:59:09.581132 2026] [:error] [pid 1506:tid 140169382237952] [client 162.141.167.36:59758] [client 162.141.167.36] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amTPPS3IyKke5GRSFVrQ7QAABUM"]
[Sat Jul 25 16:59:09.685844 2026] [:error] [pid 1506:tid 140169252423424] [client 162.141.167.36:59832] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/js/config.js"] [unique_id "amTPPS3IyKke5GRSFVrQ7gAABUo"]
[Sat Jul 25 16:59:09.685843 2026] [:error] [pid 1287:tid 140169382237952] [client 162.141.167.36:59794] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amTPPQAinyFWeA3f0raDeAAABEM"]
[Sat Jul 25 16:59:09.686458 2026] [:error] [pid 1481:tid 140169134925568] [client 162.141.167.36:59814] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amTPPY5TdhIOmiRS1p3feQAABRg"]
[Sat Jul 25 16:59:09.686520 2026] [:error] [pid 1506:tid 140169252423424] [client 162.141.167.36:59832] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/js/config.js"] [unique_id "amTPPS3IyKke5GRSFVrQ7gAABUo"]
[Sat Jul 25 16:59:09.686526 2026] [:error] [pid 1287:tid 140169382237952] [client 162.141.167.36:59794] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amTPPQAinyFWeA3f0raDeAAABEM"]
[Sat Jul 25 16:59:09.686661 2026] [:error] [pid 1481:tid 140169202067200] [client 162.141.167.36:59792] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amTPPY5TdhIOmiRS1p3feAAABRA"]
[Sat Jul 25 16:59:09.686728 2026] [:error] [pid 1481:tid 140169244030720] [client 162.141.167.36:59768] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amTPPY5TdhIOmiRS1p3fegAABQs"]
[Sat Jul 25 16:59:09.686962 2026] [:error] [pid 1287:tid 140169382237952] [client 162.141.167.36:59794] [client 162.141.167.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amTPPQAinyFWeA3f0raDeAAABEM"]
[Sat Jul 25 16:59:09.687578 2026] [:error] [pid 1481:tid 140169134925568] [client 162.141.167.36:59814] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amTPPY5TdhIOmiRS1p3feQAABRg"]
[Sat Jul 25 16:59:09.687808 2026] [:error] [pid 1481:tid 140169202067200] [client 162.141.167.36:59792] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amTPPY5TdhIOmiRS1p3feAAABRA"]
[Sat Jul 25 16:59:09.687831 2026] [:error] [pid 1481:tid 140169244030720] [client 162.141.167.36:59768] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amTPPY5TdhIOmiRS1p3fegAABQs"]
[Sat Jul 25 16:59:09.688142 2026] [:error] [pid 1481:tid 140169134925568] [client 162.141.167.36:59814] [client 162.141.167.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amTPPY5TdhIOmiRS1p3feQAABRg"]
[Sat Jul 25 16:59:09.688280 2026] [:error] [pid 1481:tid 140169244030720] [client 162.141.167.36:59768] [client 162.141.167.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amTPPY5TdhIOmiRS1p3fegAABQs"]
[Sat Jul 25 16:59:09.688280 2026] [:error] [pid 1481:tid 140169202067200] [client 162.141.167.36:59792] [client 162.141.167.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amTPPY5TdhIOmiRS1p3feAAABRA"]
[Sat Jul 25 16:59:09.690148 2026] [:error] [pid 1506:tid 140169269208832] [client 162.141.167.36:59828] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amTPPS3IyKke5GRSFVrQ7wAABUg"]
[Sat Jul 25 16:59:09.690835 2026] [:error] [pid 1506:tid 140169269208832] [client 162.141.167.36:59828] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amTPPS3IyKke5GRSFVrQ7wAABUg"]
[Sat Jul 25 16:59:09.691233 2026] [:error] [pid 1506:tid 140169269208832] [client 162.141.167.36:59828] [client 162.141.167.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amTPPS3IyKke5GRSFVrQ7wAABUg"]
[Sat Jul 25 16:59:09.731364 2026] [:error] [pid 1481:tid 140169269208832] [client 162.141.167.36:59796] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amTPPY5TdhIOmiRS1p3fewAABQg"]
[Sat Jul 25 16:59:09.732534 2026] [:error] [pid 1481:tid 140169269208832] [client 162.141.167.36:59796] [client 162.141.167.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amTPPY5TdhIOmiRS1p3fewAABQg"]
[Sat Jul 25 16:59:09.733147 2026] [:error] [pid 1481:tid 140169269208832] [client 162.141.167.36:59796] [client 162.141.167.36] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amTPPY5TdhIOmiRS1p3fewAABQg"]
[Sat Jul 25 17:04:36.682095 2026] [:error] [pid 1286:tid 140169382237952] [client 100.59.10.31:48708] [client 100.59.10.31] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTQhFd8qdADrnpCrgTWSgAABAM"]
[Sat Jul 25 17:04:36.682761 2026] [:error] [pid 1286:tid 140169382237952] [client 100.59.10.31:48708] [client 100.59.10.31] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTQhFd8qdADrnpCrgTWSgAABAM"]
[Sat Jul 25 17:04:36.871626 2026] [:error] [pid 1481:tid 140169365452544] [client 100.59.10.31:36878] [client 100.59.10.31] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTQhI5TdhIOmiRS1p3hhAAABQU"]
[Sat Jul 25 17:04:36.872381 2026] [:error] [pid 1481:tid 140169365452544] [client 100.59.10.31:36878] [client 100.59.10.31] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTQhI5TdhIOmiRS1p3hhAAABQU"]
[Sat Jul 25 17:10:06.974838 2026] [:error] [pid 1506:tid 140169365452544] [client 44.222.221.139:55246] [client 44.222.221.139] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTRzi3IyKke5GRSFVrY2QAABUU"]
[Sat Jul 25 17:10:06.975516 2026] [:error] [pid 1506:tid 140169365452544] [client 44.222.221.139:55246] [client 44.222.221.139] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTRzi3IyKke5GRSFVrY2QAABUU"]
[Sat Jul 25 17:13:58.744376 2026] [:error] [pid 1506:tid 140169143318272] [client 20.168.95.16:62621] [client 20.168.95.16] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amTSti3IyKke5GRSFVrcDwAABVc"]
[Sat Jul 25 17:13:58.745534 2026] [:error] [pid 1506:tid 140169143318272] [client 20.168.95.16:62621] [client 20.168.95.16] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amTSti3IyKke5GRSFVrcDwAABVc"]
[Sat Jul 25 17:48:59.707602 2026] [:error] [pid 1288:tid 140169185281792] [client 45.148.10.244:13378] [client 45.148.10.244] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amTa67ku2ZzMUQZOdoRaFgAABJI"]
[Sat Jul 25 17:48:59.711316 2026] [:error] [pid 1288:tid 140169185281792] [client 45.148.10.244:13378] [client 45.148.10.244] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amTa67ku2ZzMUQZOdoRaFgAABJI"]
[Sat Jul 25 17:49:11.663810 2026] [:error] [pid 1288:tid 140169407416064] [client 45.148.10.244:36912] [client 45.148.10.244] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amTa97ku2ZzMUQZOdoRaIAAABIA"]
[Sat Jul 25 17:49:11.664779 2026] [:error] [pid 1288:tid 140169407416064] [client 45.148.10.244:36912] [client 45.148.10.244] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amTa97ku2ZzMUQZOdoRaIAAABIA"]
[Sat Jul 25 17:57:13.208995 2026] [:error] [pid 1506:tid 140169390630656] [client 104.23.221.24:13829] [client 104.23.221.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amTc2S3IyKke5GRSFVr-YwAABUI"]
[Sat Jul 25 17:57:13.210072 2026] [:error] [pid 1506:tid 140169390630656] [client 104.23.221.24:13829] [client 104.23.221.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amTc2S3IyKke5GRSFVr-YwAABUI"]
[Sat Jul 25 17:57:13.210627 2026] [:error] [pid 1506:tid 140169390630656] [client 104.23.221.24:13829] [client 104.23.221.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amTc2S3IyKke5GRSFVr-YwAABUI"]
[Sat Jul 25 18:04:42.558111 2026] [:error] [pid 1506:tid 140169407416064] [client 129.28.84.30:36748] [client 129.28.84.30] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTemi3IyKke5GRSFVoEuQAABUA"]
[Sat Jul 25 18:04:42.559161 2026] [:error] [pid 1506:tid 140169407416064] [client 129.28.84.30:36748] [client 129.28.84.30] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTemi3IyKke5GRSFVoEuQAABUA"]
[Sat Jul 25 18:04:42.559378 2026] [:error] [pid 1506:tid 140169407416064] [client 129.28.84.30:36748] [client 129.28.84.30] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTemi3IyKke5GRSFVoEuQAABUA"]
[Sat Jul 25 18:14:34.877888 2026] [:error] [pid 1481:tid 140169151710976] [client 45.148.10.120:57538] [client 45.148.10.120] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amTg6o5TdhIOmiRS1p0UBQAABRY"]
[Sat Jul 25 18:14:34.878929 2026] [:error] [pid 1481:tid 140169151710976] [client 45.148.10.120:57538] [client 45.148.10.120] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amTg6o5TdhIOmiRS1p0UBQAABRY"]
[Sat Jul 25 18:14:34.879494 2026] [:error] [pid 1481:tid 140169151710976] [client 45.148.10.120:57538] [client 45.148.10.120] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amTg6o5TdhIOmiRS1p0UBQAABRY"]
[Sat Jul 25 18:14:34.928299 2026] [:error] [pid 1506:tid 140169143318272] [client 45.148.10.120:57552] [client 45.148.10.120] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aws.env"] [unique_id "amTg6i3IyKke5GRSFVoMrQAABVc"]
[Sat Jul 25 18:14:34.929284 2026] [:error] [pid 1506:tid 140169143318272] [client 45.148.10.120:57552] [client 45.148.10.120] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aws.env"] [unique_id "amTg6i3IyKke5GRSFVoMrQAABVc"]
[Sat Jul 25 18:14:34.973679 2026] [:error] [pid 1506:tid 140169365452544] [client 45.148.10.120:57554] [client 45.148.10.120] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amTg6i3IyKke5GRSFVoMrgAABUU"]
[Sat Jul 25 18:14:34.974351 2026] [:error] [pid 1506:tid 140169365452544] [client 45.148.10.120:57554] [client 45.148.10.120] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amTg6i3IyKke5GRSFVoMrgAABUU"]
[Sat Jul 25 18:14:34.974808 2026] [:error] [pid 1506:tid 140169365452544] [client 45.148.10.120:57554] [client 45.148.10.120] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amTg6i3IyKke5GRSFVoMrgAABUU"]
[Sat Jul 25 18:14:34.981605 2026] [:error] [pid 1288:tid 140169210459904] [client 45.148.10.120:57570] [client 45.148.10.120] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amTg6rku2ZzMUQZOdoRjygAABI8"]
[Sat Jul 25 18:14:34.982251 2026] [:error] [pid 1288:tid 140169210459904] [client 45.148.10.120:57570] [client 45.148.10.120] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amTg6rku2ZzMUQZOdoRjygAABI8"]
[Sat Jul 25 18:14:34.982722 2026] [:error] [pid 1288:tid 140169210459904] [client 45.148.10.120:57570] [client 45.148.10.120] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amTg6rku2ZzMUQZOdoRjygAABI8"]
[Sat Jul 25 18:14:54.114523 2026] [:error] [pid 1481:tid 140169365452544] [client 49.51.38.193:38674] [client 49.51.38.193] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTg_o5TdhIOmiRS1p0UPwAABQU"]
[Sat Jul 25 18:14:54.115437 2026] [:error] [pid 1481:tid 140169365452544] [client 49.51.38.193:38674] [client 49.51.38.193] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTg_o5TdhIOmiRS1p0UPwAABQU"]
[Sat Jul 25 18:14:54.115703 2026] [:error] [pid 1481:tid 140169365452544] [client 49.51.38.193:38674] [client 49.51.38.193] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTg_o5TdhIOmiRS1p0UPwAABQU"]
[Sat Jul 25 18:19:53.398351 2026] [:error] [pid 1288:tid 140169143318272] [client 192.36.109.123:38407] [client 192.36.109.123] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTiKbku2ZzMUQZOdoRlrwAABJc"]
[Sat Jul 25 18:19:53.399413 2026] [:error] [pid 1288:tid 140169143318272] [client 192.36.109.123:38407] [client 192.36.109.123] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTiKbku2ZzMUQZOdoRlrwAABJc"]
[Sat Jul 25 18:29:26.230226 2026] [:error] [pid 1481:tid 140169382237952] [client 44.222.221.139:57591] [client 44.222.221.139] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTkZo5TdhIOmiRS1p0d6AAABQM"]
[Sat Jul 25 18:29:26.231138 2026] [:error] [pid 1481:tid 140169382237952] [client 44.222.221.139:57591] [client 44.222.221.139] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTkZo5TdhIOmiRS1p0d6AAABQM"]
[Sat Jul 25 19:06:10.038281 2026] [:error] [pid 1506:tid 140169390630656] [client 43.134.68.29:41002] [client 43.134.68.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amTtAi3IyKke5GRSFVoyaAAABUI"]
[Sat Jul 25 19:06:10.041148 2026] [:error] [pid 1506:tid 140169390630656] [client 43.134.68.29:41002] [client 43.134.68.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amTtAi3IyKke5GRSFVoyaAAABUI"]
[Sat Jul 25 19:06:10.041350 2026] [:error] [pid 1506:tid 140169390630656] [client 43.134.68.29:41002] [client 43.134.68.29] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amTtAi3IyKke5GRSFVoyaAAABUI"]
[Sat Jul 25 19:21:40.374240 2026] [:error] [pid 1287:tid 140169269208832] [client 136.113.9.105:59468] [client 136.113.9.105] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTwpAAinyFWeA3f0raPYQAABEg"]
[Sat Jul 25 19:21:40.375363 2026] [:error] [pid 1287:tid 140169269208832] [client 136.113.9.105:59468] [client 136.113.9.105] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTwpAAinyFWeA3f0raPYQAABEg"]
[Sat Jul 25 19:21:40.376055 2026] [:error] [pid 1287:tid 140169269208832] [client 136.113.9.105:59468] [client 136.113.9.105] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amTwpAAinyFWeA3f0raPYQAABEg"]
[Sat Jul 25 19:40:45.892487 2026] [:error] [pid 1288:tid 140169390630656] [client 87.106.75.222:50494] [client 87.106.75.222] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amT1Hbku2ZzMUQZOdoSNJwAABII"], referer: https://sbf-consultancy.com/
[Sat Jul 25 19:40:45.896493 2026] [:error] [pid 1288:tid 140169390630656] [client 87.106.75.222:50494] [client 87.106.75.222] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amT1Hbku2ZzMUQZOdoSNJwAABII"], referer: https://sbf-consultancy.com/
[Sat Jul 25 19:44:09.475992 2026] [:error] [pid 22325:tid 140169365452544] [client 172.69.151.107:12136] [client 172.69.151.107] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amT16b960d_6k2gdW-7b9QAAAMU"]
[Sat Jul 25 19:44:09.476886 2026] [:error] [pid 22325:tid 140169365452544] [client 172.69.151.107:12136] [client 172.69.151.107] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amT16b960d_6k2gdW-7b9QAAAMU"]
[Sat Jul 25 19:44:09.477511 2026] [:error] [pid 22325:tid 140169365452544] [client 172.69.151.107:12136] [client 172.69.151.107] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amT16b960d_6k2gdW-7b9QAAAMU"]
[Sat Jul 25 19:46:38.755206 2026] [:error] [pid 22226:tid 140169269208832] [client 54.157.149.144:43848] [client 54.157.149.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amT2fh5FX32vfHTp22IPLgAABQg"]
[Sat Jul 25 19:46:38.756101 2026] [:error] [pid 22226:tid 140169269208832] [client 54.157.149.144:43848] [client 54.157.149.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amT2fh5FX32vfHTp22IPLgAABQg"]
[Sat Jul 25 20:36:19.953035 2026] [:error] [pid 25582:tid 140169227245312] [client 185.149.26.183:57901] [client 185.149.26.183] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amUCI4lHCSx-vTXrLC8-dwAAAA0"]
[Sat Jul 25 20:36:19.959919 2026] [:error] [pid 25582:tid 140169227245312] [client 185.149.26.183:57901] [client 185.149.26.183] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amUCI4lHCSx-vTXrLC8-dwAAAA0"]
[Sat Jul 25 20:36:19.961183 2026] [:error] [pid 25582:tid 140169227245312] [client 185.149.26.183:57901] [client 185.149.26.183] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amUCI4lHCSx-vTXrLC8-dwAAAA0"]
[Sat Jul 25 21:35:26.408224 2026] [:error] [pid 25582:tid 140169244030720] [client 104.23.223.54:9944] [client 104.23.223.54] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amUP_olHCSx-vTXrLC9pBQAAAAs"]
[Sat Jul 25 21:35:26.412340 2026] [:error] [pid 25582:tid 140169244030720] [client 104.23.223.54:9944] [client 104.23.223.54] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amUP_olHCSx-vTXrLC9pBQAAAAs"]
[Sat Jul 25 21:35:26.413035 2026] [:error] [pid 25582:tid 140169244030720] [client 104.23.223.54:9944] [client 104.23.223.54] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amUP_olHCSx-vTXrLC9pBQAAAAs"]
[Sat Jul 25 22:08:10.285349 2026] [:error] [pid 10800:tid 140169390630656] [client 195.178.110.199:37430] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/*/[id]"] [unique_id "amUXqkQR0Lne3b5h1H2RpwAAAEI"]
[Sat Jul 25 22:08:10.285373 2026] [:error] [pid 22225:tid 140169176889088] [client 195.178.110.199:37460] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/%2fbackend%2f%2eenv"] [unique_id "amUXqiPSIfqBZpXN_94dpAAABNM"]
[Sat Jul 25 22:08:10.286098 2026] [:error] [pid 10800:tid 140169390630656] [client 195.178.110.199:37430] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/*/[id]"] [unique_id "amUXqkQR0Lne3b5h1H2RpwAAAEI"]
[Sat Jul 25 22:08:10.315736 2026] [:error] [pid 25582:tid 140169160103680] [client 195.178.110.199:37466] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/..%5c..%5c..%5c..%5c..%5c..%5cvar/log/apache2/access.log"] [unique_id "amUXqolHCSx-vTXrLC-BbQAAABU"]
[Sat Jul 25 22:08:10.316733 2026] [:error] [pid 25582:tid 140169160103680] [client 195.178.110.199:37466] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\var/log/apache2/access.log"] [unique_id "amUXqolHCSx-vTXrLC-BbQAAABU"]
[Sat Jul 25 22:08:10.317216 2026] [:error] [pid 25582:tid 140169160103680] [client 195.178.110.199:37466] [client 195.178.110.199] ModSecurity: Warning. Pattern match "(?i)(?:\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "47"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /..%5c found within REQUEST_URI_RAW: /..%5c..%5c..%5c..%5c..%5c..%5cvar/log/apache2/access.log"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "sbf-consultancy.com"] [uri "/..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\var/log/apache2/access.log"] [unique_id "amUXqolHCSx-vTXrLC-BbQAAABU"]
[Sat Jul 25 22:08:10.345914 2026] [:error] [pid 22325:tid 140169277601536] [client 195.178.110.199:37436] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.aws/config"] [unique_id "amUXqr960d_6k2gdW-4mBgAAAMc"]
[Sat Jul 25 22:08:10.346679 2026] [:error] [pid 22325:tid 140169277601536] [client 195.178.110.199:37436] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.aws/config"] [unique_id "amUXqr960d_6k2gdW-4mBgAAAMc"]
[Sat Jul 25 22:08:10.347000 2026] [:error] [pid 22325:tid 140169277601536] [client 195.178.110.199:37436] [client 195.178.110.199] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.aws/config"] [unique_id "amUXqr960d_6k2gdW-4mBgAAAMc"]
[Sat Jul 25 22:08:11.085568 2026] [:error] [pid 22325:tid 140169365452544] [client 195.178.110.199:37522] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/%2f%2eaws%2fcredentials"] [unique_id "amUXq7960d_6k2gdW-4mCAAAAMU"]
[Sat Jul 25 22:08:11.088751 2026] [:error] [pid 22225:tid 140169373845248] [client 195.178.110.199:37460] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.boto"] [unique_id "amUXqyPSIfqBZpXN_94dpQAABMQ"]
[Sat Jul 25 22:08:11.089496 2026] [:error] [pid 22225:tid 140169373845248] [client 195.178.110.199:37460] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.boto"] [unique_id "amUXqyPSIfqBZpXN_94dpQAABMQ"]
[Sat Jul 25 22:08:11.089903 2026] [:error] [pid 22225:tid 140169373845248] [client 195.178.110.199:37460] [client 195.178.110.199] ModSecurity: Warning. Matched phrase ".boto" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .boto found within REQUEST_FILENAME: /.boto"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.boto"] [unique_id "amUXqyPSIfqBZpXN_94dpQAABMQ"]
[Sat Jul 25 22:08:11.089957 2026] [:error] [pid 10800:tid 140169185281792] [client 195.178.110.199:37430] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/%2egit/%63onfig"] [unique_id "amUXq0QR0Lne3b5h1H2RqQAAAFI"]
[Sat Jul 25 22:08:11.090652 2026] [:error] [pid 10800:tid 140169185281792] [client 195.178.110.199:37430] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amUXq0QR0Lne3b5h1H2RqQAAAFI"]
[Sat Jul 25 22:08:11.091051 2026] [:error] [pid 10800:tid 140169185281792] [client 195.178.110.199:37430] [client 195.178.110.199] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amUXq0QR0Lne3b5h1H2RqQAAAFI"]
[Sat Jul 25 22:08:11.151440 2026] [:error] [pid 25582:tid 140169252423424] [client 195.178.110.199:37466] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/%2eenv"] [unique_id "amUXq4lHCSx-vTXrLC-BbwAAAAo"]
[Sat Jul 25 22:08:11.152087 2026] [:error] [pid 25582:tid 140169252423424] [client 195.178.110.199:37466] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amUXq4lHCSx-vTXrLC-BbwAAAAo"]
[Sat Jul 25 22:08:11.152515 2026] [:error] [pid 25582:tid 140169252423424] [client 195.178.110.199:37466] [client 195.178.110.199] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amUXq4lHCSx-vTXrLC-BbwAAAAo"]
[Sat Jul 25 22:08:11.256171 2026] [:error] [pid 22325:tid 140169168496384] [client 195.178.110.199:37436] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amUXq7960d_6k2gdW-4mCQAAANQ"]
[Sat Jul 25 22:08:11.257204 2026] [:error] [pid 22325:tid 140169168496384] [client 195.178.110.199:37436] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amUXq7960d_6k2gdW-4mCQAAANQ"]
[Sat Jul 25 22:08:12.384347 2026] [:error] [pid 22325:tid 140169252423424] [client 195.178.110.199:37522] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.cache"] [unique_id "amUXrL960d_6k2gdW-4mDAAAAMo"]
[Sat Jul 25 22:08:12.385353 2026] [:error] [pid 22325:tid 140169252423424] [client 195.178.110.199:37522] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.cache"] [unique_id "amUXrL960d_6k2gdW-4mDAAAAMo"]
[Sat Jul 25 22:08:12.428065 2026] [:error] [pid 25582:tid 140169134925568] [client 195.178.110.199:37466] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amUXrIlHCSx-vTXrLC-BcgAAABg"]
[Sat Jul 25 22:08:12.428865 2026] [:error] [pid 25582:tid 140169134925568] [client 195.178.110.199:37466] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amUXrIlHCSx-vTXrLC-BcgAAABg"]
[Sat Jul 25 22:08:12.429218 2026] [:error] [pid 25582:tid 140169134925568] [client 195.178.110.199:37466] [client 195.178.110.199] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amUXrIlHCSx-vTXrLC-BcgAAABg"]
[Sat Jul 25 22:08:12.844977 2026] [:error] [pid 22325:tid 140169357059840] [client 195.178.110.199:37522] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.dockerignore"] [unique_id "amUXrL960d_6k2gdW-4mDgAAAMY"]
[Sat Jul 25 22:08:12.844980 2026] [:error] [pid 25582:tid 140169176889088] [client 195.178.110.199:37466] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amUXrIlHCSx-vTXrLC-BdQAAABM"]
[Sat Jul 25 22:08:12.845689 2026] [:error] [pid 25582:tid 140169176889088] [client 195.178.110.199:37466] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amUXrIlHCSx-vTXrLC-BdQAAABM"]
[Sat Jul 25 22:08:12.845698 2026] [:error] [pid 22325:tid 140169357059840] [client 195.178.110.199:37522] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.dockerignore"] [unique_id "amUXrL960d_6k2gdW-4mDgAAAMY"]
[Sat Jul 25 22:08:12.846023 2026] [:error] [pid 25582:tid 140169176889088] [client 195.178.110.199:37466] [client 195.178.110.199] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amUXrIlHCSx-vTXrLC-BdQAAABM"]
[Sat Jul 25 22:08:12.848340 2026] [:error] [pid 22225:tid 140169185281792] [client 195.178.110.199:37460] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.docker/secrets.json"] [unique_id "amUXrCPSIfqBZpXN_94dpgAABNI"]
[Sat Jul 25 22:08:12.848369 2026] [:error] [pid 22325:tid 140169160103680] [client 195.178.110.199:37436] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.docker/laravel/app/.env"] [unique_id "amUXrL960d_6k2gdW-4mDwAAANU"]
[Sat Jul 25 22:08:12.848947 2026] [:error] [pid 22325:tid 140169160103680] [client 195.178.110.199:37436] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.docker/laravel/app/.env"] [unique_id "amUXrL960d_6k2gdW-4mDwAAANU"]
[Sat Jul 25 22:08:12.848978 2026] [:error] [pid 22225:tid 140169185281792] [client 195.178.110.199:37460] [client 195.178.110.199] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.docker/secrets.json"] [unique_id "amUXrCPSIfqBZpXN_94dpgAABNI"]
[Sat Jul 25 22:08:12.849296 2026] [:error] [pid 22325:tid 140169160103680] [client 195.178.110.199:37436] [client 195.178.110.199] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/laravel/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.docker/laravel/app/.env"] [unique_id "amUXrL960d_6k2gdW-4mDwAAANU"]
[Sat Jul 25 22:08:12.849307 2026] [:error] [pid 22225:tid 140169185281792] [client 195.178.110.199:37460] [client 195.178.110.199] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/secrets.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.docker/secrets.json"] [unique_id "amUXrCPSIfqBZpXN_94dpgAABNI"]
[Sat Jul 25 22:30:46.116757 2026] [:error] [pid 10800:tid 140169202067200] [client 52.200.251.20:1343] [client 52.200.251.20] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amUc9kQR0Lne3b5h1H2k1wAAAFA"]
[Sat Jul 25 22:30:46.118092 2026] [:error] [pid 10800:tid 140169202067200] [client 52.200.251.20:1343] [client 52.200.251.20] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amUc9kQR0Lne3b5h1H2k1wAAAFA"]
[Sat Jul 25 22:45:38.110795 2026] [:error] [pid 22325:tid 140169143318272] [client 43.166.130.123:56904] [client 43.166.130.123] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amUgcr960d_6k2gdW-4zIAAAANc"]
[Sat Jul 25 22:45:38.116592 2026] [:error] [pid 22325:tid 140169143318272] [client 43.166.130.123:56904] [client 43.166.130.123] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amUgcr960d_6k2gdW-4zIAAAANc"]
[Sat Jul 25 22:45:38.116893 2026] [:error] [pid 22325:tid 140169143318272] [client 43.166.130.123:56904] [client 43.166.130.123] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amUgcr960d_6k2gdW-4zIAAAANc"]
[Sat Jul 25 23:06:03.075972 2026] [:error] [pid 10800:tid 140169407416064] [client 107.170.9.103:51122] [client 107.170.9.103] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amUlO0QR0Lne3b5h1H3GCAAAAEA"]
[Sat Jul 25 23:06:03.077056 2026] [:error] [pid 10800:tid 140169407416064] [client 107.170.9.103:51122] [client 107.170.9.103] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amUlO0QR0Lne3b5h1H3GCAAAAEA"]
[Sat Jul 25 23:06:03.077682 2026] [:error] [pid 10800:tid 140169407416064] [client 107.170.9.103:51122] [client 107.170.9.103] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amUlO0QR0Lne3b5h1H3GCAAAAEA"]
[Sat Jul 25 23:06:03.078008 2026] [:error] [pid 10800:tid 140169407416064] [client 107.170.9.103:51122] [client 107.170.9.103] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amUlO0QR0Lne3b5h1H3GCAAAAEA"]
[Sat Jul 25 23:16:27.325355 2026] [:error] [pid 10800:tid 140169399023360] [client 172.70.240.73:10671] [client 172.70.240.73] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amUnq0QR0Lne3b5h1H3NbwAAAEE"]
[Sat Jul 25 23:16:27.326338 2026] [:error] [pid 10800:tid 140169399023360] [client 172.70.240.73:10671] [client 172.70.240.73] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amUnq0QR0Lne3b5h1H3NbwAAAEE"]
[Sat Jul 25 23:16:27.326916 2026] [:error] [pid 10800:tid 140169399023360] [client 172.70.240.73:10671] [client 172.70.240.73] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amUnq0QR0Lne3b5h1H3NbwAAAEE"]
[Sat Jul 25 23:23:27.921804 2026] [:error] [pid 25582:tid 140169218852608] [client 52.20.55.133:29076] [client 52.20.55.133] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amUpT4lHCSx-vTXrLC-3gQAAAA4"]
[Sat Jul 25 23:23:27.922838 2026] [:error] [pid 25582:tid 140169218852608] [client 52.20.55.133:29076] [client 52.20.55.133] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amUpT4lHCSx-vTXrLC-3gQAAAA4"]
[Sat Jul 25 23:32:34.503938 2026] [:error] [pid 25582:tid 140169365452544] [client 49.51.52.250:43622] [client 49.51.52.250] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amUrcolHCSx-vTXrLC-8LgAAAAU"]
[Sat Jul 25 23:32:34.505303 2026] [:error] [pid 25582:tid 140169365452544] [client 49.51.52.250:43622] [client 49.51.52.250] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amUrcolHCSx-vTXrLC-8LgAAAAU"]
[Sat Jul 25 23:32:34.505607 2026] [:error] [pid 25582:tid 140169365452544] [client 49.51.52.250:43622] [client 49.51.52.250] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amUrcolHCSx-vTXrLC-8LgAAAAU"]
[Sat Jul 25 23:49:48.845301 2026] [:error] [pid 25582:tid 140169269208832] [client 91.202.233.61:10430] [client 91.202.233.61] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amUvfIlHCSx-vTXrLC_FYAAAAAg"]
[Sat Jul 25 23:49:48.848632 2026] [:error] [pid 25582:tid 140169269208832] [client 91.202.233.61:10430] [client 91.202.233.61] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amUvfIlHCSx-vTXrLC_FYAAAAAg"]
[Sat Jul 25 23:52:47.509632 2026] [:error] [pid 10800:tid 140169357059840] [client 107.170.9.103:10070] [client 107.170.9.103] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amUwL0QR0Lne3b5h1H3lywAAAEY"]
[Sat Jul 25 23:52:47.511047 2026] [:error] [pid 10800:tid 140169357059840] [client 107.170.9.103:10070] [client 107.170.9.103] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amUwL0QR0Lne3b5h1H3lywAAAEY"]
[Sat Jul 25 23:52:47.511857 2026] [:error] [pid 10800:tid 140169357059840] [client 107.170.9.103:10070] [client 107.170.9.103] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amUwL0QR0Lne3b5h1H3lywAAAEY"]
[Sat Jul 25 23:52:47.512463 2026] [:error] [pid 10800:tid 140169357059840] [client 107.170.9.103:10070] [client 107.170.9.103] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amUwL0QR0Lne3b5h1H3lywAAAEY"]
[Sun Jul 26 00:53:56.374501 2026] [:error] [pid 22226:tid 140169193674496] [client 43.138.68.113:45908] [client 43.138.68.113] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amU-hB5FX32vfHTp22JP2gAABRE"]
[Sun Jul 26 00:53:56.380292 2026] [:error] [pid 22226:tid 140169193674496] [client 43.138.68.113:45908] [client 43.138.68.113] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amU-hB5FX32vfHTp22JP2gAABRE"]
[Sun Jul 26 00:53:56.380579 2026] [:error] [pid 22226:tid 140169193674496] [client 43.138.68.113:45908] [client 43.138.68.113] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amU-hB5FX32vfHTp22JP2gAABRE"]
[Sun Jul 26 01:03:53.611107 2026] [:error] [pid 22226:tid 140169382237952] [client 172.71.148.71:11070] [client 172.71.148.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amVA2R5FX32vfHTp22JRvwAABQM"]
[Sun Jul 26 01:03:53.612108 2026] [:error] [pid 22226:tid 140169382237952] [client 172.71.148.71:11070] [client 172.71.148.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amVA2R5FX32vfHTp22JRvwAABQM"]
[Sun Jul 26 01:03:53.612790 2026] [:error] [pid 22226:tid 140169382237952] [client 172.71.148.71:11070] [client 172.71.148.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amVA2R5FX32vfHTp22JRvwAABQM"]
[Sun Jul 26 01:06:38.362642 2026] [:error] [pid 22226:tid 140169277601536] [client 159.69.209.206:48600] [client 159.69.209.206] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVBfh5FX32vfHTp22JR4QAABQc"]
[Sun Jul 26 01:06:38.363605 2026] [:error] [pid 22226:tid 140169277601536] [client 159.69.209.206:48600] [client 159.69.209.206] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVBfh5FX32vfHTp22JR4QAABQc"]
[Sun Jul 26 01:06:38.363864 2026] [:error] [pid 22226:tid 140169277601536] [client 159.69.209.206:48600] [client 159.69.209.206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVBfh5FX32vfHTp22JR4QAABQc"]
[Sun Jul 26 02:02:50.139142 2026] [:error] [pid 22325:tid 140169151710976] [client 62.60.130.230:59959] [client 62.60.130.230] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVOqr960d_6k2gdW-5xuwAAANY"]
[Sun Jul 26 02:02:50.142159 2026] [:error] [pid 22325:tid 140169151710976] [client 62.60.130.230:59959] [client 62.60.130.230] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVOqr960d_6k2gdW-5xuwAAANY"]
[Sun Jul 26 02:02:50.142348 2026] [:error] [pid 22325:tid 140169151710976] [client 62.60.130.230:59959] [client 62.60.130.230] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVOqr960d_6k2gdW-5xuwAAANY"]
[Sun Jul 26 02:02:50.142457 2026] [:error] [pid 22325:tid 140169151710976] [client 62.60.130.230:59959] [client 62.60.130.230] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVOqr960d_6k2gdW-5xuwAAANY"]
[Sun Jul 26 02:02:50.142518 2026] [:error] [pid 22325:tid 140169151710976] [client 62.60.130.230:59959] [client 62.60.130.230] ModSecurity: Warning. Found 2 byte(s) in ARGS:rest_route outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:rest_route=/batch/v1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVOqr960d_6k2gdW-5xuwAAANY"]
[Sun Jul 26 02:02:50.505266 2026] [:error] [pid 22325:tid 140169176889088] [client 62.60.130.230:60096] [client 62.60.130.230] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-json/batch/v1"] [unique_id "amVOqr960d_6k2gdW-5xvgAAANM"]
[Sun Jul 26 02:02:50.506409 2026] [:error] [pid 22325:tid 140169176889088] [client 62.60.130.230:60096] [client 62.60.130.230] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-json/batch/v1"] [unique_id "amVOqr960d_6k2gdW-5xvgAAANM"]
[Sun Jul 26 02:02:50.506661 2026] [:error] [pid 22325:tid 140169176889088] [client 62.60.130.230:60096] [client 62.60.130.230] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-json/batch/v1"] [unique_id "amVOqr960d_6k2gdW-5xvgAAANM"]
[Sun Jul 26 02:02:50.506874 2026] [:error] [pid 22325:tid 140169176889088] [client 62.60.130.230:60096] [client 62.60.130.230] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-json/batch/v1"] [unique_id "amVOqr960d_6k2gdW-5xvgAAANM"]
[Sun Jul 26 02:43:21.136477 2026] [:error] [pid 22325:tid 140169244030720] [client 43.173.1.57:47702] [client 43.173.1.57] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVYKb960d_6k2gdW-6CNAAAAMs"]
[Sun Jul 26 02:43:21.140821 2026] [:error] [pid 22325:tid 140169244030720] [client 43.173.1.57:47702] [client 43.173.1.57] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVYKb960d_6k2gdW-6CNAAAAMs"]
[Sun Jul 26 02:43:21.141079 2026] [:error] [pid 22325:tid 140169244030720] [client 43.173.1.57:47702] [client 43.173.1.57] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVYKb960d_6k2gdW-6CNAAAAMs"]
[Sun Jul 26 02:44:59.780759 2026] [:error] [pid 4449:tid 140169210459904] [client 104.23.223.55:9553] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amVYi3EP_JaefnjzQFsSCAAAAQ8"]
[Sun Jul 26 02:44:59.781430 2026] [:error] [pid 4449:tid 140169210459904] [client 104.23.223.55:9553] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amVYi3EP_JaefnjzQFsSCAAAAQ8"]
[Sun Jul 26 02:44:59.781864 2026] [:error] [pid 4449:tid 140169210459904] [client 104.23.223.55:9553] [client 104.23.223.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amVYi3EP_JaefnjzQFsSCAAAAQ8"]
[Sun Jul 26 03:40:10.492441 2026] [:error] [pid 3332:tid 140070552037120] [client 43.167.241.46:52850] [client 43.167.241.46] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amVleoQhsJfItKlMcnVatwAAAA4"]
[Sun Jul 26 03:40:10.519040 2026] [:error] [pid 3332:tid 140070552037120] [client 43.167.241.46:52850] [client 43.167.241.46] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amVleoQhsJfItKlMcnVatwAAAA4"]
[Sun Jul 26 03:40:10.519292 2026] [:error] [pid 3332:tid 140070552037120] [client 43.167.241.46:52850] [client 43.167.241.46] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amVleoQhsJfItKlMcnVatwAAAA4"]
[Sun Jul 26 03:57:19.521906 2026] [:error] [pid 3339:tid 140070535251712] [client 34.122.16.212:58610] [client 34.122.16.212] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVpfzpp49GF-jPI3LEm3gAAAJA"]
[Sun Jul 26 03:57:19.522949 2026] [:error] [pid 3339:tid 140070535251712] [client 34.122.16.212:58610] [client 34.122.16.212] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVpfzpp49GF-jPI3LEm3gAAAJA"]
[Sun Jul 26 03:57:19.523497 2026] [:error] [pid 3339:tid 140070535251712] [client 34.122.16.212:58610] [client 34.122.16.212] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua=\\x22Not(A:Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22144\\x22, \\x22Google Chrome\\x22;v=\\x22144\\x22"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVpfzpp49GF-jPI3LEm3gAAAJA"]
[Sun Jul 26 03:57:19.523613 2026] [:error] [pid 3339:tid 140070535251712] [client 34.122.16.212:58610] [client 34.122.16.212] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amVpfzpp49GF-jPI3LEm3gAAAJA"]
[Sun Jul 26 04:11:55.812743 2026] [:error] [pid 3880:tid 140070560429824] [client 4.223.77.241:42832] [client 4.223.77.241] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amVs687ZG1QQK_KHlJ1spQAAAM0"]
[Sun Jul 26 04:11:55.813844 2026] [:error] [pid 3880:tid 140070560429824] [client 4.223.77.241:42832] [client 4.223.77.241] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amVs687ZG1QQK_KHlJ1spQAAAM0"]
[Sun Jul 26 04:11:55.814130 2026] [:error] [pid 3880:tid 140070560429824] [client 4.223.77.241:42832] [client 4.223.77.241] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amVs687ZG1QQK_KHlJ1spQAAAM0"]
[Sun Jul 26 04:18:34.438380 2026] [:error] [pid 3339:tid 140070602393344] [client 172.174.110.129:20635] [client 172.174.110.129] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amVuejpp49GF-jPI3LEuTgAAAIg"]
[Sun Jul 26 04:18:34.439633 2026] [:error] [pid 3339:tid 140070602393344] [client 172.174.110.129:20635] [client 172.174.110.129] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amVuejpp49GF-jPI3LEuTgAAAIg"]
[Sun Jul 26 04:29:19.307570 2026] [:error] [pid 3339:tid 140070535251712] [client 104.23.223.55:9753] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amVw_zpp49GF-jPI3LEzdQAAAJA"]
[Sun Jul 26 04:29:19.308360 2026] [:error] [pid 3339:tid 140070535251712] [client 104.23.223.55:9753] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amVw_zpp49GF-jPI3LEzdQAAAJA"]
[Sun Jul 26 04:29:19.309192 2026] [:error] [pid 3339:tid 140070535251712] [client 104.23.223.55:9753] [client 104.23.223.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amVw_zpp49GF-jPI3LEzdQAAAJA"]
[Sun Jul 26 05:15:01.833077 2026] [:error] [pid 3334:tid 140070543644416] [client 185.93.89.147:47522] [client 185.93.89.147] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amV7tc1h5VdHMptLZhDvxQAAAE8"]
[Sun Jul 26 05:15:01.845026 2026] [:error] [pid 3334:tid 140070543644416] [client 185.93.89.147:47522] [client 185.93.89.147] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amV7tc1h5VdHMptLZhDvxQAAAE8"]
[Sun Jul 26 05:15:05.701689 2026] [:error] [pid 3880:tid 140070610786048] [client 185.93.89.147:58858] [client 185.93.89.147] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amV7uc7ZG1QQK_KHlJ2kGAAAAMc"]
[Sun Jul 26 05:15:05.702661 2026] [:error] [pid 3880:tid 140070610786048] [client 185.93.89.147:58858] [client 185.93.89.147] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amV7uc7ZG1QQK_KHlJ2kGAAAAMc"]
[Sun Jul 26 05:48:55.840969 2026] [:error] [pid 3334:tid 140070552037120] [client 195.178.110.211:44896] [client 195.178.110.211] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "amWDp81h5VdHMptLZhAHfwAAAE4"]
[Sun Jul 26 05:48:55.847484 2026] [:error] [pid 3334:tid 140070552037120] [client 195.178.110.211:44896] [client 195.178.110.211] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "amWDp81h5VdHMptLZhAHfwAAAE4"]
[Sun Jul 26 05:48:55.847922 2026] [:error] [pid 3334:tid 140070552037120] [client 195.178.110.211:44896] [client 195.178.110.211] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "amWDp81h5VdHMptLZhAHfwAAAE4"]
[Sun Jul 26 05:58:12.491859 2026] [:error] [pid 3339:tid 140070552037120] [client 52.0.218.219:23018] [client 52.0.218.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWF1Dpp49GF-jPI3LFbGAAAAI4"]
[Sun Jul 26 05:58:12.493003 2026] [:error] [pid 3339:tid 140070552037120] [client 52.0.218.219:23018] [client 52.0.218.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWF1Dpp49GF-jPI3LFbGAAAAI4"]
[Sun Jul 26 05:58:17.240067 2026] [:error] [pid 3334:tid 140070476502784] [client 3.213.213.161:65359] [client 3.213.213.161] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWF2c1h5VdHMptLZhASDwAAAFc"]
[Sun Jul 26 05:58:17.240975 2026] [:error] [pid 3334:tid 140070476502784] [client 3.213.213.161:65359] [client 3.213.213.161] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWF2c1h5VdHMptLZhASDwAAAFc"]
[Sun Jul 26 06:03:48.088951 2026] [:error] [pid 3334:tid 140070723757824] [client 51.68.107.144:18585] [client 51.68.107.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWHJM1h5VdHMptLZhAX4QAAAEI"]
[Sun Jul 26 06:03:48.090165 2026] [:error] [pid 3334:tid 140070723757824] [client 51.68.107.144:18585] [client 51.68.107.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWHJM1h5VdHMptLZhAX4QAAAEI"]
[Sun Jul 26 06:03:48.090331 2026] [:error] [pid 3334:tid 140070723757824] [client 51.68.107.144:18585] [client 51.68.107.144] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "176"] [id "913102"] [msg "Found User-Agent associated with web crawler/bot"] [data "Matched Data: MJ12bot found within REQUEST_HEADERS:User-Agent: mozilla/5.0 (compatible; mj12bot/v2.0.5; http://mj12bot.com/)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-crawler"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWHJM1h5VdHMptLZhAX4QAAAEI"]
[Sun Jul 26 06:03:48.348207 2026] [:error] [pid 3334:tid 140070585607936] [client 51.68.107.144:18585] [client 51.68.107.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWHJM1h5VdHMptLZhAX4wAAAEo"]
[Sun Jul 26 06:03:48.349052 2026] [:error] [pid 3334:tid 140070585607936] [client 51.68.107.144:18585] [client 51.68.107.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWHJM1h5VdHMptLZhAX4wAAAEo"]
[Sun Jul 26 06:03:48.349191 2026] [:error] [pid 3334:tid 140070585607936] [client 51.68.107.144:18585] [client 51.68.107.144] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "176"] [id "913102"] [msg "Found User-Agent associated with web crawler/bot"] [data "Matched Data: MJ12bot found within REQUEST_HEADERS:User-Agent: mozilla/5.0 (compatible; mj12bot/v2.0.5; http://mj12bot.com/)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-crawler"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWHJM1h5VdHMptLZhAX4wAAAEo"]
[Sun Jul 26 06:48:15.808726 2026] [:error] [pid 3334:tid 140070568822528] [client 43.166.136.153:43810] [client 43.166.136.153] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWRj81h5VdHMptLZhBO8wAAAEw"]
[Sun Jul 26 06:48:15.811786 2026] [:error] [pid 3334:tid 140070568822528] [client 43.166.136.153:43810] [client 43.166.136.153] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWRj81h5VdHMptLZhBO8wAAAEw"]
[Sun Jul 26 06:48:15.812031 2026] [:error] [pid 3334:tid 140070568822528] [client 43.166.136.153:43810] [client 43.166.136.153] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWRj81h5VdHMptLZhBO8wAAAEw"]
[Sun Jul 26 06:53:50.542335 2026] [:error] [pid 5596:tid 140637319931648] [client 172.71.148.71:10106] [client 172.71.148.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amWS3tByyk8BtWGuoptYDQAAAI8"]
[Sun Jul 26 06:53:50.543111 2026] [:error] [pid 5596:tid 140637319931648] [client 172.71.148.71:10106] [client 172.71.148.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amWS3tByyk8BtWGuoptYDQAAAI8"]
[Sun Jul 26 06:53:50.543570 2026] [:error] [pid 5596:tid 140637319931648] [client 172.71.148.71:10106] [client 172.71.148.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amWS3tByyk8BtWGuoptYDQAAAI8"]
[Sun Jul 26 07:09:46.480900 2026] [:error] [pid 5754:tid 140637252790016] [client 74.7.228.53:41968] [client 74.7.228.53] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWWmhNda9Y_z4_oImIhYwAAANc"]
[Sun Jul 26 07:09:46.482082 2026] [:error] [pid 5754:tid 140637252790016] [client 74.7.228.53:41968] [client 74.7.228.53] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWWmhNda9Y_z4_oImIhYwAAANc"]
[Sun Jul 26 07:09:46.482385 2026] [:error] [pid 5754:tid 140637252790016] [client 74.7.228.53:41968] [client 74.7.228.53] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:from outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:from=oai-searchbot(at)openai.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWWmhNda9Y_z4_oImIhYwAAANc"]
[Sun Jul 26 07:09:51.895645 2026] [:error] [pid 5596:tid 140637319931648] [client 74.7.228.53:57986] [client 74.7.228.53] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWWn9Byyk8BtWGuoptgywAAAI8"]
[Sun Jul 26 07:09:51.896634 2026] [:error] [pid 5596:tid 140637319931648] [client 74.7.228.53:57986] [client 74.7.228.53] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWWn9Byyk8BtWGuoptgywAAAI8"]
[Sun Jul 26 07:09:51.897050 2026] [:error] [pid 5596:tid 140637319931648] [client 74.7.228.53:57986] [client 74.7.228.53] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:from outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:from=oai-searchbot(at)openai.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWWn9Byyk8BtWGuoptgywAAAI8"]
[Sun Jul 26 07:09:52.313190 2026] [:error] [pid 5754:tid 140637286360832] [client 74.7.228.53:57990] [client 74.7.228.53] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWWoBNda9Y_z4_oImIhfgAAANM"]
[Sun Jul 26 07:09:52.314012 2026] [:error] [pid 5754:tid 140637286360832] [client 74.7.228.53:57990] [client 74.7.228.53] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWWoBNda9Y_z4_oImIhfgAAANM"]
[Sun Jul 26 07:09:52.314403 2026] [:error] [pid 5754:tid 140637286360832] [client 74.7.228.53:57990] [client 74.7.228.53] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:from outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:from=oai-searchbot(at)openai.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWWoBNda9Y_z4_oImIhfgAAANM"]
[Sun Jul 26 07:33:42.844792 2026] [:error] [pid 5595:tid 140637504599808] [client 124.221.163.189:44772] [client 124.221.163.189] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWcNqEGMhtncrWTp9etWQAAAEE"]
[Sun Jul 26 07:33:42.851696 2026] [:error] [pid 5595:tid 140637504599808] [client 124.221.163.189:44772] [client 124.221.163.189] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWcNqEGMhtncrWTp9etWQAAAEE"]
[Sun Jul 26 07:33:42.851869 2026] [:error] [pid 5595:tid 140637504599808] [client 124.221.163.189:44772] [client 124.221.163.189] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWcNqEGMhtncrWTp9etWQAAAEE"]
[Sun Jul 26 07:46:33.669190 2026] [:error] [pid 5754:tid 140637512992512] [client 43.134.91.35:47218] [client 43.134.91.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amWfORNda9Y_z4_oImJMJwAAAMA"]
[Sun Jul 26 07:46:33.670134 2026] [:error] [pid 5754:tid 140637512992512] [client 43.134.91.35:47218] [client 43.134.91.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amWfORNda9Y_z4_oImJMJwAAAMA"]
[Sun Jul 26 07:46:33.670366 2026] [:error] [pid 5754:tid 140637512992512] [client 43.134.91.35:47218] [client 43.134.91.35] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amWfORNda9Y_z4_oImJMJwAAAMA"]
[Sun Jul 26 08:00:40.895018 2026] [:error] [pid 5596:tid 140637336717056] [client 45.148.10.244:34378] [client 45.148.10.244] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWiiNByyk8BtWGuopt_IAAAAI0"]
[Sun Jul 26 08:00:40.896179 2026] [:error] [pid 5596:tid 140637336717056] [client 45.148.10.244:34378] [client 45.148.10.244] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWiiNByyk8BtWGuopt_IAAAAI0"]
[Sun Jul 26 08:16:47.128565 2026] [:error] [pid 32686:tid 140637353502464] [client 66.249.78.7:49686] [client 66.249.78.7] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWmT_gpOYThtIuUA_oNXQAAAQs"]
[Sun Jul 26 08:16:47.129475 2026] [:error] [pid 32686:tid 140637353502464] [client 66.249.78.7:49686] [client 66.249.78.7] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amWmT_gpOYThtIuUA_oNXQAAAQs"]
[Sun Jul 26 08:16:48.638944 2026] [:error] [pid 32686:tid 140637269575424] [client 66.249.78.7:49686] [client 66.249.78.7] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWmUPgpOYThtIuUA_oNZgAAARU"]
[Sun Jul 26 08:16:48.639577 2026] [:error] [pid 32686:tid 140637269575424] [client 66.249.78.7:49686] [client 66.249.78.7] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWmUPgpOYThtIuUA_oNZgAAARU"]
[Sun Jul 26 08:16:48.639945 2026] [:error] [pid 32686:tid 140637269575424] [client 66.249.78.7:49686] [client 66.249.78.7] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:From outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:From=googlebot(at)googlebot.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amWmUPgpOYThtIuUA_oNZgAAARU"]
[Sun Jul 26 08:36:42.799496 2026] [:error] [pid 32686:tid 140637512992512] [client 172.71.164.5:12265] [client 172.71.164.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amWq-vgpOYThtIuUA_oiAQAAAQA"]
[Sun Jul 26 08:36:42.804095 2026] [:error] [pid 32686:tid 140637512992512] [client 172.71.164.5:12265] [client 172.71.164.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amWq-vgpOYThtIuUA_oiAQAAAQA"]
[Sun Jul 26 08:36:42.804532 2026] [:error] [pid 32686:tid 140637512992512] [client 172.71.164.5:12265] [client 172.71.164.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amWq-vgpOYThtIuUA_oiAQAAAQA"]
[Sun Jul 26 08:40:46.340230 2026] [:error] [pid 5754:tid 140637261182720] [client 172.70.240.73:10168] [client 172.70.240.73] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amWr7hNda9Y_z4_oImJ1eAAAANY"]
[Sun Jul 26 08:40:46.341088 2026] [:error] [pid 5754:tid 140637261182720] [client 172.70.240.73:10168] [client 172.70.240.73] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amWr7hNda9Y_z4_oImJ1eAAAANY"]
[Sun Jul 26 08:40:46.341481 2026] [:error] [pid 5754:tid 140637261182720] [client 172.70.240.73:10168] [client 172.70.240.73] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amWr7hNda9Y_z4_oImJ1eAAAANY"]
[Sun Jul 26 09:10:28.114214 2026] [:error] [pid 5754:tid 140637244397312] [client 191.11.196.94:64150] [client 191.11.196.94] ModSecurity: Warning. Match of "rx ^%{tx.allowed_request_content_type_charset}$" against "TX:1" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "983"] [id "920480"] [msg "Request content type charset is not allowed by policy"] [data "utf-8"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "amWy5BNda9Y_z4_oImKKbAAAANg"]
[Sun Jul 26 09:10:28.114325 2026] [:error] [pid 5754:tid 140637244397312] [client 191.11.196.94:64150] [client 191.11.196.94] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "amWy5BNda9Y_z4_oImKKbAAAANg"]
[Sun Jul 26 09:10:28.115148 2026] [:error] [pid 5754:tid 140637244397312] [client 191.11.196.94:64150] [client 191.11.196.94] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "amWy5BNda9Y_z4_oImKKbAAAANg"]
[Sun Jul 26 09:10:28.115403 2026] [:error] [pid 5754:tid 140637244397312] [client 191.11.196.94:64150] [client 191.11.196.94] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|text/xml|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "amWy5BNda9Y_z4_oImKKbAAAANg"]
[Sun Jul 26 09:10:28.115685 2026] [:error] [pid 5754:tid 140637244397312] [client 191.11.196.94:64150] [client 191.11.196.94] ModSecurity: Warning. Found 177 byte(s) in REQUEST_BODY outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "REQUEST_BODY=<?xml version=\\x221.0\\x22?><methodCall><methodName>metaWeblog.newPost</methodName><params><param><value><string>1</string></value></param><param><value><string>43860</string></value></param><param><value><string>43860</string></value></param><param><value><struct><member><name>title</name><value><string>0x84d0fc02</string></value></member><member><name>description</name><value><string>0x84d0fc02</string></value></member><member><name>mt_keywords</name><value><string>0x84d0fc02</string></valu..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "amWy5BNda9Y_z4_oImKKbAAAANg"]
[Sun Jul 26 09:51:23.844221 2026] [:error] [pid 5754:tid 140637311538944] [client 3.229.213.129:33986] [client 3.229.213.129] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amW8exNda9Y_z4_oImKjUwAAANA"]
[Sun Jul 26 09:51:23.848931 2026] [:error] [pid 5754:tid 140637311538944] [client 3.229.213.129:33986] [client 3.229.213.129] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amW8exNda9Y_z4_oImKjUwAAANA"]
[Sun Jul 26 10:21:03.875997 2026] [:error] [pid 32686:tid 140637294753536] [client 104.23.221.25:12186] [client 104.23.221.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amXDb_gpOYThtIuUA_p-zwAAARI"]
[Sun Jul 26 10:21:03.876814 2026] [:error] [pid 32686:tid 140637294753536] [client 104.23.221.25:12186] [client 104.23.221.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amXDb_gpOYThtIuUA_p-zwAAARI"]
[Sun Jul 26 10:21:03.877201 2026] [:error] [pid 32686:tid 140637294753536] [client 104.23.221.25:12186] [client 104.23.221.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amXDb_gpOYThtIuUA_p-zwAAARI"]
[Sun Jul 26 10:39:27.552202 2026] [:error] [pid 5596:tid 140637353502464] [client 54.38.176.226:34146] [client 54.38.176.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amXHv9Byyk8BtWGuopu40QAAAIs"]
[Sun Jul 26 10:39:27.555829 2026] [:error] [pid 5596:tid 140637353502464] [client 54.38.176.226:34146] [client 54.38.176.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amXHv9Byyk8BtWGuopu40QAAAIs"]
[Sun Jul 26 10:39:27.579851 2026] [:error] [pid 5594:tid 140637269575424] [client 54.38.176.226:54582] [client 54.38.176.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amXHvwjaFasezQy5uM2t6QAAABU"]
[Sun Jul 26 10:39:27.580894 2026] [:error] [pid 5594:tid 140637269575424] [client 54.38.176.226:54582] [client 54.38.176.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amXHvwjaFasezQy5uM2t6QAAABU"]
[Sun Jul 26 10:54:11.636453 2026] [:error] [pid 2699:tid 140637353502464] [client 43.135.172.89:50124] [client 43.135.172.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amXLMz2mYcK8EcuM2ezNtAAAAYs"]
[Sun Jul 26 10:54:11.637374 2026] [:error] [pid 2699:tid 140637353502464] [client 43.135.172.89:50124] [client 43.135.172.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amXLMz2mYcK8EcuM2ezNtAAAAYs"]
[Sun Jul 26 10:54:11.637626 2026] [:error] [pid 2699:tid 140637353502464] [client 43.135.172.89:50124] [client 43.135.172.89] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amXLMz2mYcK8EcuM2ezNtAAAAYs"]
[Sun Jul 26 11:27:56.097165 2026] [:error] [pid 32686:tid 140637328324352] [client 212.32.69.244:58665] [client 212.32.69.244] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amXTHPgpOYThtIuUA_qKxgAAAQ4"]
[Sun Jul 26 11:27:56.098664 2026] [:error] [pid 32686:tid 140637328324352] [client 212.32.69.244:58665] [client 212.32.69.244] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amXTHPgpOYThtIuUA_qKxgAAAQ4"]
[Sun Jul 26 11:27:56.099536 2026] [:error] [pid 32686:tid 140637328324352] [client 212.32.69.244:58665] [client 212.32.69.244] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amXTHPgpOYThtIuUA_qKxgAAAQ4"]
[Sun Jul 26 11:36:33.483646 2026] [:error] [pid 26466:tid 140637252790016] [client 49.51.195.195:33390] [client 49.51.195.195] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amXVIfJKkfnWBtPEXvgawQAAAlc"]
[Sun Jul 26 11:36:33.487909 2026] [:error] [pid 26466:tid 140637252790016] [client 49.51.195.195:33390] [client 49.51.195.195] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amXVIfJKkfnWBtPEXvgawQAAAlc"]
[Sun Jul 26 11:36:33.488109 2026] [:error] [pid 26466:tid 140637252790016] [client 49.51.195.195:33390] [client 49.51.195.195] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amXVIfJKkfnWBtPEXvgawQAAAlc"]
[Sun Jul 26 12:06:07.939622 2026] [:error] [pid 26466:tid 140637328324352] [client 172.71.148.71:11943] [client 172.71.148.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amXcD_JKkfnWBtPEXvgnOwAAAk4"]
[Sun Jul 26 12:06:07.940546 2026] [:error] [pid 26466:tid 140637328324352] [client 172.71.148.71:11943] [client 172.71.148.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amXcD_JKkfnWBtPEXvgnOwAAAk4"]
[Sun Jul 26 12:06:07.941120 2026] [:error] [pid 26466:tid 140637328324352] [client 172.71.148.71:11943] [client 172.71.148.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amXcD_JKkfnWBtPEXvgnOwAAAk4"]
[Sun Jul 26 12:24:53.641817 2026] [:error] [pid 10555:tid 140637412251392] [client 34.150.214.136:63368] [client 34.150.214.136] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amXgdYRv78pCAopwdxl_xwAAAAQ"]
[Sun Jul 26 12:24:53.642799 2026] [:error] [pid 10555:tid 140637412251392] [client 34.150.214.136:63368] [client 34.150.214.136] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amXgdYRv78pCAopwdxl_xwAAAAQ"]
[Sun Jul 26 12:24:53.643118 2026] [:error] [pid 10555:tid 140637412251392] [client 34.150.214.136:63368] [client 34.150.214.136] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amXgdYRv78pCAopwdxl_xwAAAAQ"]
[Sun Jul 26 12:43:14.199119 2026] [:error] [pid 27400:tid 140140907431680] [client 136.66.254.226:63480] [client 136.66.254.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amXkwodDVjTFeyHnElQQAAAAAcQ"]
[Sun Jul 26 12:43:14.203219 2026] [:error] [pid 27400:tid 140140907431680] [client 136.66.254.226:63480] [client 136.66.254.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amXkwodDVjTFeyHnElQQAAAAAcQ"]
[Sun Jul 26 12:43:14.203718 2026] [:error] [pid 27400:tid 140140907431680] [client 136.66.254.226:63480] [client 136.66.254.226] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amXkwodDVjTFeyHnElQQAAAAAcQ"]
[Sun Jul 26 13:07:21.757775 2026] [:error] [pid 3933:tid 140140714338048] [client 3.224.205.25:16717] [client 3.224.205.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amXqadI48nNwl9aPiibJngAAAFM"]
[Sun Jul 26 13:07:21.758996 2026] [:error] [pid 3933:tid 140140714338048] [client 3.224.205.25:16717] [client 3.224.205.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amXqadI48nNwl9aPiibJngAAAFM"]
[Sun Jul 26 13:50:19.004179 2026] [:error] [pid 3933:tid 140140941002496] [client 172.68.193.169:13165] [client 172.68.193.169] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amX0e9I48nNwl9aPiibiSgAAAEA"]
[Sun Jul 26 13:50:19.008435 2026] [:error] [pid 3933:tid 140140941002496] [client 172.68.193.169:13165] [client 172.68.193.169] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amX0e9I48nNwl9aPiibiSgAAAEA"]
[Sun Jul 26 13:50:19.009120 2026] [:error] [pid 3933:tid 140140941002496] [client 172.68.193.169:13165] [client 172.68.193.169] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amX0e9I48nNwl9aPiibiSgAAAEA"]
[Sun Jul 26 14:36:57.825214 2026] [:error] [pid 3900:tid 140140789872384] [client 43.167.241.46:42994] [client 43.167.241.46] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amX_aSHeMDiKBn4nZ4HY5AAAAAo"]
[Sun Jul 26 14:36:57.829329 2026] [:error] [pid 3900:tid 140140789872384] [client 43.167.241.46:42994] [client 43.167.241.46] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amX_aSHeMDiKBn4nZ4HY5AAAAAo"]
[Sun Jul 26 14:36:57.829504 2026] [:error] [pid 3900:tid 140140789872384] [client 43.167.241.46:42994] [client 43.167.241.46] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amX_aSHeMDiKBn4nZ4HY5AAAAAo"]
[Sun Jul 26 14:47:27.775468 2026] [:error] [pid 27400:tid 140140899038976] [client 49.235.136.28:47882] [client 49.235.136.28] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amYB34dDVjTFeyHnElQ3ZQAAAcU"]
[Sun Jul 26 14:47:27.776221 2026] [:error] [pid 27400:tid 140140899038976] [client 49.235.136.28:47882] [client 49.235.136.28] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amYB34dDVjTFeyHnElQ3ZQAAAcU"]
[Sun Jul 26 14:47:27.776446 2026] [:error] [pid 27400:tid 140140899038976] [client 49.235.136.28:47882] [client 49.235.136.28] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amYB34dDVjTFeyHnElQ3ZQAAAcU"]
[Sun Jul 26 15:22:10.307382 2026] [:error] [pid 3933:tid 140140789872384] [client 20.197.195.24:60352] [client 20.197.195.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amYKAtI48nNwl9aPiiYaEwAAAEo"]
[Sun Jul 26 15:22:10.309089 2026] [:error] [pid 3933:tid 140140789872384] [client 20.197.195.24:60352] [client 20.197.195.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amYKAtI48nNwl9aPiiYaEwAAAEo"]
[Sun Jul 26 15:22:10.309587 2026] [:error] [pid 3933:tid 140140789872384] [client 20.197.195.24:60352] [client 20.197.195.24] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amYKAtI48nNwl9aPiiYaEwAAAEo"]
[Sun Jul 26 15:27:57.394754 2026] [:error] [pid 3900:tid 140140697552640] [client 43.159.141.150:39014] [client 43.159.141.150] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amYLXSHeMDiKBn4nZ4H6BQAAABU"]
[Sun Jul 26 15:27:57.395835 2026] [:error] [pid 3900:tid 140140697552640] [client 43.159.141.150:39014] [client 43.159.141.150] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amYLXSHeMDiKBn4nZ4H6BQAAABU"]
[Sun Jul 26 15:27:57.396116 2026] [:error] [pid 3900:tid 140140697552640] [client 43.159.141.150:39014] [client 43.159.141.150] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amYLXSHeMDiKBn4nZ4H6BQAAABU"]
[Sun Jul 26 15:35:14.220067 2026] [:error] [pid 3933:tid 140140789872384] [client 172.70.240.72:11354] [client 172.70.240.72] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amYNEtI48nNwl9aPiiYkyAAAAEo"]
[Sun Jul 26 15:35:14.223081 2026] [:error] [pid 3933:tid 140140789872384] [client 172.70.240.72:11354] [client 172.70.240.72] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amYNEtI48nNwl9aPiiYkyAAAAEo"]
[Sun Jul 26 15:35:14.223581 2026] [:error] [pid 3933:tid 140140789872384] [client 172.70.240.72:11354] [client 172.70.240.72] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amYNEtI48nNwl9aPiiYkyAAAAEo"]
[Sun Jul 26 16:24:02.275183 2026] [:error] [pid 3933:tid 140140915824384] [client 158.101.144.198:19790] [client 158.101.144.198] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amYYgtI48nNwl9aPiiZMiwAAAEM"]
[Sun Jul 26 16:24:02.276240 2026] [:error] [pid 3933:tid 140140915824384] [client 158.101.144.198:19790] [client 158.101.144.198] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amYYgtI48nNwl9aPiiZMiwAAAEM"]
[Sun Jul 26 16:24:02.276818 2026] [:error] [pid 3933:tid 140140915824384] [client 158.101.144.198:19790] [client 158.101.144.198] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amYYgtI48nNwl9aPiiZMiwAAAEM"]
[Sun Jul 26 17:20:05.641111 2026] [:error] [pid 27304:tid 140140714338048] [client 104.23.223.55:10604] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amYlpb6ko4O5Pn0gGUeyOgAAAVM"]
[Sun Jul 26 17:20:05.644626 2026] [:error] [pid 27304:tid 140140714338048] [client 104.23.223.55:10604] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amYlpb6ko4O5Pn0gGUeyOgAAAVM"]
[Sun Jul 26 17:20:05.645310 2026] [:error] [pid 27304:tid 140140714338048] [client 104.23.223.55:10604] [client 104.23.223.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amYlpb6ko4O5Pn0gGUeyOgAAAVM"]
[Sun Jul 26 17:20:13.613638 2026] [:error] [pid 27305:tid 140140680767232] [client 34.181.172.115:56988] [client 34.181.172.115] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amYlreVYyXRoT8g9-3bv_gAAAZc"]
[Sun Jul 26 17:20:13.614316 2026] [:error] [pid 27305:tid 140140680767232] [client 34.181.172.115:56988] [client 34.181.172.115] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amYlreVYyXRoT8g9-3bv_gAAAZc"]
[Sun Jul 26 17:20:13.614597 2026] [:error] [pid 27305:tid 140140680767232] [client 34.181.172.115:56988] [client 34.181.172.115] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amYlreVYyXRoT8g9-3bv_gAAAZc"]
[Sun Jul 26 17:28:12.074118 2026] [:error] [pid 27305:tid 140140789872384] [client 74.248.139.103:24696] [client 74.248.139.103] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amYnjOVYyXRoT8g9-3b2PgAAAYo"]
[Sun Jul 26 17:28:12.075185 2026] [:error] [pid 27305:tid 140140789872384] [client 74.248.139.103:24696] [client 74.248.139.103] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amYnjOVYyXRoT8g9-3b2PgAAAYo"]
[Sun Jul 26 17:28:12.075486 2026] [:error] [pid 27305:tid 140140789872384] [client 74.248.139.103:24696] [client 74.248.139.103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amYnjOVYyXRoT8g9-3b2PgAAAYo"]
[Sun Jul 26 17:39:40.620709 2026] [:error] [pid 3933:tid 140140672374528] [client 52.173.162.96:8502] [client 52.173.162.96] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amYqPNI48nNwl9aPiiaDCgAAAFg"]
[Sun Jul 26 17:39:40.674447 2026] [:error] [pid 3933:tid 140140672374528] [client 52.173.162.96:8502] [client 52.173.162.96] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amYqPNI48nNwl9aPiiaDCgAAAFg"]
[Sun Jul 26 17:39:40.674863 2026] [:error] [pid 3933:tid 140140672374528] [client 52.173.162.96:8502] [client 52.173.162.96] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amYqPNI48nNwl9aPiiaDCgAAAFg"]
[Sun Jul 26 18:13:45.807049 2026] [:error] [pid 27305:tid 140140823443200] [client 3.227.226.73:58445] [client 3.227.226.73] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amYyOeVYyXRoT8g9-3YGdQAAAYY"]
[Sun Jul 26 18:13:45.808267 2026] [:error] [pid 27305:tid 140140823443200] [client 3.227.226.73:58445] [client 3.227.226.73] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amYyOeVYyXRoT8g9-3YGdQAAAYY"]
[Sun Jul 26 18:26:19.251293 2026] [:error] [pid 27305:tid 140140815050496] [client 34.224.132.215:18963] [client 34.224.132.215] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amY1K-VYyXRoT8g9-3YKbQAAAYc"]
[Sun Jul 26 18:26:19.252089 2026] [:error] [pid 27305:tid 140140815050496] [client 34.224.132.215:18963] [client 34.224.132.215] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amY1K-VYyXRoT8g9-3YKbQAAAYc"]
[Sun Jul 26 18:36:56.708855 2026] [:error] [pid 27305:tid 140140722730752] [client 47.254.92.190:36890] [client 47.254.92.190] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amY3qOVYyXRoT8g9-3YPegAAAZI"]
[Sun Jul 26 18:36:56.713070 2026] [:error] [pid 27305:tid 140140722730752] [client 47.254.92.190:36890] [client 47.254.92.190] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amY3qOVYyXRoT8g9-3YPegAAAZI"]
[Sun Jul 26 18:36:56.713338 2026] [:error] [pid 27305:tid 140140722730752] [client 47.254.92.190:36890] [client 47.254.92.190] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amY3qOVYyXRoT8g9-3YPegAAAZI"]
[Sun Jul 26 18:38:53.508169 2026] [:error] [pid 1294:tid 140140924217088] [client 54.87.95.7:6621] [client 54.87.95.7] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amY4Hdrg84vUb1nD3O6rsAAAAII"]
[Sun Jul 26 18:38:53.508642 2026] [:error] [pid 1294:tid 140140924217088] [client 54.87.95.7:6621] [client 54.87.95.7] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amY4Hdrg84vUb1nD3O6rsAAAAII"]
[Sun Jul 26 18:39:36.848376 2026] [:error] [pid 27305:tid 140140689159936] [client 52.20.91.185:61223] [client 52.20.91.185] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amY4SOVYyXRoT8g9-3YQNAAAAZY"]
[Sun Jul 26 18:39:36.849473 2026] [:error] [pid 27305:tid 140140689159936] [client 52.20.91.185:61223] [client 52.20.91.185] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amY4SOVYyXRoT8g9-3YQNAAAAZY"]
[Sun Jul 26 18:48:14.160126 2026] [:error] [pid 27305:tid 140140932609792] [client 109.199.118.129:33008] [client 109.199.118.129] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amY6TuVYyXRoT8g9-3YTqQAAAYE"]
[Sun Jul 26 18:48:14.160954 2026] [:error] [pid 27305:tid 140140932609792] [client 109.199.118.129:33008] [client 109.199.118.129] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amY6TuVYyXRoT8g9-3YTqQAAAYE"]
[Sun Jul 26 19:07:02.955469 2026] [:error] [pid 3933:tid 140140907431680] [client 172.70.242.202:10135] [client 172.70.242.202] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amY-ttI48nNwl9aPiiaRXQAAAEQ"]
[Sun Jul 26 19:07:02.956233 2026] [:error] [pid 3933:tid 140140907431680] [client 172.70.242.202:10135] [client 172.70.242.202] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amY-ttI48nNwl9aPiiaRXQAAAEQ"]
[Sun Jul 26 19:07:02.956784 2026] [:error] [pid 3933:tid 140140907431680] [client 172.70.242.202:10135] [client 172.70.242.202] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amY-ttI48nNwl9aPiiaRXQAAAEQ"]
[Sun Jul 26 19:15:39.758488 2026] [:error] [pid 27305:tid 140140907431680] [client 174.129.182.173:18612] [client 174.129.182.173] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZAu-VYyXRoT8g9-3YgcwAAAYQ"]
[Sun Jul 26 19:15:39.759521 2026] [:error] [pid 27305:tid 140140907431680] [client 174.129.182.173:18612] [client 174.129.182.173] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZAu-VYyXRoT8g9-3YgcwAAAYQ"]
[Sun Jul 26 19:33:04.740285 2026] [:error] [pid 27305:tid 140140731123456] [client 35.172.91.99:12041] [client 35.172.91.99] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZE0OVYyXRoT8g9-3Ym-wAAAZE"]
[Sun Jul 26 19:33:04.742851 2026] [:error] [pid 27305:tid 140140731123456] [client 35.172.91.99:12041] [client 35.172.91.99] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZE0OVYyXRoT8g9-3Ym-wAAAZE"]
[Sun Jul 26 19:50:48.949971 2026] [:error] [pid 24270:tid 140140697552640] [client 43.157.53.115:51494] [client 43.157.53.115] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amZI-O_7ME10GwCFyrjTdwAAAJU"]
[Sun Jul 26 19:50:48.952395 2026] [:error] [pid 24270:tid 140140697552640] [client 43.157.53.115:51494] [client 43.157.53.115] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amZI-O_7ME10GwCFyrjTdwAAAJU"]
[Sun Jul 26 19:50:48.952666 2026] [:error] [pid 24270:tid 140140697552640] [client 43.157.53.115:51494] [client 43.157.53.115] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amZI-O_7ME10GwCFyrjTdwAAAJU"]
[Sun Jul 26 19:51:51.688496 2026] [:error] [pid 24317:tid 140140941002496] [client 158.101.144.198:6724] [client 158.101.144.198] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amZJNz5dN7w6fiFxIZbXogAAAMA"]
[Sun Jul 26 19:51:51.689168 2026] [:error] [pid 24317:tid 140140941002496] [client 158.101.144.198:6724] [client 158.101.144.198] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amZJNz5dN7w6fiFxIZbXogAAAMA"]
[Sun Jul 26 19:51:51.689531 2026] [:error] [pid 24317:tid 140140941002496] [client 158.101.144.198:6724] [client 158.101.144.198] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amZJNz5dN7w6fiFxIZbXogAAAMA"]
[Sun Jul 26 20:45:24.309841 2026] [:error] [pid 24270:tid 140140697552640] [client 158.101.144.198:12656] [client 158.101.144.198] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amZVxO_7ME10GwCFyrj21gAAAJU"]
[Sun Jul 26 20:45:24.315275 2026] [:error] [pid 24270:tid 140140697552640] [client 158.101.144.198:12656] [client 158.101.144.198] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amZVxO_7ME10GwCFyrj21gAAAJU"]
[Sun Jul 26 20:45:24.315701 2026] [:error] [pid 24270:tid 140140697552640] [client 158.101.144.198:12656] [client 158.101.144.198] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amZVxO_7ME10GwCFyrj21gAAAJU"]
[Sun Jul 26 20:45:24.315915 2026] [:error] [pid 24270:tid 140140697552640] [client 158.101.144.198:12656] [client 158.101.144.198] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amZVxO_7ME10GwCFyrj21gAAAJU"]
[Sun Jul 26 20:47:14.837355 2026] [:error] [pid 24176:tid 140140924217088] [client 195.178.110.211:46232] [client 195.178.110.211] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "amZWMh8_aWcKKoEpOWSVbQAAAEI"]
[Sun Jul 26 20:47:14.838434 2026] [:error] [pid 24176:tid 140140924217088] [client 195.178.110.211:46232] [client 195.178.110.211] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "amZWMh8_aWcKKoEpOWSVbQAAAEI"]
[Sun Jul 26 20:47:14.838854 2026] [:error] [pid 24176:tid 140140924217088] [client 195.178.110.211:46232] [client 195.178.110.211] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "amZWMh8_aWcKKoEpOWSVbQAAAEI"]
[Sun Jul 26 20:51:57.062733 2026] [:error] [pid 24270:tid 140140739516160] [client 104.23.221.25:9237] [client 104.23.221.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amZXTe_7ME10GwCFyrj6igAAAJA"]
[Sun Jul 26 20:51:57.063653 2026] [:error] [pid 24270:tid 140140739516160] [client 104.23.221.25:9237] [client 104.23.221.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amZXTe_7ME10GwCFyrj6igAAAJA"]
[Sun Jul 26 20:51:57.064139 2026] [:error] [pid 24270:tid 140140739516160] [client 104.23.221.25:9237] [client 104.23.221.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amZXTe_7ME10GwCFyrj6igAAAJA"]
[Sun Jul 26 21:28:16.647807 2026] [:error] [pid 24317:tid 140140731123456] [client 146.190.33.220:45198] [client 146.190.33.220] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZf0D5dN7w6fiFxIZYgsQAAANE"]
[Sun Jul 26 21:28:16.648740 2026] [:error] [pid 24317:tid 140140731123456] [client 146.190.33.220:45198] [client 146.190.33.220] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZf0D5dN7w6fiFxIZYgsQAAANE"]
[Sun Jul 26 21:28:16.949013 2026] [:error] [pid 24317:tid 140140697552640] [client 146.190.33.220:45206] [client 146.190.33.220] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amZf0D5dN7w6fiFxIZYgsgAAANU"], referer: http://sbf-consultancy.com/
[Sun Jul 26 21:28:16.949966 2026] [:error] [pid 24317:tid 140140697552640] [client 146.190.33.220:45206] [client 146.190.33.220] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amZf0D5dN7w6fiFxIZYgsgAAANU"], referer: http://sbf-consultancy.com/
[Sun Jul 26 21:28:17.556004 2026] [:error] [pid 24270:tid 140140689159936] [client 146.190.33.220:56980] [client 146.190.33.220] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZf0e_7ME10GwCFyrgSCgAAAJY"]
[Sun Jul 26 21:28:17.557006 2026] [:error] [pid 24270:tid 140140689159936] [client 146.190.33.220:56980] [client 146.190.33.220] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZf0e_7ME10GwCFyrgSCgAAAJY"]
[Sun Jul 26 21:28:21.163970 2026] [:error] [pid 22826:tid 140140722730752] [client 146.190.33.220:33956] [client 146.190.33.220] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amZf1SBv006Wr4aGC54HRAAAAdI"], referer: https://sbf-consultancy.com/
[Sun Jul 26 21:28:21.165104 2026] [:error] [pid 22826:tid 140140722730752] [client 146.190.33.220:33956] [client 146.190.33.220] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amZf1SBv006Wr4aGC54HRAAAAdI"], referer: https://sbf-consultancy.com/
[Sun Jul 26 21:47:19.459366 2026] [:error] [pid 24317:tid 140140739516160] [client 118.24.135.34:45126] [client 118.24.135.34] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZkRz5dN7w6fiFxIZYq7QAAANA"]
[Sun Jul 26 21:47:19.462971 2026] [:error] [pid 24317:tid 140140739516160] [client 118.24.135.34:45126] [client 118.24.135.34] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZkRz5dN7w6fiFxIZYq7QAAANA"]
[Sun Jul 26 21:47:19.463210 2026] [:error] [pid 24317:tid 140140739516160] [client 118.24.135.34:45126] [client 118.24.135.34] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZkRz5dN7w6fiFxIZYq7QAAANA"]
[Sun Jul 26 22:15:06.437249 2026] [:error] [pid 24270:tid 140140773086976] [client 44.227.127.2:1331] [client 44.227.127.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZqyu_7ME10GwCFyrgtpAAAAIw"]
[Sun Jul 26 22:15:06.438308 2026] [:error] [pid 24270:tid 140140773086976] [client 44.227.127.2:1331] [client 44.227.127.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZqyu_7ME10GwCFyrgtpAAAAIw"]
[Sun Jul 26 22:15:06.438638 2026] [:error] [pid 24270:tid 140140773086976] [client 44.227.127.2:1331] [client 44.227.127.2] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZqyu_7ME10GwCFyrgtpAAAAIw"]
[Sun Jul 26 22:15:06.464850 2026] [:error] [pid 24317:tid 140140806657792] [client 44.227.127.2:58236] [client 44.227.127.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amZqyj5dN7w6fiFxIZZCFgAAAMg"]
[Sun Jul 26 22:15:06.465988 2026] [:error] [pid 24317:tid 140140806657792] [client 44.227.127.2:58236] [client 44.227.127.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amZqyj5dN7w6fiFxIZZCFgAAAMg"]
[Sun Jul 26 22:15:06.466343 2026] [:error] [pid 24317:tid 140140806657792] [client 44.227.127.2:58236] [client 44.227.127.2] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amZqyj5dN7w6fiFxIZZCFgAAAMg"]
[Sun Jul 26 22:15:07.002479 2026] [:error] [pid 24270:tid 140140722730752] [client 44.227.127.2:1118] [client 44.227.127.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZqy-_7ME10GwCFyrgtpQAAAJI"]
[Sun Jul 26 22:15:07.003202 2026] [:error] [pid 24270:tid 140140722730752] [client 44.227.127.2:1118] [client 44.227.127.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZqy-_7ME10GwCFyrgtpQAAAJI"]
[Sun Jul 26 22:15:07.003647 2026] [:error] [pid 24270:tid 140140722730752] [client 44.227.127.2:1118] [client 44.227.127.2] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZqy-_7ME10GwCFyrgtpQAAAJI"]
[Sun Jul 26 22:43:26.110785 2026] [:error] [pid 22826:tid 140140907431680] [client 185.149.26.183:59287] [client 185.149.26.183] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZxbiBv006Wr4aGC54LzwAAAcQ"]
[Sun Jul 26 22:43:26.114747 2026] [:error] [pid 22826:tid 140140907431680] [client 185.149.26.183:59287] [client 185.149.26.183] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZxbiBv006Wr4aGC54LzwAAAcQ"]
[Sun Jul 26 22:43:26.115338 2026] [:error] [pid 22826:tid 140140907431680] [client 185.149.26.183:59287] [client 185.149.26.183] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZxbiBv006Wr4aGC54LzwAAAcQ"]
[Sun Jul 26 22:45:49.281671 2026] [:error] [pid 24317:tid 140140932609792] [client 45.131.193.125:54119] [client 45.131.193.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amZx_T5dN7w6fiFxIZZR-wAAAME"]
[Sun Jul 26 22:45:49.282458 2026] [:error] [pid 24317:tid 140140932609792] [client 45.131.193.125:54119] [client 45.131.193.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amZx_T5dN7w6fiFxIZZR-wAAAME"]
[Sun Jul 26 22:45:49.810178 2026] [:error] [pid 24317:tid 140140705945344] [client 45.131.193.125:54119] [client 45.131.193.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/"] [unique_id "amZx_T5dN7w6fiFxIZZR_AAAANQ"]
[Sun Jul 26 22:45:49.811212 2026] [:error] [pid 24317:tid 140140705945344] [client 45.131.193.125:54119] [client 45.131.193.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/"] [unique_id "amZx_T5dN7w6fiFxIZZR_AAAANQ"]
[Sun Jul 26 22:45:50.496800 2026] [:error] [pid 24317:tid 140140789872384] [client 45.131.193.125:54119] [client 45.131.193.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZx_j5dN7w6fiFxIZZR_QAAAMo"]
[Sun Jul 26 22:45:50.497724 2026] [:error] [pid 24317:tid 140140789872384] [client 45.131.193.125:54119] [client 45.131.193.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZx_j5dN7w6fiFxIZZR_QAAAMo"]
[Sun Jul 26 22:45:50.902426 2026] [:error] [pid 24317:tid 140140689159936] [client 45.131.193.125:54119] [client 45.131.193.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZx_j5dN7w6fiFxIZZR_gAAANY"]
[Sun Jul 26 22:45:50.903162 2026] [:error] [pid 24317:tid 140140689159936] [client 45.131.193.125:54119] [client 45.131.193.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZx_j5dN7w6fiFxIZZR_gAAANY"]
[Sun Jul 26 22:45:50.903482 2026] [:error] [pid 24317:tid 140140689159936] [client 45.131.193.125:54119] [client 45.131.193.125] ModSecurity: Warning. Found 3 byte(s) in ARGS:rest_route outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:rest_route=/wp/v2/users"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZx_j5dN7w6fiFxIZZR_gAAANY"]
[Sun Jul 26 22:45:51.285926 2026] [:error] [pid 24317:tid 140140697552640] [client 45.131.193.125:54119] [client 45.131.193.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/feed"] [unique_id "amZx_z5dN7w6fiFxIZZR_wAAANU"]
[Sun Jul 26 22:45:51.286763 2026] [:error] [pid 24317:tid 140140697552640] [client 45.131.193.125:54119] [client 45.131.193.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/feed"] [unique_id "amZx_z5dN7w6fiFxIZZR_wAAANU"]
[Sun Jul 26 22:47:00.323414 2026] [:error] [pid 24270:tid 140140907431680] [client 104.23.221.24:11408] [client 104.23.221.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amZyRO_7ME10GwCFyrhD5QAAAIQ"]
[Sun Jul 26 22:47:00.325078 2026] [:error] [pid 24270:tid 140140907431680] [client 104.23.221.24:11408] [client 104.23.221.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amZyRO_7ME10GwCFyrhD5QAAAIQ"]
[Sun Jul 26 22:47:00.326301 2026] [:error] [pid 24270:tid 140140907431680] [client 104.23.221.24:11408] [client 104.23.221.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amZyRO_7ME10GwCFyrhD5QAAAIQ"]
[Sun Jul 26 23:15:10.499799 2026] [:error] [pid 24317:tid 140140781479680] [client 51.68.111.215:29937] [client 51.68.111.215] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amZ43j5dN7w6fiFxIZZkgwAAAMs"]
[Sun Jul 26 23:15:10.500842 2026] [:error] [pid 24317:tid 140140781479680] [client 51.68.111.215:29937] [client 51.68.111.215] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amZ43j5dN7w6fiFxIZZkgwAAAMs"]
[Sun Jul 26 23:15:10.501048 2026] [:error] [pid 24317:tid 140140781479680] [client 51.68.111.215:29937] [client 51.68.111.215] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "176"] [id "913102"] [msg "Found User-Agent associated with web crawler/bot"] [data "Matched Data: MJ12bot found within REQUEST_HEADERS:User-Agent: mozilla/5.0 (compatible; mj12bot/v2.0.5; http://mj12bot.com/)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-crawler"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amZ43j5dN7w6fiFxIZZkgwAAAMs"]
[Sun Jul 26 23:15:10.749974 2026] [:error] [pid 24317:tid 140140924217088] [client 51.68.111.215:29937] [client 51.68.111.215] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZ43j5dN7w6fiFxIZZkhAAAAMI"]
[Sun Jul 26 23:15:10.750860 2026] [:error] [pid 24317:tid 140140924217088] [client 51.68.111.215:29937] [client 51.68.111.215] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZ43j5dN7w6fiFxIZZkhAAAAMI"]
[Sun Jul 26 23:15:10.751055 2026] [:error] [pid 24317:tid 140140924217088] [client 51.68.111.215:29937] [client 51.68.111.215] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "176"] [id "913102"] [msg "Found User-Agent associated with web crawler/bot"] [data "Matched Data: MJ12bot found within REQUEST_HEADERS:User-Agent: mozilla/5.0 (compatible; mj12bot/v2.0.5; http://mj12bot.com/)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-crawler"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amZ43j5dN7w6fiFxIZZkhAAAAMI"]
[Sun Jul 26 23:54:26.095726 2026] [:error] [pid 24317:tid 140140731123456] [client 3.217.141.132:49333] [client 3.217.141.132] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amaCEj5dN7w6fiFxIZZ8CgAAANE"]
[Sun Jul 26 23:54:26.099144 2026] [:error] [pid 24317:tid 140140731123456] [client 3.217.141.132:49333] [client 3.217.141.132] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amaCEj5dN7w6fiFxIZZ8CgAAANE"]
[Mon Jul 27 00:32:21.338524 2026] [:error] [pid 24317:tid 140140773086976] [client 104.23.223.54:12508] [client 104.23.223.54] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amaK9T5dN7w6fiFxIZaSGgAAAMw"]
[Mon Jul 27 00:32:21.340163 2026] [:error] [pid 24317:tid 140140773086976] [client 104.23.223.54:12508] [client 104.23.223.54] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amaK9T5dN7w6fiFxIZaSGgAAAMw"]
[Mon Jul 27 00:32:21.340991 2026] [:error] [pid 24317:tid 140140773086976] [client 104.23.223.54:12508] [client 104.23.223.54] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amaK9T5dN7w6fiFxIZaSGgAAAMw"]
[Mon Jul 27 00:39:33.646187 2026] [:error] [pid 24317:tid 140140823443200] [client 158.101.144.198:40878] [client 158.101.144.198] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amaMpT5dN7w6fiFxIZaVzAAAAMY"]
[Mon Jul 27 00:39:33.652411 2026] [:error] [pid 24317:tid 140140823443200] [client 158.101.144.198:40878] [client 158.101.144.198] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amaMpT5dN7w6fiFxIZaVzAAAAMY"]
[Mon Jul 27 00:39:33.653036 2026] [:error] [pid 24317:tid 140140823443200] [client 158.101.144.198:40878] [client 158.101.144.198] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amaMpT5dN7w6fiFxIZaVzAAAAMY"]
[Mon Jul 27 00:41:45.774321 2026] [:error] [pid 24270:tid 140140697552640] [client 43.153.135.208:36552] [client 43.153.135.208] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amaNKe_7ME10GwCFyriGawAAAJU"]
[Mon Jul 27 00:41:45.775117 2026] [:error] [pid 24270:tid 140140697552640] [client 43.153.135.208:36552] [client 43.153.135.208] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amaNKe_7ME10GwCFyriGawAAAJU"]
[Mon Jul 27 00:41:45.775274 2026] [:error] [pid 24270:tid 140140697552640] [client 43.153.135.208:36552] [client 43.153.135.208] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amaNKe_7ME10GwCFyriGawAAAJU"]
[Mon Jul 27 01:31:45.960514 2026] [:error] [pid 17806:tid 140140899038976] [client 43.164.129.191:56030] [client 43.164.129.191] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amaY4bwMqkMtFBesmbS2lQAAAEU"]
[Mon Jul 27 01:31:45.961517 2026] [:error] [pid 17806:tid 140140899038976] [client 43.164.129.191:56030] [client 43.164.129.191] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amaY4bwMqkMtFBesmbS2lQAAAEU"]
[Mon Jul 27 01:31:45.961765 2026] [:error] [pid 17806:tid 140140899038976] [client 43.164.129.191:56030] [client 43.164.129.191] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amaY4bwMqkMtFBesmbS2lQAAAEU"]
[Mon Jul 27 01:37:26.810986 2026] [:error] [pid 14207:tid 140140705945344] [client 146.70.40.70:45296] [client 146.70.40.70] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amaaNkFaZuGiuwt-1fWmRgAAAZQ"]
[Mon Jul 27 01:37:26.817895 2026] [:error] [pid 14207:tid 140140705945344] [client 146.70.40.70:45296] [client 146.70.40.70] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amaaNkFaZuGiuwt-1fWmRgAAAZQ"]
[Mon Jul 27 02:15:58.703042 2026] [:error] [pid 17806:tid 140140823443200] [client 104.23.221.25:9998] [client 104.23.221.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amajPrwMqkMtFBesmbTfaQAAAEY"]
[Mon Jul 27 02:15:58.704323 2026] [:error] [pid 17806:tid 140140823443200] [client 104.23.221.25:9998] [client 104.23.221.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amajPrwMqkMtFBesmbTfaQAAAEY"]
[Mon Jul 27 02:15:58.705109 2026] [:error] [pid 17806:tid 140140823443200] [client 104.23.221.25:9998] [client 104.23.221.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amajPrwMqkMtFBesmbTfaQAAAEY"]
[Mon Jul 27 03:43:27.081416 2026] [:error] [pid 29656:tid 139882831759104] [client 43.136.86.241:57532] [client 43.136.86.241] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ama3vxNBlZJMpEeDP4T39gAAAIw"]
[Mon Jul 27 03:43:27.087536 2026] [:error] [pid 29656:tid 139882831759104] [client 43.136.86.241:57532] [client 43.136.86.241] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ama3vxNBlZJMpEeDP4T39gAAAIw"]
[Mon Jul 27 03:43:27.087823 2026] [:error] [pid 29656:tid 139882831759104] [client 43.136.86.241:57532] [client 43.136.86.241] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ama3vxNBlZJMpEeDP4T39gAAAIw"]
[Mon Jul 27 04:01:30.062289 2026] [:error] [pid 3225:tid 139883004442368] [client 172.69.151.108:9862] [client 172.69.151.108] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ama7-vpF_23cxQHPG_rZvgAAAQA"]
[Mon Jul 27 04:01:30.063009 2026] [:error] [pid 3225:tid 139883004442368] [client 172.69.151.108:9862] [client 172.69.151.108] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ama7-vpF_23cxQHPG_rZvgAAAQA"]
[Mon Jul 27 04:01:30.063479 2026] [:error] [pid 3225:tid 139883004442368] [client 172.69.151.108:9862] [client 172.69.151.108] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ama7-vpF_23cxQHPG_rZvgAAAQA"]
[Mon Jul 27 04:55:00.538855 2026] [:error] [pid 3225:tid 139882915686144] [client 43.130.9.111:39710] [client 43.130.9.111] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ambIhPpF_23cxQHPG_oxbQAAAQI"]
[Mon Jul 27 04:55:00.541095 2026] [:error] [pid 3225:tid 139882915686144] [client 43.130.9.111:39710] [client 43.130.9.111] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ambIhPpF_23cxQHPG_oxbQAAAQI"]
[Mon Jul 27 04:55:00.541296 2026] [:error] [pid 3225:tid 139882915686144] [client 43.130.9.111:39710] [client 43.130.9.111] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ambIhPpF_23cxQHPG_oxbQAAAQI"]
[Mon Jul 27 05:36:08.144182 2026] [:error] [pid 29653:tid 139882798188288] [client 172.213.144.209:58212] [client 172.213.144.209] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ambSKMUGpVonhG_FWwzFhQAAAFA"]
[Mon Jul 27 05:36:08.151311 2026] [:error] [pid 29653:tid 139882798188288] [client 172.213.144.209:58212] [client 172.213.144.209] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ambSKMUGpVonhG_FWwzFhQAAAFA"]
[Mon Jul 27 05:36:08.151671 2026] [:error] [pid 29653:tid 139882798188288] [client 172.213.144.209:58212] [client 172.213.144.209] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ambSKMUGpVonhG_FWwzFhQAAAFA"]
[Mon Jul 27 05:48:01.746690 2026] [:error] [pid 29656:tid 139882823366400] [client 162.158.111.4:10748] [client 162.158.111.4] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ambU8RNBlZJMpEeDP4QdtAAAAI0"]
[Mon Jul 27 05:48:01.747813 2026] [:error] [pid 29656:tid 139882823366400] [client 162.158.111.4:10748] [client 162.158.111.4] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ambU8RNBlZJMpEeDP4QdtAAAAI0"]
[Mon Jul 27 05:48:01.748464 2026] [:error] [pid 29656:tid 139882823366400] [client 162.158.111.4:10748] [client 162.158.111.4] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ambU8RNBlZJMpEeDP4QdtAAAAI0"]
[Mon Jul 27 05:53:03.743540 2026] [:error] [pid 30240:tid 139882882115328] [client 43.164.190.28:49648] [client 43.164.190.28] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ambWH1GLgQ2_BkHSpAxixgAAAMY"]
[Mon Jul 27 05:53:03.744376 2026] [:error] [pid 30240:tid 139882882115328] [client 43.164.190.28:49648] [client 43.164.190.28] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ambWH1GLgQ2_BkHSpAxixgAAAMY"]
[Mon Jul 27 05:53:03.744594 2026] [:error] [pid 30240:tid 139882882115328] [client 43.164.190.28:49648] [client 43.164.190.28] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ambWH1GLgQ2_BkHSpAxixgAAAMY"]
[Mon Jul 27 06:11:52.850262 2026] [:error] [pid 12275:tid 140706827896576] [client 169.155.232.191:26621] [client 169.155.232.191] ModSecurity: Warning. Match of "rx ^%{tx.allowed_request_content_type_charset}$" against "TX:1" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "983"] [id "920480"] [msg "Request content type charset is not allowed by policy"] [data "utf-8"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "ambaiHFwI8r7BFXGkAsUAwAAABg"]
[Mon Jul 27 06:11:52.850478 2026] [:error] [pid 12275:tid 140706827896576] [client 169.155.232.191:26621] [client 169.155.232.191] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "ambaiHFwI8r7BFXGkAsUAwAAABg"]
[Mon Jul 27 06:11:52.856247 2026] [:error] [pid 12275:tid 140706827896576] [client 169.155.232.191:26621] [client 169.155.232.191] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "ambaiHFwI8r7BFXGkAsUAwAAABg"]
[Mon Jul 27 06:11:52.856622 2026] [:error] [pid 12275:tid 140706827896576] [client 169.155.232.191:26621] [client 169.155.232.191] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|text/xml|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "ambaiHFwI8r7BFXGkAsUAwAAABg"]
[Mon Jul 27 06:11:52.856915 2026] [:error] [pid 12275:tid 140706827896576] [client 169.155.232.191:26621] [client 169.155.232.191] ModSecurity: Warning. Found 177 byte(s) in REQUEST_BODY outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "REQUEST_BODY=<?xml version=\\x221.0\\x22?><methodCall><methodName>metaWeblog.newPost</methodName><params><param><value><string>1</string></value></param><param><value><string>36643</string></value></param><param><value><string>36643</string></value></param><param><value><struct><member><name>title</name><value><string>0xaf09a47e</string></value></member><member><name>description</name><value><string>0xaf09a47e</string></value></member><member><name>mt_keywords</name><value><string>0xaf09a47e</string></valu..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "ambaiHFwI8r7BFXGkAsUAwAAABg"]
[Mon Jul 27 06:19:55.328086 2026] [:error] [pid 12276:tid 140706836289280] [client 94.154.43.188:29062] [client 94.154.43.188] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ambca-csEMuHmMYmk65hpgAAAFc"]
[Mon Jul 27 06:19:55.329131 2026] [:error] [pid 12276:tid 140706836289280] [client 94.154.43.188:29062] [client 94.154.43.188] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ambca-csEMuHmMYmk65hpgAAAFc"]
[Mon Jul 27 06:19:55.329587 2026] [:error] [pid 12276:tid 140706836289280] [client 94.154.43.188:29062] [client 94.154.43.188] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ambca-csEMuHmMYmk65hpgAAAFc"]
[Mon Jul 27 06:49:07.706528 2026] [:error] [pid 12380:tid 140706970572544] [client 4.204.201.85:13742] [client 4.204.201.85] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ambjQ6aChfbWW0CZ_hqVMwAAAMc"]
[Mon Jul 27 06:49:07.709750 2026] [:error] [pid 12380:tid 140706970572544] [client 4.204.201.85:13742] [client 4.204.201.85] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ambjQ6aChfbWW0CZ_hqVMwAAAMc"]
[Mon Jul 27 06:49:07.710059 2026] [:error] [pid 12380:tid 140706970572544] [client 4.204.201.85:13742] [client 4.204.201.85] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ambjQ6aChfbWW0CZ_hqVMwAAAMc"]
[Mon Jul 27 06:58:32.725722 2026] [:error] [pid 12380:tid 140707020928768] [client 173.252.69.4:39162] [client 173.252.69.4] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ambleKaChfbWW0CZ_hqf9AAAAME"]
[Mon Jul 27 06:58:32.726788 2026] [:error] [pid 12380:tid 140707020928768] [client 173.252.69.4:39162] [client 173.252.69.4] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ambleKaChfbWW0CZ_hqf9AAAAME"]
[Mon Jul 27 06:58:33.585571 2026] [:error] [pid 12380:tid 140706911823616] [client 173.252.69.1:47942] [client 173.252.69.1] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ambleaaChfbWW0CZ_hqf-QAAAM4"]
[Mon Jul 27 06:58:33.586323 2026] [:error] [pid 12380:tid 140706911823616] [client 173.252.69.1:47942] [client 173.252.69.1] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ambleaaChfbWW0CZ_hqf-QAAAM4"]
[Mon Jul 27 06:58:33.696020 2026] [:error] [pid 12275:tid 140707020928768] [client 173.252.69.13:42786] [client 173.252.69.13] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ambleXFwI8r7BFXGkAsu1gAAAAE"]
[Mon Jul 27 06:58:33.697482 2026] [:error] [pid 12275:tid 140707020928768] [client 173.252.69.13:42786] [client 173.252.69.13] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ambleXFwI8r7BFXGkAsu1gAAAAE"]
[Mon Jul 27 06:58:35.186199 2026] [:error] [pid 12275:tid 140706978965248] [client 57.141.0.55:47240] [client 57.141.0.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amble3FwI8r7BFXGkAsu2gAAAAY"]
[Mon Jul 27 06:58:35.187176 2026] [:error] [pid 12275:tid 140706978965248] [client 57.141.0.55:47240] [client 57.141.0.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amble3FwI8r7BFXGkAsu2gAAAAY"]
[Mon Jul 27 07:35:11.881722 2026] [:error] [pid 12275:tid 140706928609024] [client 172.70.247.125:13638] [client 172.70.247.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ambuD3FwI8r7BFXGkAtDKgAAAAw"]
[Mon Jul 27 07:35:11.889486 2026] [:error] [pid 12275:tid 140706928609024] [client 172.70.247.125:13638] [client 172.70.247.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ambuD3FwI8r7BFXGkAtDKgAAAAw"]
[Mon Jul 27 07:35:11.890224 2026] [:error] [pid 12275:tid 140706928609024] [client 172.70.247.125:13638] [client 172.70.247.125] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ambuD3FwI8r7BFXGkAtDKgAAAAw"]
[Mon Jul 27 07:40:07.793876 2026] [:error] [pid 12275:tid 140706878252800] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ambvN3FwI8r7BFXGkAtGVgAAABI"]
[Mon Jul 27 07:40:07.794728 2026] [:error] [pid 12275:tid 140706878252800] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ambvN3FwI8r7BFXGkAtGVgAAABI"]
[Mon Jul 27 07:40:07.795015 2026] [:error] [pid 12275:tid 140706878252800] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ambvN3FwI8r7BFXGkAtGVgAAABI"]
[Mon Jul 27 07:40:08.270153 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "ambvOHFwI8r7BFXGkAtGVwAAABM"]
[Mon Jul 27 07:40:08.270818 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "ambvOHFwI8r7BFXGkAtGVwAAABM"]
[Mon Jul 27 07:40:08.271112 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "ambvOHFwI8r7BFXGkAtGVwAAABM"]
[Mon Jul 27 07:40:08.394484 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/lp6.php"] [unique_id "ambvOHFwI8r7BFXGkAtGWAAAAAU"]
[Mon Jul 27 07:40:08.395520 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/lp6.php"] [unique_id "ambvOHFwI8r7BFXGkAtGWAAAAAU"]
[Mon Jul 27 07:40:08.395813 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/lp6.php"] [unique_id "ambvOHFwI8r7BFXGkAtGWAAAAAU"]
[Mon Jul 27 07:40:08.546825 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/clasa99.php"] [unique_id "ambvOHFwI8r7BFXGkAtGWQAAAAk"]
[Mon Jul 27 07:40:08.547636 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/clasa99.php"] [unique_id "ambvOHFwI8r7BFXGkAtGWQAAAAk"]
[Mon Jul 27 07:40:08.547876 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/clasa99.php"] [unique_id "ambvOHFwI8r7BFXGkAtGWQAAAAk"]
[Mon Jul 27 07:40:08.671789 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ph33w.php"] [unique_id "ambvOHFwI8r7BFXGkAtGWgAAABU"]
[Mon Jul 27 07:40:08.672455 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ph33w.php"] [unique_id "ambvOHFwI8r7BFXGkAtGWgAAABU"]
[Mon Jul 27 07:40:08.672689 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ph33w.php"] [unique_id "ambvOHFwI8r7BFXGkAtGWgAAABU"]
[Mon Jul 27 07:40:08.793920 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/errw.php"] [unique_id "ambvOHFwI8r7BFXGkAtGWwAAAAc"]
[Mon Jul 27 07:40:08.794947 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/errw.php"] [unique_id "ambvOHFwI8r7BFXGkAtGWwAAAAc"]
[Mon Jul 27 07:40:08.795303 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/errw.php"] [unique_id "ambvOHFwI8r7BFXGkAtGWwAAAAc"]
[Mon Jul 27 07:40:08.932149 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/assacc.php"] [unique_id "ambvOHFwI8r7BFXGkAtGXQAAAAE"]
[Mon Jul 27 07:40:08.933040 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/assacc.php"] [unique_id "ambvOHFwI8r7BFXGkAtGXQAAAAE"]
[Mon Jul 27 07:40:08.933315 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/assacc.php"] [unique_id "ambvOHFwI8r7BFXGkAtGXQAAAAE"]
[Mon Jul 27 07:40:09.056585 2026] [:error] [pid 12275:tid 140706928609024] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/Geforce.php"] [unique_id "ambvOXFwI8r7BFXGkAtGXwAAAAw"]
[Mon Jul 27 07:40:09.057399 2026] [:error] [pid 12275:tid 140706928609024] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/Geforce.php"] [unique_id "ambvOXFwI8r7BFXGkAtGXwAAAAw"]
[Mon Jul 27 07:40:09.057690 2026] [:error] [pid 12275:tid 140706928609024] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/Geforce.php"] [unique_id "ambvOXFwI8r7BFXGkAtGXwAAAAw"]
[Mon Jul 27 07:40:09.184449 2026] [:error] [pid 12275:tid 140706962179840] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cs.php"] [unique_id "ambvOXFwI8r7BFXGkAtGYAAAAAg"]
[Mon Jul 27 07:40:09.185373 2026] [:error] [pid 12275:tid 140706962179840] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cs.php"] [unique_id "ambvOXFwI8r7BFXGkAtGYAAAAAg"]
[Mon Jul 27 07:40:09.185661 2026] [:error] [pid 12275:tid 140706962179840] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/cs.php"] [unique_id "ambvOXFwI8r7BFXGkAtGYAAAAAg"]
[Mon Jul 27 07:40:09.347936 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gettest.php"] [unique_id "ambvOXFwI8r7BFXGkAtGYQAAABE"]
[Mon Jul 27 07:40:09.348839 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gettest.php"] [unique_id "ambvOXFwI8r7BFXGkAtGYQAAABE"]
[Mon Jul 27 07:40:09.349096 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/gettest.php"] [unique_id "ambvOXFwI8r7BFXGkAtGYQAAABE"]
[Mon Jul 27 07:40:09.478793 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cv.php"] [unique_id "ambvOXFwI8r7BFXGkAtGYgAAABQ"]
[Mon Jul 27 07:40:09.479746 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cv.php"] [unique_id "ambvOXFwI8r7BFXGkAtGYgAAABQ"]
[Mon Jul 27 07:40:09.480033 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/cv.php"] [unique_id "ambvOXFwI8r7BFXGkAtGYgAAABQ"]
[Mon Jul 27 07:40:09.603657 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ma.php"] [unique_id "ambvOXFwI8r7BFXGkAtGYwAAAAI"]
[Mon Jul 27 07:40:09.604281 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ma.php"] [unique_id "ambvOXFwI8r7BFXGkAtGYwAAAAI"]
[Mon Jul 27 07:40:09.604501 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ma.php"] [unique_id "ambvOXFwI8r7BFXGkAtGYwAAAAI"]
[Mon Jul 27 07:40:09.728660 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ole.php"] [unique_id "ambvOXFwI8r7BFXGkAtGZAAAAAM"]
[Mon Jul 27 07:40:09.729627 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ole.php"] [unique_id "ambvOXFwI8r7BFXGkAtGZAAAAAM"]
[Mon Jul 27 07:40:09.729895 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ole.php"] [unique_id "ambvOXFwI8r7BFXGkAtGZAAAAAM"]
[Mon Jul 27 07:40:09.850112 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/x_3.php"] [unique_id "ambvOXFwI8r7BFXGkAtGZQAAAAY"]
[Mon Jul 27 07:40:09.851082 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/x_3.php"] [unique_id "ambvOXFwI8r7BFXGkAtGZQAAAAY"]
[Mon Jul 27 07:40:09.851424 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/x_3.php"] [unique_id "ambvOXFwI8r7BFXGkAtGZQAAAAY"]
[Mon Jul 27 07:40:10.092319 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bolt.php"] [unique_id "ambvOnFwI8r7BFXGkAtGZgAAABc"]
[Mon Jul 27 07:40:10.093022 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bolt.php"] [unique_id "ambvOnFwI8r7BFXGkAtGZgAAABc"]
[Mon Jul 27 07:40:10.093267 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bolt.php"] [unique_id "ambvOnFwI8r7BFXGkAtGZgAAABc"]
[Mon Jul 27 07:40:10.214322 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/adminfuns.php"] [unique_id "ambvOnFwI8r7BFXGkAtGZwAAABg"]
[Mon Jul 27 07:40:10.215150 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/adminfuns.php"] [unique_id "ambvOnFwI8r7BFXGkAtGZwAAABg"]
[Mon Jul 27 07:40:10.215418 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/adminfuns.php"] [unique_id "ambvOnFwI8r7BFXGkAtGZwAAABg"]
[Mon Jul 27 07:40:10.334506 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mar.php"] [unique_id "ambvOnFwI8r7BFXGkAtGaAAAAAs"]
[Mon Jul 27 07:40:10.335288 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mar.php"] [unique_id "ambvOnFwI8r7BFXGkAtGaAAAAAs"]
[Mon Jul 27 07:40:10.335487 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/mar.php"] [unique_id "ambvOnFwI8r7BFXGkAtGaAAAAAs"]
[Mon Jul 27 07:40:10.454389 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ellv3.php"] [unique_id "ambvOnFwI8r7BFXGkAtGaQAAAA4"]
[Mon Jul 27 07:40:10.455461 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ellv3.php"] [unique_id "ambvOnFwI8r7BFXGkAtGaQAAAA4"]
[Mon Jul 27 07:40:10.455829 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ellv3.php"] [unique_id "ambvOnFwI8r7BFXGkAtGaQAAAA4"]
[Mon Jul 27 07:40:10.587355 2026] [:error] [pid 12275:tid 140706878252800] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ak.php"] [unique_id "ambvOnFwI8r7BFXGkAtGagAAABI"]
[Mon Jul 27 07:40:10.587976 2026] [:error] [pid 12275:tid 140706878252800] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ak.php"] [unique_id "ambvOnFwI8r7BFXGkAtGagAAABI"]
[Mon Jul 27 07:40:10.588178 2026] [:error] [pid 12275:tid 140706878252800] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ak.php"] [unique_id "ambvOnFwI8r7BFXGkAtGagAAABI"]
[Mon Jul 27 07:40:10.726722 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fetch.php"] [unique_id "ambvOnFwI8r7BFXGkAtGbAAAAA8"]
[Mon Jul 27 07:40:10.727623 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fetch.php"] [unique_id "ambvOnFwI8r7BFXGkAtGbAAAAA8"]
[Mon Jul 27 07:40:10.727867 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fetch.php"] [unique_id "ambvOnFwI8r7BFXGkAtGbAAAAA8"]
[Mon Jul 27 07:40:10.850136 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bk.php"] [unique_id "ambvOnFwI8r7BFXGkAtGbgAAABM"]
[Mon Jul 27 07:40:10.850836 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bk.php"] [unique_id "ambvOnFwI8r7BFXGkAtGbgAAABM"]
[Mon Jul 27 07:40:10.851078 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bk.php"] [unique_id "ambvOnFwI8r7BFXGkAtGbgAAABM"]
[Mon Jul 27 07:40:10.974767 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/configuration.php"] [unique_id "ambvOnFwI8r7BFXGkAtGbwAAAAU"]
[Mon Jul 27 07:40:10.975701 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/configuration.php"] [unique_id "ambvOnFwI8r7BFXGkAtGbwAAAAU"]
[Mon Jul 27 07:40:10.975968 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/configuration.php"] [unique_id "ambvOnFwI8r7BFXGkAtGbwAAAAU"]
[Mon Jul 27 07:40:11.096571 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ap.php"] [unique_id "ambvO3FwI8r7BFXGkAtGcAAAAAk"]
[Mon Jul 27 07:40:11.097433 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ap.php"] [unique_id "ambvO3FwI8r7BFXGkAtGcAAAAAk"]
[Mon Jul 27 07:40:11.097704 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ap.php"] [unique_id "ambvO3FwI8r7BFXGkAtGcAAAAAk"]
[Mon Jul 27 07:40:11.214252 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/f.php"] [unique_id "ambvO3FwI8r7BFXGkAtGcQAAABU"]
[Mon Jul 27 07:40:11.215232 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/f.php"] [unique_id "ambvO3FwI8r7BFXGkAtGcQAAABU"]
[Mon Jul 27 07:40:11.215640 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/f.php"] [unique_id "ambvO3FwI8r7BFXGkAtGcQAAABU"]
[Mon Jul 27 07:40:11.347089 2026] [:error] [pid 12275:tid 140706928609024] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/environment.php"] [unique_id "ambvO3FwI8r7BFXGkAtGcgAAAAw"]
[Mon Jul 27 07:40:11.347879 2026] [:error] [pid 12275:tid 140706928609024] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/environment.php"] [unique_id "ambvO3FwI8r7BFXGkAtGcgAAAAw"]
[Mon Jul 27 07:40:11.348130 2026] [:error] [pid 12275:tid 140706928609024] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/environment.php"] [unique_id "ambvO3FwI8r7BFXGkAtGcgAAAAw"]
[Mon Jul 27 07:40:11.475330 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/zaa.php"] [unique_id "ambvO3FwI8r7BFXGkAtGdAAAABE"]
[Mon Jul 27 07:40:11.476101 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/zaa.php"] [unique_id "ambvO3FwI8r7BFXGkAtGdAAAABE"]
[Mon Jul 27 07:40:11.476349 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/zaa.php"] [unique_id "ambvO3FwI8r7BFXGkAtGdAAAABE"]
[Mon Jul 27 07:40:11.595262 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mal.php"] [unique_id "ambvO3FwI8r7BFXGkAtGdwAAAAI"]
[Mon Jul 27 07:40:11.596055 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mal.php"] [unique_id "ambvO3FwI8r7BFXGkAtGdwAAAAI"]
[Mon Jul 27 07:40:11.596294 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/mal.php"] [unique_id "ambvO3FwI8r7BFXGkAtGdwAAAAI"]
[Mon Jul 27 07:40:11.713135 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ffd.php"] [unique_id "ambvO3FwI8r7BFXGkAtGeAAAAAM"]
[Mon Jul 27 07:40:11.713755 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ffd.php"] [unique_id "ambvO3FwI8r7BFXGkAtGeAAAAAM"]
[Mon Jul 27 07:40:11.713936 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ffd.php"] [unique_id "ambvO3FwI8r7BFXGkAtGeAAAAAM"]
[Mon Jul 27 07:40:11.831717 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/zwq13.php"] [unique_id "ambvO3FwI8r7BFXGkAtGeQAAAAY"]
[Mon Jul 27 07:40:11.832580 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/zwq13.php"] [unique_id "ambvO3FwI8r7BFXGkAtGeQAAAAY"]
[Mon Jul 27 07:40:11.832838 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/zwq13.php"] [unique_id "ambvO3FwI8r7BFXGkAtGeQAAAAY"]
[Mon Jul 27 07:40:11.965090 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wqqs.php"] [unique_id "ambvO3FwI8r7BFXGkAtGegAAAAs"]
[Mon Jul 27 07:40:11.965767 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wqqs.php"] [unique_id "ambvO3FwI8r7BFXGkAtGegAAAAs"]
[Mon Jul 27 07:40:11.966061 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wqqs.php"] [unique_id "ambvO3FwI8r7BFXGkAtGegAAAAs"]
[Mon Jul 27 07:40:12.083072 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp_wlx.php"] [unique_id "ambvPHFwI8r7BFXGkAtGewAAAA4"]
[Mon Jul 27 07:40:12.083812 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp_wlx.php"] [unique_id "ambvPHFwI8r7BFXGkAtGewAAAA4"]
[Mon Jul 27 07:40:12.084086 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp_wlx.php"] [unique_id "ambvPHFwI8r7BFXGkAtGewAAAA4"]
[Mon Jul 27 07:40:12.202171 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/100.kb.php"] [unique_id "ambvPHFwI8r7BFXGkAtGfQAAAA8"]
[Mon Jul 27 07:40:12.203248 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/100.kb.php"] [unique_id "ambvPHFwI8r7BFXGkAtGfQAAAA8"]
[Mon Jul 27 07:40:12.203504 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/100.kb.php"] [unique_id "ambvPHFwI8r7BFXGkAtGfQAAAA8"]
[Mon Jul 27 07:40:12.324220 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/vx.php"] [unique_id "ambvPHFwI8r7BFXGkAtGfgAAABY"]
[Mon Jul 27 07:40:12.325082 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/vx.php"] [unique_id "ambvPHFwI8r7BFXGkAtGfgAAABY"]
[Mon Jul 27 07:40:12.325348 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/vx.php"] [unique_id "ambvPHFwI8r7BFXGkAtGfgAAABY"]
[Mon Jul 27 07:40:12.446935 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/eetu.php"] [unique_id "ambvPHFwI8r7BFXGkAtGgAAAAAA"]
[Mon Jul 27 07:40:12.447996 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/eetu.php"] [unique_id "ambvPHFwI8r7BFXGkAtGgAAAAAA"]
[Mon Jul 27 07:40:12.448264 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/eetu.php"] [unique_id "ambvPHFwI8r7BFXGkAtGgAAAAAA"]
[Mon Jul 27 07:40:12.573583 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/lang/en.php"] [unique_id "ambvPHFwI8r7BFXGkAtGgQAAAAU"]
[Mon Jul 27 07:40:12.574508 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/lang/en.php"] [unique_id "ambvPHFwI8r7BFXGkAtGgQAAAAU"]
[Mon Jul 27 07:40:12.574818 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/lang/en.php"] [unique_id "ambvPHFwI8r7BFXGkAtGgQAAAAU"]
[Mon Jul 27 07:40:12.700429 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/01.php"] [unique_id "ambvPHFwI8r7BFXGkAtGgwAAAA0"]
[Mon Jul 27 07:40:12.701357 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/01.php"] [unique_id "ambvPHFwI8r7BFXGkAtGgwAAAA0"]
[Mon Jul 27 07:40:12.701629 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/01.php"] [unique_id "ambvPHFwI8r7BFXGkAtGgwAAAA0"]
[Mon Jul 27 07:40:12.824307 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sh.php"] [unique_id "ambvPHFwI8r7BFXGkAtGhAAAABU"]
[Mon Jul 27 07:40:12.824938 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sh.php"] [unique_id "ambvPHFwI8r7BFXGkAtGhAAAABU"]
[Mon Jul 27 07:40:12.825157 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sh.php"] [unique_id "ambvPHFwI8r7BFXGkAtGhAAAABU"]
[Mon Jul 27 07:40:12.961487 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/class.1.php"] [unique_id "ambvPHFwI8r7BFXGkAtGhQAAABQ"]
[Mon Jul 27 07:40:12.962686 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/class.1.php"] [unique_id "ambvPHFwI8r7BFXGkAtGhQAAABQ"]
[Mon Jul 27 07:40:12.963321 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/class.1.php"] [unique_id "ambvPHFwI8r7BFXGkAtGhQAAABQ"]
[Mon Jul 27 07:40:13.084932 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/0byte.php"] [unique_id "ambvPXFwI8r7BFXGkAtGhgAAAAQ"]
[Mon Jul 27 07:40:13.085844 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/0byte.php"] [unique_id "ambvPXFwI8r7BFXGkAtGhgAAAAQ"]
[Mon Jul 27 07:40:13.086136 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/0byte.php"] [unique_id "ambvPXFwI8r7BFXGkAtGhgAAAAQ"]
[Mon Jul 27 07:40:13.216012 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/se/name.php"] [unique_id "ambvPXFwI8r7BFXGkAtGhwAAAAM"]
[Mon Jul 27 07:40:13.216721 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/se/name.php"] [unique_id "ambvPXFwI8r7BFXGkAtGhwAAAAM"]
[Mon Jul 27 07:40:13.216913 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/se/name.php"] [unique_id "ambvPXFwI8r7BFXGkAtGhwAAAAM"]
[Mon Jul 27 07:40:13.349581 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/beence.php"] [unique_id "ambvPXFwI8r7BFXGkAtGiAAAABg"]
[Mon Jul 27 07:40:13.350507 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/beence.php"] [unique_id "ambvPXFwI8r7BFXGkAtGiAAAABg"]
[Mon Jul 27 07:40:13.350810 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/beence.php"] [unique_id "ambvPXFwI8r7BFXGkAtGiAAAABg"]
[Mon Jul 27 07:40:13.479085 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "ambvPXFwI8r7BFXGkAtGiQAAAA4"]
[Mon Jul 27 07:40:13.479821 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "ambvPXFwI8r7BFXGkAtGiQAAAA4"]
[Mon Jul 27 07:40:13.480117 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "ambvPXFwI8r7BFXGkAtGiQAAAA4"]
[Mon Jul 27 07:40:13.602117 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ws.php"] [unique_id "ambvPXFwI8r7BFXGkAtGigAAAA8"]
[Mon Jul 27 07:40:13.603252 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ws.php"] [unique_id "ambvPXFwI8r7BFXGkAtGigAAAA8"]
[Mon Jul 27 07:40:13.603487 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ws.php"] [unique_id "ambvPXFwI8r7BFXGkAtGigAAAA8"]
[Mon Jul 27 07:40:13.738768 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/zfe.php"] [unique_id "ambvPXFwI8r7BFXGkAtGiwAAAAA"]
[Mon Jul 27 07:40:13.739600 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/zfe.php"] [unique_id "ambvPXFwI8r7BFXGkAtGiwAAAAA"]
[Mon Jul 27 07:40:13.739804 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/zfe.php"] [unique_id "ambvPXFwI8r7BFXGkAtGiwAAAAA"]
[Mon Jul 27 07:40:13.880530 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/hello.php"] [unique_id "ambvPXFwI8r7BFXGkAtGjAAAAAU"]
[Mon Jul 27 07:40:13.881233 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/hello.php"] [unique_id "ambvPXFwI8r7BFXGkAtGjAAAAAU"]
[Mon Jul 27 07:40:13.881431 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/hello.php"] [unique_id "ambvPXFwI8r7BFXGkAtGjAAAAAU"]
[Mon Jul 27 07:40:14.014641 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/f6.php"] [unique_id "ambvPnFwI8r7BFXGkAtGjQAAAAk"]
[Mon Jul 27 07:40:14.015545 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/f6.php"] [unique_id "ambvPnFwI8r7BFXGkAtGjQAAAAk"]
[Mon Jul 27 07:40:14.015828 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/f6.php"] [unique_id "ambvPnFwI8r7BFXGkAtGjQAAAAk"]
[Mon Jul 27 07:40:14.137004 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-info.php"] [unique_id "ambvPnFwI8r7BFXGkAtGjwAAAA0"]
[Mon Jul 27 07:40:14.137903 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-info.php"] [unique_id "ambvPnFwI8r7BFXGkAtGjwAAAA0"]
[Mon Jul 27 07:40:14.138153 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-info.php"] [unique_id "ambvPnFwI8r7BFXGkAtGjwAAAA0"]
[Mon Jul 27 07:40:14.332492 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/elect.php"] [unique_id "ambvPnFwI8r7BFXGkAtGkgAAAAc"]
[Mon Jul 27 07:40:14.333282 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/elect.php"] [unique_id "ambvPnFwI8r7BFXGkAtGkgAAAAc"]
[Mon Jul 27 07:40:14.333488 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/elect.php"] [unique_id "ambvPnFwI8r7BFXGkAtGkgAAAAc"]
[Mon Jul 27 07:40:14.458128 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/shx.php"] [unique_id "ambvPnFwI8r7BFXGkAtGlAAAAAE"]
[Mon Jul 27 07:40:14.458954 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/shx.php"] [unique_id "ambvPnFwI8r7BFXGkAtGlAAAAAE"]
[Mon Jul 27 07:40:14.459189 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/shx.php"] [unique_id "ambvPnFwI8r7BFXGkAtGlAAAAAE"]
[Mon Jul 27 07:40:14.584284 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/new.php"] [unique_id "ambvPnFwI8r7BFXGkAtGlQAAABQ"]
[Mon Jul 27 07:40:14.585123 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/new.php"] [unique_id "ambvPnFwI8r7BFXGkAtGlQAAABQ"]
[Mon Jul 27 07:40:14.585358 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/new.php"] [unique_id "ambvPnFwI8r7BFXGkAtGlQAAABQ"]
[Mon Jul 27 07:40:14.723997 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ver.php"] [unique_id "ambvPnFwI8r7BFXGkAtGlgAAAAQ"]
[Mon Jul 27 07:40:14.724862 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ver.php"] [unique_id "ambvPnFwI8r7BFXGkAtGlgAAAAQ"]
[Mon Jul 27 07:40:14.725140 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ver.php"] [unique_id "ambvPnFwI8r7BFXGkAtGlgAAAAQ"]
[Mon Jul 27 07:40:14.842873 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/as.php"] [unique_id "ambvPnFwI8r7BFXGkAtGlwAAAAM"]
[Mon Jul 27 07:40:14.843953 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/as.php"] [unique_id "ambvPnFwI8r7BFXGkAtGlwAAAAM"]
[Mon Jul 27 07:40:14.844308 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/as.php"] [unique_id "ambvPnFwI8r7BFXGkAtGlwAAAAM"]
[Mon Jul 27 07:40:14.974473 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index_w.php"] [unique_id "ambvPnFwI8r7BFXGkAtGmAAAABA"]
[Mon Jul 27 07:40:14.975642 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index_w.php"] [unique_id "ambvPnFwI8r7BFXGkAtGmAAAABA"]
[Mon Jul 27 07:40:14.975968 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/index_w.php"] [unique_id "ambvPnFwI8r7BFXGkAtGmAAAABA"]
[Mon Jul 27 07:40:15.113846 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/c99.php"] [unique_id "ambvP3FwI8r7BFXGkAtGmgAAAAY"]
[Mon Jul 27 07:40:15.114800 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/c99.php"] [unique_id "ambvP3FwI8r7BFXGkAtGmgAAAAY"]
[Mon Jul 27 07:40:15.115148 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/c99.php"] [unique_id "ambvP3FwI8r7BFXGkAtGmgAAAAY"]
[Mon Jul 27 07:40:15.243527 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/a.php"] [unique_id "ambvP3FwI8r7BFXGkAtGmwAAABg"]
[Mon Jul 27 07:40:15.244418 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/a.php"] [unique_id "ambvP3FwI8r7BFXGkAtGmwAAABg"]
[Mon Jul 27 07:40:15.244704 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/a.php"] [unique_id "ambvP3FwI8r7BFXGkAtGmwAAABg"]
[Mon Jul 27 07:40:15.367310 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wso2.php"] [unique_id "ambvP3FwI8r7BFXGkAtGnAAAAAs"]
[Mon Jul 27 07:40:15.368186 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wso2.php"] [unique_id "ambvP3FwI8r7BFXGkAtGnAAAAAs"]
[Mon Jul 27 07:40:15.368466 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wso2.php"] [unique_id "ambvP3FwI8r7BFXGkAtGnAAAAAs"]
[Mon Jul 27 07:40:15.497797 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/small.php"] [unique_id "ambvP3FwI8r7BFXGkAtGnQAAAA4"]
[Mon Jul 27 07:40:15.498489 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/small.php"] [unique_id "ambvP3FwI8r7BFXGkAtGnQAAAA4"]
[Mon Jul 27 07:40:15.498740 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/small.php"] [unique_id "ambvP3FwI8r7BFXGkAtGnQAAAA4"]
[Mon Jul 27 07:40:15.632253 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sf.php"] [unique_id "ambvP3FwI8r7BFXGkAtGngAAAA8"]
[Mon Jul 27 07:40:15.632923 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sf.php"] [unique_id "ambvP3FwI8r7BFXGkAtGngAAAA8"]
[Mon Jul 27 07:40:15.633169 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sf.php"] [unique_id "ambvP3FwI8r7BFXGkAtGngAAAA8"]
[Mon Jul 27 07:40:15.761969 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/contact-demo.php"] [unique_id "ambvP3FwI8r7BFXGkAtGnwAAAAk"]
[Mon Jul 27 07:40:15.762997 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/contact-demo.php"] [unique_id "ambvP3FwI8r7BFXGkAtGnwAAAAk"]
[Mon Jul 27 07:40:15.763274 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/contact-demo.php"] [unique_id "ambvP3FwI8r7BFXGkAtGnwAAAAk"]
[Mon Jul 27 07:40:15.904803 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/luuf.php"] [unique_id "ambvP3FwI8r7BFXGkAtGoAAAABc"]
[Mon Jul 27 07:40:15.905446 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/luuf.php"] [unique_id "ambvP3FwI8r7BFXGkAtGoAAAABc"]
[Mon Jul 27 07:40:15.905705 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/luuf.php"] [unique_id "ambvP3FwI8r7BFXGkAtGoAAAABc"]
[Mon Jul 27 07:40:16.027654 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/reze.php"] [unique_id "ambvQHFwI8r7BFXGkAtGoQAAAA0"]
[Mon Jul 27 07:40:16.028731 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/reze.php"] [unique_id "ambvQHFwI8r7BFXGkAtGoQAAAA0"]
[Mon Jul 27 07:40:16.029151 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/reze.php"] [unique_id "ambvQHFwI8r7BFXGkAtGoQAAAA0"]
[Mon Jul 27 07:40:16.165637 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/license.php"] [unique_id "ambvQHFwI8r7BFXGkAtGpAAAABQ"]
[Mon Jul 27 07:40:16.166175 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/license.php"] [unique_id "ambvQHFwI8r7BFXGkAtGpAAAABQ"]
[Mon Jul 27 07:40:16.166361 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/license.php"] [unique_id "ambvQHFwI8r7BFXGkAtGpAAAABQ"]
[Mon Jul 27 07:40:16.316417 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ambvQHFwI8r7BFXGkAtGpgAAAAI"]
[Mon Jul 27 07:40:16.317290 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ambvQHFwI8r7BFXGkAtGpgAAAAI"]
[Mon Jul 27 07:40:16.317572 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ambvQHFwI8r7BFXGkAtGpgAAAAI"]
[Mon Jul 27 07:40:16.445306 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/contact-us.php"] [unique_id "ambvQHFwI8r7BFXGkAtGpwAAAAQ"]
[Mon Jul 27 07:40:16.446241 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/contact-us.php"] [unique_id "ambvQHFwI8r7BFXGkAtGpwAAAAQ"]
[Mon Jul 27 07:40:16.446511 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/contact-us.php"] [unique_id "ambvQHFwI8r7BFXGkAtGpwAAAAQ"]
[Mon Jul 27 07:40:16.569037 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/doc.php"] [unique_id "ambvQHFwI8r7BFXGkAtGqAAAABA"]
[Mon Jul 27 07:40:16.569662 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/doc.php"] [unique_id "ambvQHFwI8r7BFXGkAtGqAAAABA"]
[Mon Jul 27 07:40:16.569857 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/doc.php"] [unique_id "ambvQHFwI8r7BFXGkAtGqAAAABA"]
[Mon Jul 27 07:40:16.687110 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/X7x.php"] [unique_id "ambvQHFwI8r7BFXGkAtGqQAAAAY"]
[Mon Jul 27 07:40:16.688062 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/X7x.php"] [unique_id "ambvQHFwI8r7BFXGkAtGqQAAAAY"]
[Mon Jul 27 07:40:16.688317 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/X7x.php"] [unique_id "ambvQHFwI8r7BFXGkAtGqQAAAAY"]
[Mon Jul 27 07:40:16.825009 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/1975.php"] [unique_id "ambvQHFwI8r7BFXGkAtGqgAAABg"]
[Mon Jul 27 07:40:16.825660 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/1975.php"] [unique_id "ambvQHFwI8r7BFXGkAtGqgAAABg"]
[Mon Jul 27 07:40:16.825898 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/1975.php"] [unique_id "ambvQHFwI8r7BFXGkAtGqgAAABg"]
[Mon Jul 27 07:40:16.965441 2026] [:error] [pid 12275:tid 140706878252800] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/root.php"] [unique_id "ambvQHFwI8r7BFXGkAtGqwAAABI"]
[Mon Jul 27 07:40:16.966164 2026] [:error] [pid 12275:tid 140706878252800] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/root.php"] [unique_id "ambvQHFwI8r7BFXGkAtGqwAAABI"]
[Mon Jul 27 07:40:16.966371 2026] [:error] [pid 12275:tid 140706878252800] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/root.php"] [unique_id "ambvQHFwI8r7BFXGkAtGqwAAABI"]
[Mon Jul 27 07:40:17.088747 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ioxi-o.php"] [unique_id "ambvQXFwI8r7BFXGkAtGrAAAAAs"]
[Mon Jul 27 07:40:17.089631 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ioxi-o.php"] [unique_id "ambvQXFwI8r7BFXGkAtGrAAAAAs"]
[Mon Jul 27 07:40:17.089897 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ioxi-o.php"] [unique_id "ambvQXFwI8r7BFXGkAtGrAAAAAs"]
[Mon Jul 27 07:40:17.221229 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/themes.php"] [unique_id "ambvQXFwI8r7BFXGkAtGrQAAAAo"]
[Mon Jul 27 07:40:17.221960 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/themes.php"] [unique_id "ambvQXFwI8r7BFXGkAtGrQAAAAo"]
[Mon Jul 27 07:40:17.222219 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/themes.php"] [unique_id "ambvQXFwI8r7BFXGkAtGrQAAAAo"]
[Mon Jul 27 07:40:17.348918 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ct.php"] [unique_id "ambvQXFwI8r7BFXGkAtGrgAAABE"]
[Mon Jul 27 07:40:17.349827 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ct.php"] [unique_id "ambvQXFwI8r7BFXGkAtGrgAAABE"]
[Mon Jul 27 07:40:17.350113 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ct.php"] [unique_id "ambvQXFwI8r7BFXGkAtGrgAAABE"]
[Mon Jul 27 07:40:17.479113 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/13.php"] [unique_id "ambvQXFwI8r7BFXGkAtGrwAAAA8"]
[Mon Jul 27 07:40:17.479757 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/13.php"] [unique_id "ambvQXFwI8r7BFXGkAtGrwAAAA8"]
[Mon Jul 27 07:40:17.479948 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/13.php"] [unique_id "ambvQXFwI8r7BFXGkAtGrwAAAA8"]
[Mon Jul 27 07:40:17.607279 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ok.php"] [unique_id "ambvQXFwI8r7BFXGkAtGsAAAAAA"]
[Mon Jul 27 07:40:17.607960 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ok.php"] [unique_id "ambvQXFwI8r7BFXGkAtGsAAAAAA"]
[Mon Jul 27 07:40:17.608209 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ok.php"] [unique_id "ambvQXFwI8r7BFXGkAtGsAAAAAA"]
[Mon Jul 27 07:40:17.730512 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/a1.php"] [unique_id "ambvQXFwI8r7BFXGkAtGsQAAAAU"]
[Mon Jul 27 07:40:17.731302 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/a1.php"] [unique_id "ambvQXFwI8r7BFXGkAtGsQAAAAU"]
[Mon Jul 27 07:40:17.731497 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/a1.php"] [unique_id "ambvQXFwI8r7BFXGkAtGsQAAAAU"]
[Mon Jul 27 07:40:17.852335 2026] [:error] [pid 12275:tid 140706928609024] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wso1337.php"] [unique_id "ambvQXFwI8r7BFXGkAtGsgAAAAw"]
[Mon Jul 27 07:40:17.853166 2026] [:error] [pid 12275:tid 140706928609024] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wso1337.php"] [unique_id "ambvQXFwI8r7BFXGkAtGsgAAAAw"]
[Mon Jul 27 07:40:17.853412 2026] [:error] [pid 12275:tid 140706928609024] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wso1337.php"] [unique_id "ambvQXFwI8r7BFXGkAtGsgAAAAw"]
[Mon Jul 27 07:40:17.979376 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/class-t.api.php"] [unique_id "ambvQXFwI8r7BFXGkAtGswAAABY"]
[Mon Jul 27 07:40:17.980105 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/class-t.api.php"] [unique_id "ambvQXFwI8r7BFXGkAtGswAAABY"]
[Mon Jul 27 07:40:17.980307 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/class-t.api.php"] [unique_id "ambvQXFwI8r7BFXGkAtGswAAABY"]
[Mon Jul 27 07:40:18.100313 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/anone.php"] [unique_id "ambvQnFwI8r7BFXGkAtGtAAAABc"]
[Mon Jul 27 07:40:18.101094 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/anone.php"] [unique_id "ambvQnFwI8r7BFXGkAtGtAAAABc"]
[Mon Jul 27 07:40:18.101357 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/anone.php"] [unique_id "ambvQnFwI8r7BFXGkAtGtAAAABc"]
[Mon Jul 27 07:40:18.222166 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env.php"] [unique_id "ambvQnFwI8r7BFXGkAtGtgAAABU"]
[Mon Jul 27 07:40:18.223268 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env.php"] [unique_id "ambvQnFwI8r7BFXGkAtGtgAAABU"]
[Mon Jul 27 07:40:18.223593 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/env.php"] [unique_id "ambvQnFwI8r7BFXGkAtGtgAAABU"]
[Mon Jul 27 07:40:18.379746 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/3301.php"] [unique_id "ambvQnFwI8r7BFXGkAtGtwAAAAc"]
[Mon Jul 27 07:40:18.380496 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/3301.php"] [unique_id "ambvQnFwI8r7BFXGkAtGtwAAAAc"]
[Mon Jul 27 07:40:18.380766 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/3301.php"] [unique_id "ambvQnFwI8r7BFXGkAtGtwAAAAc"]
[Mon Jul 27 07:40:18.500826 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/il.php"] [unique_id "ambvQnFwI8r7BFXGkAtGuQAAAAE"]
[Mon Jul 27 07:40:18.501660 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/il.php"] [unique_id "ambvQnFwI8r7BFXGkAtGuQAAAAE"]
[Mon Jul 27 07:40:18.501896 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/il.php"] [unique_id "ambvQnFwI8r7BFXGkAtGuQAAAAE"]
[Mon Jul 27 07:40:18.619398 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/166.php"] [unique_id "ambvQnFwI8r7BFXGkAtGugAAABQ"]
[Mon Jul 27 07:40:18.620474 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/166.php"] [unique_id "ambvQnFwI8r7BFXGkAtGugAAABQ"]
[Mon Jul 27 07:40:18.620773 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/166.php"] [unique_id "ambvQnFwI8r7BFXGkAtGugAAABQ"]
[Mon Jul 27 07:40:18.756463 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/images/index.php"] [unique_id "ambvQnFwI8r7BFXGkAtGuwAAAAI"]
[Mon Jul 27 07:40:18.757298 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/images/index.php"] [unique_id "ambvQnFwI8r7BFXGkAtGuwAAAAI"]
[Mon Jul 27 07:40:18.757568 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/images/index.php"] [unique_id "ambvQnFwI8r7BFXGkAtGuwAAAAI"]
[Mon Jul 27 07:40:18.875579 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/10.php"] [unique_id "ambvQnFwI8r7BFXGkAtGvAAAAAQ"]
[Mon Jul 27 07:40:18.876491 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/10.php"] [unique_id "ambvQnFwI8r7BFXGkAtGvAAAAAQ"]
[Mon Jul 27 07:40:18.876801 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/10.php"] [unique_id "ambvQnFwI8r7BFXGkAtGvAAAAAQ"]
[Mon Jul 27 07:40:18.997691 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.tmb/LA.php"] [unique_id "ambvQnFwI8r7BFXGkAtGvQAAAAM"]
[Mon Jul 27 07:40:18.998575 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.tmb/LA.php"] [unique_id "ambvQnFwI8r7BFXGkAtGvQAAAAM"]
[Mon Jul 27 07:40:18.998838 2026] [:error] [pid 12275:tid 140707004143360] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.tmb/LA.php"] [unique_id "ambvQnFwI8r7BFXGkAtGvQAAAAM"]
[Mon Jul 27 07:40:19.128386 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/larva.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGvgAAABM"]
[Mon Jul 27 07:40:19.129318 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/larva.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGvgAAABM"]
[Mon Jul 27 07:40:19.129598 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/larva.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGvgAAABM"]
[Mon Jul 27 07:40:19.281366 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aaa.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGvwAAABg"]
[Mon Jul 27 07:40:19.282035 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aaa.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGvwAAABg"]
[Mon Jul 27 07:40:19.282232 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/aaa.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGvwAAABg"]
[Mon Jul 27 07:40:19.399699 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/shell.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGwAAAAAs"]
[Mon Jul 27 07:40:19.400646 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/shell.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGwAAAAAs"]
[Mon Jul 27 07:40:19.400932 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/shell.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGwAAAAAs"]
[Mon Jul 27 07:40:19.533227 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGwQAAAAo"]
[Mon Jul 27 07:40:19.534107 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGwQAAAAo"]
[Mon Jul 27 07:40:19.534395 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGwQAAAAo"]
[Mon Jul 27 07:40:19.653830 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ract.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGwgAAABE"]
[Mon Jul 27 07:40:19.654674 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ract.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGwgAAABE"]
[Mon Jul 27 07:40:19.654953 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ract.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGwgAAABE"]
[Mon Jul 27 07:40:19.783284 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/city-ajax.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGwwAAAA8"]
[Mon Jul 27 07:40:19.784119 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/city-ajax.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGwwAAAA8"]
[Mon Jul 27 07:40:19.784415 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/city-ajax.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGwwAAAA8"]
[Mon Jul 27 07:40:19.904303 2026] [:error] [pid 12275:tid 140706962179840] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fi.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGxAAAAAg"]
[Mon Jul 27 07:40:19.905600 2026] [:error] [pid 12275:tid 140706962179840] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fi.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGxAAAAAg"]
[Mon Jul 27 07:40:19.905944 2026] [:error] [pid 12275:tid 140706962179840] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fi.php"] [unique_id "ambvQ3FwI8r7BFXGkAtGxAAAAAg"]
[Mon Jul 27 07:40:20.025846 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/lf.php"] [unique_id "ambvRHFwI8r7BFXGkAtGxgAAABY"]
[Mon Jul 27 07:40:20.026749 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/lf.php"] [unique_id "ambvRHFwI8r7BFXGkAtGxgAAABY"]
[Mon Jul 27 07:40:20.027073 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/lf.php"] [unique_id "ambvRHFwI8r7BFXGkAtGxgAAABY"]
[Mon Jul 27 07:40:20.151856 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/5index.php"] [unique_id "ambvRHFwI8r7BFXGkAtGxwAAABc"]
[Mon Jul 27 07:40:20.152777 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/5index.php"] [unique_id "ambvRHFwI8r7BFXGkAtGxwAAABc"]
[Mon Jul 27 07:40:20.153055 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/5index.php"] [unique_id "ambvRHFwI8r7BFXGkAtGxwAAABc"]
[Mon Jul 27 07:40:20.273861 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sterJs.php"] [unique_id "ambvRHFwI8r7BFXGkAtGyQAAABU"]
[Mon Jul 27 07:40:20.274750 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sterJs.php"] [unique_id "ambvRHFwI8r7BFXGkAtGyQAAABU"]
[Mon Jul 27 07:40:20.275049 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sterJs.php"] [unique_id "ambvRHFwI8r7BFXGkAtGyQAAABU"]
[Mon Jul 27 07:40:20.394399 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/155.php"] [unique_id "ambvRHFwI8r7BFXGkAtGygAAAAc"]
[Mon Jul 27 07:40:20.395281 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/155.php"] [unique_id "ambvRHFwI8r7BFXGkAtGygAAAAc"]
[Mon Jul 27 07:40:20.395544 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/155.php"] [unique_id "ambvRHFwI8r7BFXGkAtGygAAAAc"]
[Mon Jul 27 07:40:20.536910 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/themes/about.php"] [unique_id "ambvRHFwI8r7BFXGkAtGywAAAAE"]
[Mon Jul 27 07:40:20.537731 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/themes/about.php"] [unique_id "ambvRHFwI8r7BFXGkAtGywAAAAE"]
[Mon Jul 27 07:40:20.537987 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/themes/about.php"] [unique_id "ambvRHFwI8r7BFXGkAtGywAAAAE"]
[Mon Jul 27 07:40:20.659213 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-rss2.php"] [unique_id "ambvRHFwI8r7BFXGkAtGzAAAABQ"]
[Mon Jul 27 07:40:20.660067 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-rss2.php"] [unique_id "ambvRHFwI8r7BFXGkAtGzAAAABQ"]
[Mon Jul 27 07:40:20.660317 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-rss2.php"] [unique_id "ambvRHFwI8r7BFXGkAtGzAAAABQ"]
[Mon Jul 27 07:40:20.784220 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-rss.php"] [unique_id "ambvRHFwI8r7BFXGkAtGzQAAAAQ"]
[Mon Jul 27 07:40:20.785074 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-rss.php"] [unique_id "ambvRHFwI8r7BFXGkAtGzQAAAAQ"]
[Mon Jul 27 07:40:20.785319 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-rss.php"] [unique_id "ambvRHFwI8r7BFXGkAtGzQAAAAQ"]
[Mon Jul 27 07:40:20.902023 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/lib.php"] [unique_id "ambvRHFwI8r7BFXGkAtGzgAAABA"]
[Mon Jul 27 07:40:20.902837 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/lib.php"] [unique_id "ambvRHFwI8r7BFXGkAtGzgAAABA"]
[Mon Jul 27 07:40:20.903113 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/lib.php"] [unique_id "ambvRHFwI8r7BFXGkAtGzgAAABA"]
[Mon Jul 27 07:40:21.025392 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dr.php"] [unique_id "ambvRXFwI8r7BFXGkAtGzwAAAAk"]
[Mon Jul 27 07:40:21.026077 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dr.php"] [unique_id "ambvRXFwI8r7BFXGkAtGzwAAAAk"]
[Mon Jul 27 07:40:21.026275 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/dr.php"] [unique_id "ambvRXFwI8r7BFXGkAtGzwAAAAk"]
[Mon Jul 27 07:40:21.149164 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/blog.php"] [unique_id "ambvRXFwI8r7BFXGkAtG0AAAABg"]
[Mon Jul 27 07:40:21.149805 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/blog.php"] [unique_id "ambvRXFwI8r7BFXGkAtG0AAAABg"]
[Mon Jul 27 07:40:21.150046 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43431] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/blog.php"] [unique_id "ambvRXFwI8r7BFXGkAtG0AAAABg"]
[Mon Jul 27 07:40:21.392135 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/am.php"] [unique_id "ambvRXFwI8r7BFXGkAtG0gAAAAo"]
[Mon Jul 27 07:40:21.393100 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/am.php"] [unique_id "ambvRXFwI8r7BFXGkAtG0gAAAAo"]
[Mon Jul 27 07:40:21.393357 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/am.php"] [unique_id "ambvRXFwI8r7BFXGkAtG0gAAAAo"]
[Mon Jul 27 07:40:21.513402 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/jindex.php"] [unique_id "ambvRXFwI8r7BFXGkAtG1AAAABE"]
[Mon Jul 27 07:40:21.514108 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/jindex.php"] [unique_id "ambvRXFwI8r7BFXGkAtG1AAAABE"]
[Mon Jul 27 07:40:21.514339 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/jindex.php"] [unique_id "ambvRXFwI8r7BFXGkAtG1AAAABE"]
[Mon Jul 27 07:40:21.653117 2026] [:error] [pid 12275:tid 140706962179840] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/geck.php"] [unique_id "ambvRXFwI8r7BFXGkAtG1QAAAAg"]
[Mon Jul 27 07:40:21.654178 2026] [:error] [pid 12275:tid 140706962179840] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/geck.php"] [unique_id "ambvRXFwI8r7BFXGkAtG1QAAAAg"]
[Mon Jul 27 07:40:21.654524 2026] [:error] [pid 12275:tid 140706962179840] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/geck.php"] [unique_id "ambvRXFwI8r7BFXGkAtG1QAAAAg"]
[Mon Jul 27 07:40:21.788010 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xox.php"] [unique_id "ambvRXFwI8r7BFXGkAtG1gAAABY"]
[Mon Jul 27 07:40:21.788797 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xox.php"] [unique_id "ambvRXFwI8r7BFXGkAtG1gAAABY"]
[Mon Jul 27 07:40:21.789064 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/xox.php"] [unique_id "ambvRXFwI8r7BFXGkAtG1gAAABY"]
[Mon Jul 27 07:40:21.920664 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wen.php"] [unique_id "ambvRXFwI8r7BFXGkAtG1wAAABc"]
[Mon Jul 27 07:40:21.921575 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wen.php"] [unique_id "ambvRXFwI8r7BFXGkAtG1wAAABc"]
[Mon Jul 27 07:40:21.921844 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wen.php"] [unique_id "ambvRXFwI8r7BFXGkAtG1wAAABc"]
[Mon Jul 27 07:40:22.043963 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gel4y.php"] [unique_id "ambvRnFwI8r7BFXGkAtG2AAAAA4"]
[Mon Jul 27 07:40:22.044828 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gel4y.php"] [unique_id "ambvRnFwI8r7BFXGkAtG2AAAAA4"]
[Mon Jul 27 07:40:22.045081 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/gel4y.php"] [unique_id "ambvRnFwI8r7BFXGkAtG2AAAAA4"]
[Mon Jul 27 07:40:22.175820 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gif.php"] [unique_id "ambvRnFwI8r7BFXGkAtG2QAAAAc"]
[Mon Jul 27 07:40:22.176676 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gif.php"] [unique_id "ambvRnFwI8r7BFXGkAtG2QAAAAc"]
[Mon Jul 27 07:40:22.176919 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/gif.php"] [unique_id "ambvRnFwI8r7BFXGkAtG2QAAAAc"]
[Mon Jul 27 07:40:22.300999 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/rJs.php"] [unique_id "ambvRnFwI8r7BFXGkAtG2gAAAAE"]
[Mon Jul 27 07:40:22.301681 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/rJs.php"] [unique_id "ambvRnFwI8r7BFXGkAtG2gAAAAE"]
[Mon Jul 27 07:40:22.301924 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/rJs.php"] [unique_id "ambvRnFwI8r7BFXGkAtG2gAAAAE"]
[Mon Jul 27 07:40:22.437006 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/00:.php"] [unique_id "ambvRnFwI8r7BFXGkAtG2wAAAA0"]
[Mon Jul 27 07:40:22.437808 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/00:.php"] [unique_id "ambvRnFwI8r7BFXGkAtG2wAAAA0"]
[Mon Jul 27 07:40:22.438083 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/00:.php"] [unique_id "ambvRnFwI8r7BFXGkAtG2wAAAA0"]
[Mon Jul 27 07:40:22.560031 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/at/name.php"] [unique_id "ambvRnFwI8r7BFXGkAtG3AAAABQ"]
[Mon Jul 27 07:40:22.560768 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/at/name.php"] [unique_id "ambvRnFwI8r7BFXGkAtG3AAAABQ"]
[Mon Jul 27 07:40:22.561004 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/at/name.php"] [unique_id "ambvRnFwI8r7BFXGkAtG3AAAABQ"]
[Mon Jul 27 07:40:22.686079 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ta.php"] [unique_id "ambvRnFwI8r7BFXGkAtG3QAAAAQ"]
[Mon Jul 27 07:40:22.686927 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ta.php"] [unique_id "ambvRnFwI8r7BFXGkAtG3QAAAAQ"]
[Mon Jul 27 07:40:22.687268 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ta.php"] [unique_id "ambvRnFwI8r7BFXGkAtG3QAAAAQ"]
[Mon Jul 27 07:40:22.808374 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/moon.php"] [unique_id "ambvRnFwI8r7BFXGkAtG3gAAABA"]
[Mon Jul 27 07:40:22.809389 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/moon.php"] [unique_id "ambvRnFwI8r7BFXGkAtG3gAAABA"]
[Mon Jul 27 07:40:22.809708 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/moon.php"] [unique_id "ambvRnFwI8r7BFXGkAtG3gAAABA"]
[Mon Jul 27 07:40:22.936526 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/41.php"] [unique_id "ambvRnFwI8r7BFXGkAtG3wAAABg"]
[Mon Jul 27 07:40:22.937414 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/41.php"] [unique_id "ambvRnFwI8r7BFXGkAtG3wAAABg"]
[Mon Jul 27 07:40:22.937699 2026] [:error] [pid 12275:tid 140706827896576] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/41.php"] [unique_id "ambvRnFwI8r7BFXGkAtG3wAAABg"]
[Mon Jul 27 07:40:23.064791 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/data.php"] [unique_id "ambvR3FwI8r7BFXGkAtG4AAAAAo"]
[Mon Jul 27 07:40:23.065793 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/data.php"] [unique_id "ambvR3FwI8r7BFXGkAtG4AAAAAo"]
[Mon Jul 27 07:40:23.066073 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/data.php"] [unique_id "ambvR3FwI8r7BFXGkAtG4AAAAAo"]
[Mon Jul 27 07:40:23.221052 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/edit-css.php"] [unique_id "ambvR3FwI8r7BFXGkAtG4wAAAA8"]
[Mon Jul 27 07:40:23.221881 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/edit-css.php"] [unique_id "ambvR3FwI8r7BFXGkAtG4wAAAA8"]
[Mon Jul 27 07:40:23.222139 2026] [:error] [pid 12275:tid 140706903430912] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/edit-css.php"] [unique_id "ambvR3FwI8r7BFXGkAtG4wAAAA8"]
[Mon Jul 27 07:40:23.350918 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mar.php"] [unique_id "ambvR3FwI8r7BFXGkAtG5AAAAAU"]
[Mon Jul 27 07:40:23.351833 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mar.php"] [unique_id "ambvR3FwI8r7BFXGkAtG5AAAAAU"]
[Mon Jul 27 07:40:23.352140 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/mar.php"] [unique_id "ambvR3FwI8r7BFXGkAtG5AAAAAU"]
[Mon Jul 27 07:40:23.480276 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/op.php"] [unique_id "ambvR3FwI8r7BFXGkAtG5QAAABY"]
[Mon Jul 27 07:40:23.481157 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/op.php"] [unique_id "ambvR3FwI8r7BFXGkAtG5QAAABY"]
[Mon Jul 27 07:40:23.481444 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/op.php"] [unique_id "ambvR3FwI8r7BFXGkAtG5QAAABY"]
[Mon Jul 27 07:40:23.609159 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bipas.php"] [unique_id "ambvR3FwI8r7BFXGkAtG5gAAAAs"]
[Mon Jul 27 07:40:23.610025 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bipas.php"] [unique_id "ambvR3FwI8r7BFXGkAtG5gAAAAs"]
[Mon Jul 27 07:40:23.610260 2026] [:error] [pid 12275:tid 140706937001728] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bipas.php"] [unique_id "ambvR3FwI8r7BFXGkAtG5gAAAAs"]
[Mon Jul 27 07:40:23.731891 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/plss3.php"] [unique_id "ambvR3FwI8r7BFXGkAtG5wAAABc"]
[Mon Jul 27 07:40:23.732819 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/plss3.php"] [unique_id "ambvR3FwI8r7BFXGkAtG5wAAABc"]
[Mon Jul 27 07:40:23.733088 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/plss3.php"] [unique_id "ambvR3FwI8r7BFXGkAtG5wAAABc"]
[Mon Jul 27 07:40:23.860241 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/minimo.php"] [unique_id "ambvR3FwI8r7BFXGkAtG6AAAAAA"]
[Mon Jul 27 07:40:23.861128 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/minimo.php"] [unique_id "ambvR3FwI8r7BFXGkAtG6AAAAAA"]
[Mon Jul 27 07:40:23.861341 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/minimo.php"] [unique_id "ambvR3FwI8r7BFXGkAtG6AAAAAA"]
[Mon Jul 27 07:40:23.994408 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/RxR.php"] [unique_id "ambvR3FwI8r7BFXGkAtG6QAAAA4"]
[Mon Jul 27 07:40:23.995047 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/RxR.php"] [unique_id "ambvR3FwI8r7BFXGkAtG6QAAAA4"]
[Mon Jul 27 07:40:23.995240 2026] [:error] [pid 12275:tid 140706911823616] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/RxR.php"] [unique_id "ambvR3FwI8r7BFXGkAtG6QAAAA4"]
[Mon Jul 27 07:40:24.117934 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin/function.php"] [unique_id "ambvSHFwI8r7BFXGkAtG6gAAABU"]
[Mon Jul 27 07:40:24.118801 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin/function.php"] [unique_id "ambvSHFwI8r7BFXGkAtG6gAAABU"]
[Mon Jul 27 07:40:24.119059 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/admin/function.php"] [unique_id "ambvSHFwI8r7BFXGkAtG6gAAABU"]
[Mon Jul 27 07:40:24.239892 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gifclass4.php"] [unique_id "ambvSHFwI8r7BFXGkAtG6wAAAAE"]
[Mon Jul 27 07:40:24.241028 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gifclass4.php"] [unique_id "ambvSHFwI8r7BFXGkAtG6wAAAAE"]
[Mon Jul 27 07:40:24.241384 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/gifclass4.php"] [unique_id "ambvSHFwI8r7BFXGkAtG6wAAAAE"]
[Mon Jul 27 07:40:24.364511 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/nw.php"] [unique_id "ambvSHFwI8r7BFXGkAtG7AAAAA0"]
[Mon Jul 27 07:40:24.365260 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/nw.php"] [unique_id "ambvSHFwI8r7BFXGkAtG7AAAAA0"]
[Mon Jul 27 07:40:24.365484 2026] [:error] [pid 12275:tid 140706920216320] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/nw.php"] [unique_id "ambvSHFwI8r7BFXGkAtG7AAAAA0"]
[Mon Jul 27 07:40:24.506020 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/it/name.php"] [unique_id "ambvSHFwI8r7BFXGkAtG7gAAABQ"]
[Mon Jul 27 07:40:24.507088 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/it/name.php"] [unique_id "ambvSHFwI8r7BFXGkAtG7gAAABQ"]
[Mon Jul 27 07:40:24.507450 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/it/name.php"] [unique_id "ambvSHFwI8r7BFXGkAtG7gAAABQ"]
[Mon Jul 27 07:40:24.648360 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/FoxWSO.php"] [unique_id "ambvSHFwI8r7BFXGkAtG8AAAABM"]
[Mon Jul 27 07:40:24.649316 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/FoxWSO.php"] [unique_id "ambvSHFwI8r7BFXGkAtG8AAAABM"]
[Mon Jul 27 07:40:24.649612 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/FoxWSO.php"] [unique_id "ambvSHFwI8r7BFXGkAtG8AAAABM"]
[Mon Jul 27 07:40:24.770425 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/lol.php"] [unique_id "ambvSHFwI8r7BFXGkAtG8gAAABA"]
[Mon Jul 27 07:40:24.771038 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/lol.php"] [unique_id "ambvSHFwI8r7BFXGkAtG8gAAABA"]
[Mon Jul 27 07:40:24.771282 2026] [:error] [pid 12275:tid 140706895038208] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/lol.php"] [unique_id "ambvSHFwI8r7BFXGkAtG8gAAABA"]
[Mon Jul 27 07:40:24.898532 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api.php"] [unique_id "ambvSHFwI8r7BFXGkAtG8wAAAAk"]
[Mon Jul 27 07:40:24.899314 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api.php"] [unique_id "ambvSHFwI8r7BFXGkAtG8wAAAAk"]
[Mon Jul 27 07:40:24.899518 2026] [:error] [pid 12275:tid 140706953787136] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/api.php"] [unique_id "ambvSHFwI8r7BFXGkAtG8wAAAAk"]
[Mon Jul 27 07:40:25.039807 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/kn.php"] [unique_id "ambvSXFwI8r7BFXGkAtG9QAAAAY"]
[Mon Jul 27 07:40:25.040531 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/kn.php"] [unique_id "ambvSXFwI8r7BFXGkAtG9QAAAAY"]
[Mon Jul 27 07:40:25.040752 2026] [:error] [pid 12275:tid 140706978965248] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/kn.php"] [unique_id "ambvSXFwI8r7BFXGkAtG9QAAAAY"]
[Mon Jul 27 07:40:25.189808 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sql.php"] [unique_id "ambvSXFwI8r7BFXGkAtG9wAAAAo"]
[Mon Jul 27 07:40:25.190832 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sql.php"] [unique_id "ambvSXFwI8r7BFXGkAtG9wAAAAo"]
[Mon Jul 27 07:40:25.191100 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sql.php"] [unique_id "ambvSXFwI8r7BFXGkAtG9wAAAAo"]
[Mon Jul 27 07:40:25.320117 2026] [:error] [pid 12275:tid 140706878252800] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/t.php"] [unique_id "ambvSXFwI8r7BFXGkAtG-AAAABI"]
[Mon Jul 27 07:40:25.320830 2026] [:error] [pid 12275:tid 140706878252800] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/t.php"] [unique_id "ambvSXFwI8r7BFXGkAtG-AAAABI"]
[Mon Jul 27 07:40:25.321095 2026] [:error] [pid 12275:tid 140706878252800] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/t.php"] [unique_id "ambvSXFwI8r7BFXGkAtG-AAAABI"]
[Mon Jul 27 07:40:25.446968 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/revealability.php"] [unique_id "ambvSXFwI8r7BFXGkAtG-QAAABE"]
[Mon Jul 27 07:40:25.447873 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/revealability.php"] [unique_id "ambvSXFwI8r7BFXGkAtG-QAAABE"]
[Mon Jul 27 07:40:25.448097 2026] [:error] [pid 12275:tid 140706886645504] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/revealability.php"] [unique_id "ambvSXFwI8r7BFXGkAtG-QAAABE"]
[Mon Jul 27 07:40:25.582750 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/us/confirm.php"] [unique_id "ambvSXFwI8r7BFXGkAtG-gAAAAI"]
[Mon Jul 27 07:40:25.583474 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/us/confirm.php"] [unique_id "ambvSXFwI8r7BFXGkAtG-gAAAAI"]
[Mon Jul 27 07:40:25.583774 2026] [:error] [pid 12275:tid 140707012536064] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/us/confirm.php"] [unique_id "ambvSXFwI8r7BFXGkAtG-gAAAAI"]
[Mon Jul 27 07:40:25.727183 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-feed.php"] [unique_id "ambvSXFwI8r7BFXGkAtG-wAAAAU"]
[Mon Jul 27 07:40:25.727969 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-feed.php"] [unique_id "ambvSXFwI8r7BFXGkAtG-wAAAAU"]
[Mon Jul 27 07:40:25.728206 2026] [:error] [pid 12275:tid 140706987357952] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-feed.php"] [unique_id "ambvSXFwI8r7BFXGkAtG-wAAAAU"]
[Mon Jul 27 07:40:25.852302 2026] [:error] [pid 12275:tid 140706928609024] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-update.php"] [unique_id "ambvSXFwI8r7BFXGkAtG_AAAAAw"]
[Mon Jul 27 07:40:25.853284 2026] [:error] [pid 12275:tid 140706928609024] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-update.php"] [unique_id "ambvSXFwI8r7BFXGkAtG_AAAAAw"]
[Mon Jul 27 07:40:25.853582 2026] [:error] [pid 12275:tid 140706928609024] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-update.php"] [unique_id "ambvSXFwI8r7BFXGkAtG_AAAAAw"]
[Mon Jul 27 07:40:25.974465 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/tuco.php"] [unique_id "ambvSXFwI8r7BFXGkAtG_QAAABY"]
[Mon Jul 27 07:40:25.975453 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/tuco.php"] [unique_id "ambvSXFwI8r7BFXGkAtG_QAAABY"]
[Mon Jul 27 07:40:25.975755 2026] [:error] [pid 12275:tid 140706844681984] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/tuco.php"] [unique_id "ambvSXFwI8r7BFXGkAtG_QAAABY"]
[Mon Jul 27 07:40:26.102593 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bypass.php"] [unique_id "ambvSnFwI8r7BFXGkAtG_wAAABc"]
[Mon Jul 27 07:40:26.103573 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bypass.php"] [unique_id "ambvSnFwI8r7BFXGkAtG_wAAABc"]
[Mon Jul 27 07:40:26.103833 2026] [:error] [pid 12275:tid 140706836289280] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bypass.php"] [unique_id "ambvSnFwI8r7BFXGkAtG_wAAABc"]
[Mon Jul 27 07:40:26.233970 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/soniau.php"] [unique_id "ambvSnFwI8r7BFXGkAtHAAAAAAA"]
[Mon Jul 27 07:40:26.234761 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/soniau.php"] [unique_id "ambvSnFwI8r7BFXGkAtHAAAAAAA"]
[Mon Jul 27 07:40:26.235057 2026] [:error] [pid 12275:tid 140707103270656] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/soniau.php"] [unique_id "ambvSnFwI8r7BFXGkAtHAAAAAAA"]
[Mon Jul 27 07:40:26.377440 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fa.php"] [unique_id "ambvSnFwI8r7BFXGkAtHAgAAABU"]
[Mon Jul 27 07:40:26.378408 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fa.php"] [unique_id "ambvSnFwI8r7BFXGkAtHAgAAABU"]
[Mon Jul 27 07:40:26.378725 2026] [:error] [pid 12275:tid 140706853074688] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fa.php"] [unique_id "ambvSnFwI8r7BFXGkAtHAgAAABU"]
[Mon Jul 27 07:40:26.498802 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/pi.php"] [unique_id "ambvSnFwI8r7BFXGkAtHAwAAAAE"]
[Mon Jul 27 07:40:26.499659 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/pi.php"] [unique_id "ambvSnFwI8r7BFXGkAtHAwAAAAE"]
[Mon Jul 27 07:40:26.499890 2026] [:error] [pid 12275:tid 140707020928768] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/pi.php"] [unique_id "ambvSnFwI8r7BFXGkAtHAwAAAAE"]
[Mon Jul 27 07:40:26.669035 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/flower.php"] [unique_id "ambvSnFwI8r7BFXGkAtHBgAAABQ"]
[Mon Jul 27 07:40:26.670362 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/flower.php"] [unique_id "ambvSnFwI8r7BFXGkAtHBgAAABQ"]
[Mon Jul 27 07:40:26.670697 2026] [:error] [pid 12275:tid 140706861467392] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/flower.php"] [unique_id "ambvSnFwI8r7BFXGkAtHBgAAABQ"]
[Mon Jul 27 07:40:26.806845 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aa2.php"] [unique_id "ambvSnFwI8r7BFXGkAtHBwAAABM"]
[Mon Jul 27 07:40:26.807684 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aa2.php"] [unique_id "ambvSnFwI8r7BFXGkAtHBwAAABM"]
[Mon Jul 27 07:40:26.807922 2026] [:error] [pid 12275:tid 140706869860096] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/aa2.php"] [unique_id "ambvSnFwI8r7BFXGkAtHBwAAABM"]
[Mon Jul 27 07:40:26.928205 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/iwivi.php"] [unique_id "ambvSnFwI8r7BFXGkAtHCQAAAAQ"]
[Mon Jul 27 07:40:26.928912 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/iwivi.php"] [unique_id "ambvSnFwI8r7BFXGkAtHCQAAAAQ"]
[Mon Jul 27 07:40:26.929178 2026] [:error] [pid 12275:tid 140706995750656] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/iwivi.php"] [unique_id "ambvSnFwI8r7BFXGkAtHCQAAAAQ"]
[Mon Jul 27 07:40:27.049356 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-rdf.php"] [unique_id "ambvS3FwI8r7BFXGkAtHCgAAAAc"]
[Mon Jul 27 07:40:27.049982 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-rdf.php"] [unique_id "ambvS3FwI8r7BFXGkAtHCgAAAAc"]
[Mon Jul 27 07:40:27.050209 2026] [:error] [pid 12275:tid 140706970572544] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-rdf.php"] [unique_id "ambvS3FwI8r7BFXGkAtHCgAAAAc"]
[Mon Jul 27 07:40:27.170423 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/priv8.php"] [unique_id "ambvS3FwI8r7BFXGkAtHCwAAAAo"]
[Mon Jul 27 07:40:27.171127 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/priv8.php"] [unique_id "ambvS3FwI8r7BFXGkAtHCwAAAAo"]
[Mon Jul 27 07:40:27.171362 2026] [:error] [pid 12275:tid 140706945394432] [client 52.139.36.144:43448] [client 52.139.36.144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/priv8.php"] [unique_id "ambvS3FwI8r7BFXGkAtHCwAAAAo"]
[Mon Jul 27 08:58:08.833766 2026] [:error] [pid 17228:tid 140706937001728] [client 193.19.109.150:58801] [client 193.19.109.150] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amcBgJjBQLO4t9VCDfo-YQAAAQs"]
[Mon Jul 27 08:58:08.899868 2026] [:error] [pid 17228:tid 140706937001728] [client 193.19.109.150:58801] [client 193.19.109.150] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amcBgJjBQLO4t9VCDfo-YQAAAQs"]
[Mon Jul 27 08:58:19.222695 2026] [:error] [pid 12380:tid 140706970572544] [client 193.19.109.149:35519] [client 193.19.109.149] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/"] [unique_id "amcBi6aChfbWW0CZ_hraUwAAAMc"]
[Mon Jul 27 08:58:19.223563 2026] [:error] [pid 12380:tid 140706970572544] [client 193.19.109.149:35519] [client 193.19.109.149] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/"] [unique_id "amcBi6aChfbWW0CZ_hraUwAAAMc"]
[Mon Jul 27 08:58:31.608123 2026] [:error] [pid 12275:tid 140706836289280] [client 193.19.109.142:28459] [client 193.19.109.142] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcBl3FwI8r7BFXGkAt92QAAABc"]
[Mon Jul 27 08:58:31.608779 2026] [:error] [pid 12275:tid 140706836289280] [client 193.19.109.142:28459] [client 193.19.109.142] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcBl3FwI8r7BFXGkAt92QAAABc"]
[Mon Jul 27 08:58:32.053861 2026] [:error] [pid 12275:tid 140707020928768] [client 193.19.109.142:28459] [client 193.19.109.142] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcBmHFwI8r7BFXGkAt93QAAAAE"]
[Mon Jul 27 08:58:32.054728 2026] [:error] [pid 12275:tid 140707020928768] [client 193.19.109.142:28459] [client 193.19.109.142] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcBmHFwI8r7BFXGkAt93QAAAAE"]
[Mon Jul 27 08:58:32.055112 2026] [:error] [pid 12275:tid 140707020928768] [client 193.19.109.142:28459] [client 193.19.109.142] ModSecurity: Warning. Found 3 byte(s) in ARGS:rest_route outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:rest_route=/wp/v2/users"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcBmHFwI8r7BFXGkAt93QAAAAE"]
[Mon Jul 27 08:58:32.491375 2026] [:error] [pid 12275:tid 140706853074688] [client 193.19.109.142:28459] [client 193.19.109.142] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/feed"] [unique_id "amcBmHFwI8r7BFXGkAt94AAAABU"]
[Mon Jul 27 08:58:32.492062 2026] [:error] [pid 12275:tid 140706853074688] [client 193.19.109.142:28459] [client 193.19.109.142] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/feed"] [unique_id "amcBmHFwI8r7BFXGkAt94AAAABU"]
[Mon Jul 27 09:03:18.216955 2026] [:error] [pid 24106:tid 140706978965248] [client 159.69.209.206:46218] [client 159.69.209.206] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcCtjs8oMu6f6EYbxR8qgAAAUY"]
[Mon Jul 27 09:03:18.218098 2026] [:error] [pid 24106:tid 140706978965248] [client 159.69.209.206:46218] [client 159.69.209.206] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcCtjs8oMu6f6EYbxR8qgAAAUY"]
[Mon Jul 27 09:03:18.218409 2026] [:error] [pid 24106:tid 140706978965248] [client 159.69.209.206:46218] [client 159.69.209.206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcCtjs8oMu6f6EYbxR8qgAAAUY"]
[Mon Jul 27 09:04:04.702137 2026] [:error] [pid 12276:tid 140706861467392] [client 157.55.39.223:59086] [client 157.55.39.223] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcC5OcsEMuHmMYmk65-WgAAAFQ"]
[Mon Jul 27 09:04:04.703129 2026] [:error] [pid 12276:tid 140706861467392] [client 157.55.39.223:59086] [client 157.55.39.223] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcC5OcsEMuHmMYmk65-WgAAAFQ"]
[Mon Jul 27 09:04:04.703590 2026] [:error] [pid 12276:tid 140706861467392] [client 157.55.39.223:59086] [client 157.55.39.223] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:From outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:From=bingbot(at)microsoft.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcC5OcsEMuHmMYmk65-WgAAAFQ"]
[Mon Jul 27 09:04:05.284930 2026] [:error] [pid 12276:tid 140707103270656] [client 157.55.39.223:59086] [client 157.55.39.223] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcC5ecsEMuHmMYmk65-XAAAAEA"]
[Mon Jul 27 09:04:05.285582 2026] [:error] [pid 12276:tid 140707103270656] [client 157.55.39.223:59086] [client 157.55.39.223] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcC5ecsEMuHmMYmk65-XAAAAEA"]
[Mon Jul 27 09:04:05.285914 2026] [:error] [pid 12276:tid 140707103270656] [client 157.55.39.223:59086] [client 157.55.39.223] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:From outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:From=bingbot(at)microsoft.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcC5ecsEMuHmMYmk65-XAAAAEA"]
[Mon Jul 27 09:04:16.994347 2026] [:error] [pid 12275:tid 140706953787136] [client 52.167.144.169:8678] [client 52.167.144.169] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcC8HFwI8r7BFXGkAt_TwAAAAk"]
[Mon Jul 27 09:04:16.995253 2026] [:error] [pid 12275:tid 140706953787136] [client 52.167.144.169:8678] [client 52.167.144.169] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcC8HFwI8r7BFXGkAt_TwAAAAk"]
[Mon Jul 27 09:04:16.995693 2026] [:error] [pid 12275:tid 140706953787136] [client 52.167.144.169:8678] [client 52.167.144.169] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:From outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:From=bingbot(at)microsoft.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcC8HFwI8r7BFXGkAt_TwAAAAk"]
[Mon Jul 27 09:18:10.754728 2026] [:error] [pid 12276:tid 140706886645504] [client 43.157.158.178:44426] [client 43.157.158.178] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcGMucsEMuHmMYmk66IpQAAAFE"]
[Mon Jul 27 09:18:10.756038 2026] [:error] [pid 12276:tid 140706886645504] [client 43.157.158.178:44426] [client 43.157.158.178] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcGMucsEMuHmMYmk66IpQAAAFE"]
[Mon Jul 27 09:18:10.756403 2026] [:error] [pid 12276:tid 140706886645504] [client 43.157.158.178:44426] [client 43.157.158.178] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "338"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcGMucsEMuHmMYmk66IpQAAAFE"]
[Mon Jul 27 09:33:49.418047 2026] [:error] [pid 21545:tid 140706861467392] [client 162.159.113.45:10445] [client 162.159.113.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ3ZhXfYDIcpslIWObyQAAAZQ"]
[Mon Jul 27 09:33:49.423978 2026] [:error] [pid 21545:tid 140706861467392] [client 162.159.113.45:10445] [client 162.159.113.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ3ZhXfYDIcpslIWObyQAAAZQ"]
[Mon Jul 27 09:33:49.424765 2026] [:error] [pid 21545:tid 140706861467392] [client 162.159.113.45:10445] [client 162.159.113.45] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ3ZhXfYDIcpslIWObyQAAAZQ"]
[Mon Jul 27 09:33:49.424961 2026] [:error] [pid 21545:tid 140706861467392] [client 162.159.113.45:10445] [client 162.159.113.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ3ZhXfYDIcpslIWObyQAAAZQ"]
[Mon Jul 27 09:33:52.831668 2026] [:error] [pid 12275:tid 140706853074688] [client 172.68.238.78:11853] [client 172.68.238.78] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ4HFwI8r7BFXGkAuEZgAAABU"]
[Mon Jul 27 09:33:52.832630 2026] [:error] [pid 12275:tid 140706853074688] [client 172.68.238.78:11853] [client 172.68.238.78] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ4HFwI8r7BFXGkAuEZgAAABU"]
[Mon Jul 27 09:33:52.833093 2026] [:error] [pid 12275:tid 140706853074688] [client 172.68.238.78:11853] [client 172.68.238.78] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ4HFwI8r7BFXGkAuEZgAAABU"]
[Mon Jul 27 09:34:02.154772 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.14.60:11775] [client 162.158.14.60] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ6qaChfbWW0CZ_hrc6AAAAM0"]
[Mon Jul 27 09:34:02.155757 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.14.60:11775] [client 162.158.14.60] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ6qaChfbWW0CZ_hrc6AAAAM0"]
[Mon Jul 27 09:34:02.156295 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.14.60:11775] [client 162.158.14.60] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ6qaChfbWW0CZ_hrc6AAAAM0"]
[Mon Jul 27 09:34:09.628790 2026] [:error] [pid 24106:tid 140707020928768] [client 162.158.102.106:11417] [client 162.158.102.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ8Ts8oMu6f6EYbxSJmQAAAUE"]
[Mon Jul 27 09:34:09.629467 2026] [:error] [pid 24106:tid 140707020928768] [client 162.158.102.106:11417] [client 162.158.102.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ8Ts8oMu6f6EYbxSJmQAAAUE"]
[Mon Jul 27 09:34:09.629935 2026] [:error] [pid 24106:tid 140707020928768] [client 162.158.102.106:11417] [client 162.158.102.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ8Ts8oMu6f6EYbxSJmQAAAUE"]
[Mon Jul 27 09:34:09.635045 2026] [:error] [pid 24106:tid 140707020928768] [client 162.158.102.106:11417] [client 162.158.102.106] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:fly_ab_uid. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: -e951-48cc- found within REQUEST_COOKIES:fly_ab_uid: caffea62-e951-48cc-9acc-620a54d3c909"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ8Ts8oMu6f6EYbxSJmQAAAUE"]
[Mon Jul 27 09:34:09.635157 2026] [:error] [pid 24106:tid 140707020928768] [client 162.158.102.106:11417] [client 162.158.102.106] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:user_agent. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: -telegram-clone- found within REQUEST_COOKIES:user_agent: monitor-telegram-clone-realtime/1.0"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcJ8Ts8oMu6f6EYbxSJmQAAAUE"]
[Mon Jul 27 09:35:00.924323 2026] [:error] [pid 12276:tid 140707103270656] [client 162.159.113.45:11535] [client 162.159.113.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJOcsEMuHmMYmk66V5gAAAEA"]
[Mon Jul 27 09:35:00.927866 2026] [:error] [pid 12276:tid 140707103270656] [client 162.159.113.45:11535] [client 162.159.113.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJOcsEMuHmMYmk66V5gAAAEA"]
[Mon Jul 27 09:35:00.928359 2026] [:error] [pid 12276:tid 140707103270656] [client 162.159.113.45:11535] [client 162.159.113.45] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJOcsEMuHmMYmk66V5gAAAEA"]
[Mon Jul 27 09:35:00.928476 2026] [:error] [pid 12276:tid 140707103270656] [client 162.159.113.45:11535] [client 162.159.113.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJOcsEMuHmMYmk66V5gAAAEA"]
[Mon Jul 27 09:35:00.991628 2026] [:error] [pid 17228:tid 140706911823616] [client 172.70.162.114:12153] [client 172.70.162.114] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJJjBQLO4t9VCDfo_kwAAAQ4"]
[Mon Jul 27 09:35:00.992598 2026] [:error] [pid 17228:tid 140706911823616] [client 172.70.162.114:12153] [client 172.70.162.114] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJJjBQLO4t9VCDfo_kwAAAQ4"]
[Mon Jul 27 09:35:00.993062 2026] [:error] [pid 17228:tid 140706911823616] [client 172.70.162.114:12153] [client 172.70.162.114] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJJjBQLO4t9VCDfo_kwAAAQ4"]
[Mon Jul 27 09:35:00.993360 2026] [:error] [pid 17228:tid 140706911823616] [client 172.70.162.114:12153] [client 172.70.162.114] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJJjBQLO4t9VCDfo_kwAAAQ4"]
[Mon Jul 27 09:35:01.052767 2026] [:error] [pid 12275:tid 140706827896576] [client 172.69.130.114:12304] [client 172.69.130.114] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJXFwI8r7BFXGkAuEmwAAABg"]
[Mon Jul 27 09:35:01.053704 2026] [:error] [pid 12275:tid 140706827896576] [client 172.69.130.114:12304] [client 172.69.130.114] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJXFwI8r7BFXGkAuEmwAAABg"]
[Mon Jul 27 09:35:01.054141 2026] [:error] [pid 12275:tid 140706827896576] [client 172.69.130.114:12304] [client 172.69.130.114] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJXFwI8r7BFXGkAuEmwAAABg"]
[Mon Jul 27 09:35:01.054264 2026] [:error] [pid 12275:tid 140706827896576] [client 172.69.130.114:12304] [client 172.69.130.114] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJXFwI8r7BFXGkAuEmwAAABg"]
[Mon Jul 27 09:35:01.380515 2026] [:error] [pid 12275:tid 140706886645504] [client 104.22.20.127:10117] [client 104.22.20.127] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJXFwI8r7BFXGkAuEnQAAABE"]
[Mon Jul 27 09:35:01.381334 2026] [:error] [pid 12275:tid 140706886645504] [client 104.22.20.127:10117] [client 104.22.20.127] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJXFwI8r7BFXGkAuEnQAAABE"]
[Mon Jul 27 09:35:01.381731 2026] [:error] [pid 12275:tid 140706886645504] [client 104.22.20.127:10117] [client 104.22.20.127] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJXFwI8r7BFXGkAuEnQAAABE"]
[Mon Jul 27 09:35:01.381839 2026] [:error] [pid 12275:tid 140706886645504] [client 104.22.20.127:10117] [client 104.22.20.127] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJXFwI8r7BFXGkAuEnQAAABE"]
[Mon Jul 27 09:35:01.483911 2026] [:error] [pid 12276:tid 140706878252800] [client 104.23.190.103:10844] [client 104.23.190.103] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJecsEMuHmMYmk66V9wAAAFI"]
[Mon Jul 27 09:35:01.484638 2026] [:error] [pid 12276:tid 140706878252800] [client 104.23.190.103:10844] [client 104.23.190.103] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJecsEMuHmMYmk66V9wAAAFI"]
[Mon Jul 27 09:35:01.484942 2026] [:error] [pid 12276:tid 140706878252800] [client 104.23.190.103:10844] [client 104.23.190.103] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJecsEMuHmMYmk66V9wAAAFI"]
[Mon Jul 27 09:35:01.485009 2026] [:error] [pid 12276:tid 140706878252800] [client 104.23.190.103:10844] [client 104.23.190.103] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJecsEMuHmMYmk66V9wAAAFI"]
[Mon Jul 27 09:35:01.894216 2026] [:error] [pid 12276:tid 140706861467392] [client 162.159.113.45:11535] [client 162.159.113.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/console/"] [unique_id "amcKJecsEMuHmMYmk66V-gAAAFQ"]
[Mon Jul 27 09:35:01.895129 2026] [:error] [pid 12276:tid 140706861467392] [client 162.159.113.45:11535] [client 162.159.113.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/console/"] [unique_id "amcKJecsEMuHmMYmk66V-gAAAFQ"]
[Mon Jul 27 09:35:01.895594 2026] [:error] [pid 12276:tid 140706861467392] [client 162.159.113.45:11535] [client 162.159.113.45] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/console/"] [unique_id "amcKJecsEMuHmMYmk66V-gAAAFQ"]
[Mon Jul 27 09:35:01.895728 2026] [:error] [pid 12276:tid 140706861467392] [client 162.159.113.45:11535] [client 162.159.113.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/console/"] [unique_id "amcKJecsEMuHmMYmk66V-gAAAFQ"]
[Mon Jul 27 09:35:02.641127 2026] [:error] [pid 24106:tid 140706878252800] [client 162.158.63.138:14334] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/console/"] [unique_id "amcKJjs8oMu6f6EYbxSKHgAAAVI"]
[Mon Jul 27 09:35:02.642060 2026] [:error] [pid 24106:tid 140706878252800] [client 162.158.63.138:14334] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/console/"] [unique_id "amcKJjs8oMu6f6EYbxSKHgAAAVI"]
[Mon Jul 27 09:35:02.642516 2026] [:error] [pid 24106:tid 140706878252800] [client 162.158.63.138:14334] [client 162.158.63.138] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/console/"] [unique_id "amcKJjs8oMu6f6EYbxSKHgAAAVI"]
[Mon Jul 27 09:35:02.642638 2026] [:error] [pid 24106:tid 140706878252800] [client 162.158.63.138:14334] [client 162.158.63.138] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/console/"] [unique_id "amcKJjs8oMu6f6EYbxSKHgAAAVI"]
[Mon Jul 27 09:35:03.023423 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.183.36:10772] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server"] [unique_id "amcKJ5hXfYDIcpslIWOdEgAAAYE"]
[Mon Jul 27 09:35:03.024282 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.183.36:10772] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/server"] [unique_id "amcKJ5hXfYDIcpslIWOdEgAAAYE"]
[Mon Jul 27 09:35:03.024706 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.183.36:10772] [client 172.71.183.36] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/server"] [unique_id "amcKJ5hXfYDIcpslIWOdEgAAAYE"]
[Mon Jul 27 09:35:03.024804 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.183.36:10772] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/server"] [unique_id "amcKJ5hXfYDIcpslIWOdEgAAAYE"]
[Mon Jul 27 09:35:03.910040 2026] [:error] [pid 12276:tid 140706903430912] [client 172.71.98.106:10388] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server-status"] [unique_id "amcKJ-csEMuHmMYmk66V_QAAAE8"]
[Mon Jul 27 09:35:03.913790 2026] [authz_host:error] [pid 12276:tid 140706903430912] [client 172.71.98.106:10388] AH01753: access check of 'localhost' to /server-status failed, reason: unable to get the remote host name
[Mon Jul 27 09:35:03.913852 2026] [authz_core:error] [pid 12276:tid 140706903430912] [client 172.71.98.106:10388] AH01630: client denied by server configuration: /home/sbfconsu/sbf-consultancy.com/server-status
[Mon Jul 27 09:35:03.993453 2026] [:error] [pid 21545:tid 140707012536064] [client 172.69.95.103:9526] [client 172.69.95.103] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJ5hXfYDIcpslIWOdFgAAAYI"]
[Mon Jul 27 09:35:03.994105 2026] [:error] [pid 21545:tid 140707012536064] [client 172.69.95.103:9526] [client 172.69.95.103] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJ5hXfYDIcpslIWOdFgAAAYI"]
[Mon Jul 27 09:35:03.994438 2026] [:error] [pid 21545:tid 140707012536064] [client 172.69.95.103:9526] [client 172.69.95.103] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJ5hXfYDIcpslIWOdFgAAAYI"]
[Mon Jul 27 09:35:03.994507 2026] [:error] [pid 21545:tid 140707012536064] [client 172.69.95.103:9526] [client 172.69.95.103] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKJ5hXfYDIcpslIWOdFgAAAYI"]
[Mon Jul 27 09:35:04.193448 2026] [:error] [pid 12276:tid 140706945394432] [client 104.23.190.103:10844] [client 104.23.190.103] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server"] [unique_id "amcKKOcsEMuHmMYmk66V_gAAAEo"]
[Mon Jul 27 09:35:04.194203 2026] [:error] [pid 12276:tid 140706945394432] [client 104.23.190.103:10844] [client 104.23.190.103] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/server"] [unique_id "amcKKOcsEMuHmMYmk66V_gAAAEo"]
[Mon Jul 27 09:35:04.194523 2026] [:error] [pid 12276:tid 140706945394432] [client 104.23.190.103:10844] [client 104.23.190.103] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/server"] [unique_id "amcKKOcsEMuHmMYmk66V_gAAAEo"]
[Mon Jul 27 09:35:04.194622 2026] [:error] [pid 12276:tid 140706945394432] [client 104.23.190.103:10844] [client 104.23.190.103] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/server"] [unique_id "amcKKOcsEMuHmMYmk66V_gAAAEo"]
[Mon Jul 27 09:35:04.923652 2026] [:error] [pid 12276:tid 140706827896576] [client 172.71.203.17:11169] [client 172.71.203.17] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server-status"] [unique_id "amcKKOcsEMuHmMYmk66V_wAAAFg"]
[Mon Jul 27 09:35:04.931539 2026] [authz_host:error] [pid 12276:tid 140706827896576] [client 172.71.203.17:11169] AH01753: access check of 'localhost' to /server-status failed, reason: unable to get the remote host name
[Mon Jul 27 09:35:04.931627 2026] [authz_core:error] [pid 12276:tid 140706827896576] [client 172.71.203.17:11169] AH01630: client denied by server configuration: /home/sbfconsu/sbf-consultancy.com/server-status
[Mon Jul 27 09:35:05.904693 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.95.22:13810] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/about"] [unique_id "amcKKecsEMuHmMYmk66WAQAAAFM"]
[Mon Jul 27 09:35:05.905315 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.95.22:13810] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/about"] [unique_id "amcKKecsEMuHmMYmk66WAQAAAFM"]
[Mon Jul 27 09:35:05.905633 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.95.22:13810] [client 172.71.95.22] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/about"] [unique_id "amcKKecsEMuHmMYmk66WAQAAAFM"]
[Mon Jul 27 09:35:05.905704 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.95.22:13810] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/about"] [unique_id "amcKKecsEMuHmMYmk66WAQAAAFM"]
[Mon Jul 27 09:35:06.056189 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.203.17:11169] [client 172.71.203.17] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/about"] [unique_id "amcKKucsEMuHmMYmk66WAwAAAEg"]
[Mon Jul 27 09:35:06.057141 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.203.17:11169] [client 172.71.203.17] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/about"] [unique_id "amcKKucsEMuHmMYmk66WAwAAAEg"]
[Mon Jul 27 09:35:06.057607 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.203.17:11169] [client 172.71.203.17] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/about"] [unique_id "amcKKucsEMuHmMYmk66WAwAAAEg"]
[Mon Jul 27 09:35:06.057714 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.203.17:11169] [client 172.71.203.17] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/about"] [unique_id "amcKKucsEMuHmMYmk66WAwAAAEg"]
[Mon Jul 27 09:35:06.860815 2026] [:error] [pid 12275:tid 140706886645504] [client 104.23.187.75:13944] [client 104.23.187.75] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcKKnFwI8r7BFXGkAuErAAAABE"]
[Mon Jul 27 09:35:06.861841 2026] [:error] [pid 12275:tid 140706886645504] [client 104.23.187.75:13944] [client 104.23.187.75] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcKKnFwI8r7BFXGkAuErAAAABE"]
[Mon Jul 27 09:35:06.862271 2026] [:error] [pid 12275:tid 140706886645504] [client 104.23.187.75:13944] [client 104.23.187.75] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcKKnFwI8r7BFXGkAuErAAAABE"]
[Mon Jul 27 09:35:06.862399 2026] [:error] [pid 12275:tid 140706886645504] [client 104.23.187.75:13944] [client 104.23.187.75] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcKKnFwI8r7BFXGkAuErAAAABE"]
[Mon Jul 27 09:35:07.243935 2026] [:error] [pid 12276:tid 140706886645504] [client 172.71.95.22:13810] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcKK-csEMuHmMYmk66WBgAAAFE"]
[Mon Jul 27 09:35:07.244660 2026] [:error] [pid 12276:tid 140706886645504] [client 172.71.95.22:13810] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcKK-csEMuHmMYmk66WBgAAAFE"]
[Mon Jul 27 09:35:07.245003 2026] [:error] [pid 12276:tid 140706886645504] [client 172.71.95.22:13810] [client 172.71.95.22] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcKK-csEMuHmMYmk66WBgAAAFE"]
[Mon Jul 27 09:35:07.245077 2026] [:error] [pid 12276:tid 140706886645504] [client 172.71.95.22:13810] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcKK-csEMuHmMYmk66WBgAAAFE"]
[Mon Jul 27 09:35:07.801784 2026] [:error] [pid 12275:tid 140706911823616] [client 104.23.187.75:13944] [client 104.23.187.75] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKK3FwI8r7BFXGkAuErwAAAA4"]
[Mon Jul 27 09:35:07.802524 2026] [:error] [pid 12275:tid 140706911823616] [client 104.23.187.75:13944] [client 104.23.187.75] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKK3FwI8r7BFXGkAuErwAAAA4"]
[Mon Jul 27 09:35:07.802849 2026] [:error] [pid 12275:tid 140706911823616] [client 104.23.187.75:13944] [client 104.23.187.75] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKK3FwI8r7BFXGkAuErwAAAA4"]
[Mon Jul 27 09:35:07.802917 2026] [:error] [pid 12275:tid 140706911823616] [client 104.23.187.75:13944] [client 104.23.187.75] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKK3FwI8r7BFXGkAuErwAAAA4"]
[Mon Jul 27 09:35:07.902568 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKK5hXfYDIcpslIWOdHgAAAYE"]
[Mon Jul 27 09:35:07.903405 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKK5hXfYDIcpslIWOdHgAAAYE"]
[Mon Jul 27 09:35:07.903807 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKK5hXfYDIcpslIWOdHgAAAYE"]
[Mon Jul 27 09:35:07.903911 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKK5hXfYDIcpslIWOdHgAAAYE"]
[Mon Jul 27 09:35:07.962473 2026] [:error] [pid 21545:tid 140706995750656] [client 141.101.76.32:14153] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcKK5hXfYDIcpslIWOdHwAAAYQ"]
[Mon Jul 27 09:35:07.963361 2026] [:error] [pid 21545:tid 140706995750656] [client 141.101.76.32:14153] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcKK5hXfYDIcpslIWOdHwAAAYQ"]
[Mon Jul 27 09:35:07.963885 2026] [:error] [pid 21545:tid 140706995750656] [client 141.101.76.32:14153] [client 141.101.76.32] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcKK5hXfYDIcpslIWOdHwAAAYQ"]
[Mon Jul 27 09:35:07.964017 2026] [:error] [pid 21545:tid 140706995750656] [client 141.101.76.32:14153] [client 141.101.76.32] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcKK5hXfYDIcpslIWOdHwAAAYQ"]
[Mon Jul 27 09:35:08.018073 2026] [:error] [pid 21545:tid 140706920216320] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcKLJhXfYDIcpslIWOdIQAAAY0"]
[Mon Jul 27 09:35:08.019168 2026] [:error] [pid 21545:tid 140706920216320] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcKLJhXfYDIcpslIWOdIQAAAY0"]
[Mon Jul 27 09:35:08.019652 2026] [:error] [pid 21545:tid 140706920216320] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcKLJhXfYDIcpslIWOdIQAAAY0"]
[Mon Jul 27 09:35:08.019763 2026] [:error] [pid 21545:tid 140706920216320] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcKLJhXfYDIcpslIWOdIQAAAY0"]
[Mon Jul 27 09:35:08.229245 2026] [:error] [pid 12275:tid 140706903430912] [client 104.23.187.75:13944] [client 104.23.187.75] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcKLHFwI8r7BFXGkAuEsQAAAA8"]
[Mon Jul 27 09:35:08.229977 2026] [:error] [pid 12275:tid 140706903430912] [client 104.23.187.75:13944] [client 104.23.187.75] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcKLHFwI8r7BFXGkAuEsQAAAA8"]
[Mon Jul 27 09:35:08.230284 2026] [:error] [pid 12275:tid 140706903430912] [client 104.23.187.75:13944] [client 104.23.187.75] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcKLHFwI8r7BFXGkAuEsQAAAA8"]
[Mon Jul 27 09:35:08.230353 2026] [:error] [pid 12275:tid 140706903430912] [client 104.23.187.75:13944] [client 104.23.187.75] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcKLHFwI8r7BFXGkAuEsQAAAA8"]
[Mon Jul 27 09:35:08.299496 2026] [:error] [pid 12276:tid 140706945394432] [client 104.23.168.4:11296] [client 104.23.168.4] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/v2/_catalog"] [unique_id "amcKLOcsEMuHmMYmk66WCQAAAEo"]
[Mon Jul 27 09:35:08.300572 2026] [:error] [pid 12276:tid 140706945394432] [client 104.23.168.4:11296] [client 104.23.168.4] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/v2/_catalog"] [unique_id "amcKLOcsEMuHmMYmk66WCQAAAEo"]
[Mon Jul 27 09:35:08.301090 2026] [:error] [pid 12276:tid 140706945394432] [client 104.23.168.4:11296] [client 104.23.168.4] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/v2/_catalog"] [unique_id "amcKLOcsEMuHmMYmk66WCQAAAEo"]
[Mon Jul 27 09:35:08.773963 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.63.138:12056] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcKLOcsEMuHmMYmk66WCgAAAEU"]
[Mon Jul 27 09:35:08.774640 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.63.138:12056] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcKLOcsEMuHmMYmk66WCgAAAEU"]
[Mon Jul 27 09:35:08.774988 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.63.138:12056] [client 162.158.63.138] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcKLOcsEMuHmMYmk66WCgAAAEU"]
[Mon Jul 27 09:35:08.775064 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.63.138:12056] [client 162.158.63.138] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcKLOcsEMuHmMYmk66WCgAAAEU"]
[Mon Jul 27 09:35:09.162985 2026] [:error] [pid 21545:tid 140706928609024] [client 162.159.119.40:10438] [client 162.159.119.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/v2/_catalog"] [unique_id "amcKLZhXfYDIcpslIWOdIwAAAYw"]
[Mon Jul 27 09:35:09.163914 2026] [:error] [pid 21545:tid 140706928609024] [client 162.159.119.40:10438] [client 162.159.119.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/v2/_catalog"] [unique_id "amcKLZhXfYDIcpslIWOdIwAAAYw"]
[Mon Jul 27 09:35:09.164430 2026] [:error] [pid 21545:tid 140706928609024] [client 162.159.119.40:10438] [client 162.159.119.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/v2/_catalog"] [unique_id "amcKLZhXfYDIcpslIWOdIwAAAYw"]
[Mon Jul 27 09:35:09.439866 2026] [:error] [pid 12276:tid 140707004143360] [client 172.70.46.165:9865] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcKLecsEMuHmMYmk66WDAAAAEM"]
[Mon Jul 27 09:35:09.440761 2026] [:error] [pid 12276:tid 140707004143360] [client 172.70.46.165:9865] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcKLecsEMuHmMYmk66WDAAAAEM"]
[Mon Jul 27 09:35:09.441101 2026] [:error] [pid 12276:tid 140707004143360] [client 172.70.46.165:9865] [client 172.70.46.165] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcKLecsEMuHmMYmk66WDAAAAEM"]
[Mon Jul 27 09:35:09.441186 2026] [:error] [pid 12276:tid 140707004143360] [client 172.70.46.165:9865] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcKLecsEMuHmMYmk66WDAAAAEM"]
[Mon Jul 27 09:35:09.441351 2026] [:error] [pid 12276:tid 140707004143360] [client 172.70.46.165:9865] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcKLecsEMuHmMYmk66WDAAAAEM"]
[Mon Jul 27 09:35:09.895585 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.63.138:12056] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcKLecsEMuHmMYmk66WDQAAAFY"]
[Mon Jul 27 09:35:09.896418 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.63.138:12056] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcKLecsEMuHmMYmk66WDQAAAFY"]
[Mon Jul 27 09:35:09.896874 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.63.138:12056] [client 162.158.63.138] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcKLecsEMuHmMYmk66WDQAAAFY"]
[Mon Jul 27 09:35:09.896983 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.63.138:12056] [client 162.158.63.138] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcKLecsEMuHmMYmk66WDQAAAFY"]
[Mon Jul 27 09:35:09.897227 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.63.138:12056] [client 162.158.63.138] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcKLecsEMuHmMYmk66WDQAAAFY"]
[Mon Jul 27 09:35:10.305384 2026] [:error] [pid 17228:tid 140706987357952] [client 104.23.170.162:11109] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKLpjBQLO4t9VCDfo_lAAAAQU"]
[Mon Jul 27 09:35:10.306233 2026] [:error] [pid 17228:tid 140706987357952] [client 104.23.170.162:11109] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKLpjBQLO4t9VCDfo_lAAAAQU"]
[Mon Jul 27 09:35:10.306631 2026] [:error] [pid 17228:tid 140706987357952] [client 104.23.170.162:11109] [client 104.23.170.162] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKLpjBQLO4t9VCDfo_lAAAAQU"]
[Mon Jul 27 09:35:10.306740 2026] [:error] [pid 17228:tid 140706987357952] [client 104.23.170.162:11109] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKLpjBQLO4t9VCDfo_lAAAAQU"]
[Mon Jul 27 09:35:10.306888 2026] [:error] [pid 17228:tid 140706987357952] [client 104.23.170.162:11109] [client 104.23.170.162] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKLpjBQLO4t9VCDfo_lAAAAQU"]
[Mon Jul 27 09:35:10.924862 2026] [:error] [pid 21545:tid 140706836289280] [client 162.159.119.40:10438] [client 162.159.119.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKLphXfYDIcpslIWOdJgAAAZc"]
[Mon Jul 27 09:35:10.925721 2026] [:error] [pid 21545:tid 140706836289280] [client 162.159.119.40:10438] [client 162.159.119.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKLphXfYDIcpslIWOdJgAAAZc"]
[Mon Jul 27 09:35:10.926139 2026] [:error] [pid 21545:tid 140706836289280] [client 162.159.119.40:10438] [client 162.159.119.40] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKLphXfYDIcpslIWOdJgAAAZc"]
[Mon Jul 27 09:35:10.926280 2026] [:error] [pid 21545:tid 140706836289280] [client 162.159.119.40:10438] [client 162.159.119.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKLphXfYDIcpslIWOdJgAAAZc"]
[Mon Jul 27 09:35:10.926521 2026] [:error] [pid 21545:tid 140706836289280] [client 162.159.119.40:10438] [client 162.159.119.40] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKLphXfYDIcpslIWOdJgAAAZc"]
[Mon Jul 27 09:35:12.289686 2026] [:error] [pid 21545:tid 140706945394432] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcKMJhXfYDIcpslIWOdKgAAAYo"]
[Mon Jul 27 09:35:12.290868 2026] [:error] [pid 21545:tid 140706945394432] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcKMJhXfYDIcpslIWOdKgAAAYo"]
[Mon Jul 27 09:35:12.291407 2026] [:error] [pid 21545:tid 140706945394432] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcKMJhXfYDIcpslIWOdKgAAAYo"]
[Mon Jul 27 09:35:12.291546 2026] [:error] [pid 21545:tid 140706945394432] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcKMJhXfYDIcpslIWOdKgAAAYo"]
[Mon Jul 27 09:35:12.887635 2026] [:error] [pid 21545:tid 140706995750656] [client 162.159.119.40:10438] [client 162.159.119.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcKMJhXfYDIcpslIWOdLAAAAYQ"]
[Mon Jul 27 09:35:12.888242 2026] [:error] [pid 21545:tid 140706995750656] [client 162.159.119.40:10438] [client 162.159.119.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcKMJhXfYDIcpslIWOdLAAAAYQ"]
[Mon Jul 27 09:35:12.888590 2026] [:error] [pid 21545:tid 140706995750656] [client 162.159.119.40:10438] [client 162.159.119.40] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcKMJhXfYDIcpslIWOdLAAAAYQ"]
[Mon Jul 27 09:35:12.888663 2026] [:error] [pid 21545:tid 140706995750656] [client 162.159.119.40:10438] [client 162.159.119.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcKMJhXfYDIcpslIWOdLAAAAYQ"]
[Mon Jul 27 09:35:14.313329 2026] [:error] [pid 21545:tid 140706928609024] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKMphXfYDIcpslIWOdMAAAAYw"]
[Mon Jul 27 09:35:14.314267 2026] [:error] [pid 21545:tid 140706928609024] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKMphXfYDIcpslIWOdMAAAAYw"]
[Mon Jul 27 09:35:14.314704 2026] [:error] [pid 21545:tid 140706928609024] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKMphXfYDIcpslIWOdMAAAAYw"]
[Mon Jul 27 09:35:14.314831 2026] [:error] [pid 21545:tid 140706928609024] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKMphXfYDIcpslIWOdMAAAAYw"]
[Mon Jul 27 09:35:14.315055 2026] [:error] [pid 21545:tid 140706928609024] [client 104.23.166.82:14238] [client 104.23.166.82] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKMphXfYDIcpslIWOdMAAAAYw"]
[Mon Jul 27 09:35:15.158055 2026] [:error] [pid 24106:tid 140706878252800] [client 162.158.159.222:9498] [client 162.158.159.222] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKMzs8oMu6f6EYbxSKKgAAAVI"]
[Mon Jul 27 09:35:15.159007 2026] [:error] [pid 24106:tid 140706878252800] [client 162.158.159.222:9498] [client 162.158.159.222] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKMzs8oMu6f6EYbxSKKgAAAVI"]
[Mon Jul 27 09:35:15.159463 2026] [:error] [pid 24106:tid 140706878252800] [client 162.158.159.222:9498] [client 162.158.159.222] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKMzs8oMu6f6EYbxSKKgAAAVI"]
[Mon Jul 27 09:35:15.160535 2026] [:error] [pid 24106:tid 140706878252800] [client 162.158.159.222:9498] [client 162.158.159.222] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKMzs8oMu6f6EYbxSKKgAAAVI"]
[Mon Jul 27 09:35:15.160971 2026] [:error] [pid 24106:tid 140706878252800] [client 162.158.159.222:9498] [client 162.158.159.222] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKMzs8oMu6f6EYbxSKKgAAAVI"]
[Mon Jul 27 09:35:15.329240 2026] [:error] [pid 12276:tid 140707004143360] [client 172.70.46.165:10029] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcKM-csEMuHmMYmk66WEgAAAEM"]
[Mon Jul 27 09:35:15.330133 2026] [:error] [pid 12276:tid 140707004143360] [client 172.70.46.165:10029] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcKM-csEMuHmMYmk66WEgAAAEM"]
[Mon Jul 27 09:35:15.330399 2026] [:error] [pid 12276:tid 140707004143360] [client 172.70.46.165:10029] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcKM-csEMuHmMYmk66WEgAAAEM"]
[Mon Jul 27 09:35:15.330639 2026] [:error] [pid 12276:tid 140707004143360] [client 172.70.46.165:10029] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcKM-csEMuHmMYmk66WEgAAAEM"]
[Mon Jul 27 09:35:15.383111 2026] [:error] [pid 24106:tid 140706903430912] [client 162.159.113.45:12273] [client 162.159.113.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api"] [unique_id "amcKMzs8oMu6f6EYbxSKLAAAAU8"]
[Mon Jul 27 09:35:15.384179 2026] [:error] [pid 24106:tid 140706903430912] [client 162.159.113.45:12273] [client 162.159.113.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api"] [unique_id "amcKMzs8oMu6f6EYbxSKLAAAAU8"]
[Mon Jul 27 09:35:15.384504 2026] [:error] [pid 24106:tid 140706903430912] [client 162.159.113.45:12273] [client 162.159.113.45] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api"] [unique_id "amcKMzs8oMu6f6EYbxSKLAAAAU8"]
[Mon Jul 27 09:35:15.384930 2026] [:error] [pid 24106:tid 140706903430912] [client 162.159.113.45:12273] [client 162.159.113.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api"] [unique_id "amcKMzs8oMu6f6EYbxSKLAAAAU8"]
[Mon Jul 27 09:35:15.429631 2026] [:error] [pid 24106:tid 140706920216320] [client 162.159.113.45:12273] [client 162.159.113.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcKMzs8oMu6f6EYbxSKLQAAAU0"]
[Mon Jul 27 09:35:15.430796 2026] [:error] [pid 24106:tid 140706920216320] [client 162.159.113.45:12273] [client 162.159.113.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcKMzs8oMu6f6EYbxSKLQAAAU0"]
[Mon Jul 27 09:35:15.431088 2026] [:error] [pid 24106:tid 140706920216320] [client 162.159.113.45:12273] [client 162.159.113.45] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcKMzs8oMu6f6EYbxSKLQAAAU0"]
[Mon Jul 27 09:35:15.431490 2026] [:error] [pid 24106:tid 140706920216320] [client 162.159.113.45:12273] [client 162.159.113.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcKMzs8oMu6f6EYbxSKLQAAAU0"]
[Mon Jul 27 09:35:15.524450 2026] [:error] [pid 21545:tid 140706878252800] [client 104.23.172.124:12696] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcKM5hXfYDIcpslIWOdMwAAAZI"]
[Mon Jul 27 09:35:15.525456 2026] [:error] [pid 21545:tid 140706878252800] [client 104.23.172.124:12696] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcKM5hXfYDIcpslIWOdMwAAAZI"]
[Mon Jul 27 09:35:15.525786 2026] [:error] [pid 21545:tid 140706878252800] [client 104.23.172.124:12696] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcKM5hXfYDIcpslIWOdMwAAAZI"]
[Mon Jul 27 09:35:15.526085 2026] [:error] [pid 21545:tid 140706878252800] [client 104.23.172.124:12696] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcKM5hXfYDIcpslIWOdMwAAAZI"]
[Mon Jul 27 09:35:15.940108 2026] [:error] [pid 21545:tid 140706937001728] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcKM5hXfYDIcpslIWOdNQAAAYs"]
[Mon Jul 27 09:35:15.940900 2026] [:error] [pid 21545:tid 140706937001728] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcKM5hXfYDIcpslIWOdNQAAAYs"]
[Mon Jul 27 09:35:15.941163 2026] [:error] [pid 21545:tid 140706937001728] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcKM5hXfYDIcpslIWOdNQAAAYs"]
[Mon Jul 27 09:35:15.941464 2026] [:error] [pid 21545:tid 140706937001728] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcKM5hXfYDIcpslIWOdNQAAAYs"]
[Mon Jul 27 09:35:16.315955 2026] [:error] [pid 21545:tid 140706987357952] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcKNJhXfYDIcpslIWOdNgAAAYU"]
[Mon Jul 27 09:35:16.316793 2026] [:error] [pid 21545:tid 140706987357952] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcKNJhXfYDIcpslIWOdNgAAAYU"]
[Mon Jul 27 09:35:16.317192 2026] [:error] [pid 21545:tid 140706987357952] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcKNJhXfYDIcpslIWOdNgAAAYU"]
[Mon Jul 27 09:35:16.317299 2026] [:error] [pid 21545:tid 140706987357952] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcKNJhXfYDIcpslIWOdNgAAAYU"]
[Mon Jul 27 09:35:16.350238 2026] [:error] [pid 12380:tid 140706861467392] [client 104.23.190.102:10527] [client 104.23.190.102] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcKNKaChfbWW0CZ_hrc8gAAANQ"]
[Mon Jul 27 09:35:16.351121 2026] [:error] [pid 12380:tid 140706861467392] [client 104.23.190.102:10527] [client 104.23.190.102] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcKNKaChfbWW0CZ_hrc8gAAANQ"]
[Mon Jul 27 09:35:16.351382 2026] [:error] [pid 12380:tid 140706861467392] [client 104.23.190.102:10527] [client 104.23.190.102] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcKNKaChfbWW0CZ_hrc8gAAANQ"]
[Mon Jul 27 09:35:16.351614 2026] [:error] [pid 12380:tid 140706861467392] [client 104.23.190.102:10527] [client 104.23.190.102] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcKNKaChfbWW0CZ_hrc8gAAANQ"]
[Mon Jul 27 09:35:16.736198 2026] [:error] [pid 12380:tid 140706844681984] [client 104.23.187.75:10644] [client 104.23.187.75] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api"] [unique_id "amcKNKaChfbWW0CZ_hrc8wAAANY"]
[Mon Jul 27 09:35:16.737392 2026] [:error] [pid 12380:tid 140706844681984] [client 104.23.187.75:10644] [client 104.23.187.75] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api"] [unique_id "amcKNKaChfbWW0CZ_hrc8wAAANY"]
[Mon Jul 27 09:35:16.737759 2026] [:error] [pid 12380:tid 140706844681984] [client 104.23.187.75:10644] [client 104.23.187.75] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api"] [unique_id "amcKNKaChfbWW0CZ_hrc8wAAANY"]
[Mon Jul 27 09:35:16.738162 2026] [:error] [pid 12380:tid 140706844681984] [client 104.23.187.75:10644] [client 104.23.187.75] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api"] [unique_id "amcKNKaChfbWW0CZ_hrc8wAAANY"]
[Mon Jul 27 09:35:17.117504 2026] [:error] [pid 12276:tid 140706962179840] [client 172.70.231.63:11674] [client 172.70.231.63] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcKNecsEMuHmMYmk66WFgAAAEg"]
[Mon Jul 27 09:35:17.118406 2026] [:error] [pid 12276:tid 140706962179840] [client 172.70.231.63:11674] [client 172.70.231.63] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcKNecsEMuHmMYmk66WFgAAAEg"]
[Mon Jul 27 09:35:17.118711 2026] [:error] [pid 12276:tid 140706962179840] [client 172.70.231.63:11674] [client 172.70.231.63] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcKNecsEMuHmMYmk66WFgAAAEg"]
[Mon Jul 27 09:35:17.119018 2026] [:error] [pid 12276:tid 140706962179840] [client 172.70.231.63:11674] [client 172.70.231.63] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcKNecsEMuHmMYmk66WFgAAAEg"]
[Mon Jul 27 09:35:17.324314 2026] [:error] [pid 12276:tid 140706928609024] [client 172.71.98.107:12477] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcKNecsEMuHmMYmk66WFwAAAEw"]
[Mon Jul 27 09:35:17.325156 2026] [:error] [pid 12276:tid 140706928609024] [client 172.71.98.107:12477] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcKNecsEMuHmMYmk66WFwAAAEw"]
[Mon Jul 27 09:35:17.325473 2026] [:error] [pid 12276:tid 140706928609024] [client 172.71.98.107:12477] [client 172.71.98.107] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcKNecsEMuHmMYmk66WFwAAAEw"]
[Mon Jul 27 09:35:17.325539 2026] [:error] [pid 12276:tid 140706928609024] [client 172.71.98.107:12477] [client 172.71.98.107] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcKNecsEMuHmMYmk66WFwAAAEw"]
[Mon Jul 27 09:35:17.492466 2026] [:error] [pid 12380:tid 140706937001728] [client 162.158.63.138:11773] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcKNaaChfbWW0CZ_hrc9AAAAMs"]
[Mon Jul 27 09:35:17.493518 2026] [:error] [pid 12380:tid 140706937001728] [client 162.158.63.138:11773] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcKNaaChfbWW0CZ_hrc9AAAAMs"]
[Mon Jul 27 09:35:17.493917 2026] [:error] [pid 12380:tid 140706937001728] [client 162.158.63.138:11773] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcKNaaChfbWW0CZ_hrc9AAAAMs"]
[Mon Jul 27 09:35:17.494373 2026] [:error] [pid 12380:tid 140706937001728] [client 162.158.63.138:11773] [client 162.158.63.138] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcKNaaChfbWW0CZ_hrc9AAAAMs"]
[Mon Jul 27 09:35:17.964714 2026] [:error] [pid 24106:tid 140706928609024] [client 162.158.159.222:9498] [client 162.158.159.222] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcKNTs8oMu6f6EYbxSKMQAAAUw"]
[Mon Jul 27 09:35:17.965787 2026] [:error] [pid 24106:tid 140706928609024] [client 162.158.159.222:9498] [client 162.158.159.222] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcKNTs8oMu6f6EYbxSKMQAAAUw"]
[Mon Jul 27 09:35:17.966135 2026] [:error] [pid 24106:tid 140706928609024] [client 162.158.159.222:9498] [client 162.158.159.222] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcKNTs8oMu6f6EYbxSKMQAAAUw"]
[Mon Jul 27 09:35:17.966526 2026] [:error] [pid 24106:tid 140706928609024] [client 162.158.159.222:9498] [client 162.158.159.222] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcKNTs8oMu6f6EYbxSKMQAAAUw"]
[Mon Jul 27 09:35:18.262360 2026] [:error] [pid 12380:tid 140706886645504] [client 104.23.190.102:10527] [client 104.23.190.102] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcKNqaChfbWW0CZ_hrc9gAAANE"]
[Mon Jul 27 09:35:18.263416 2026] [:error] [pid 12380:tid 140706886645504] [client 104.23.190.102:10527] [client 104.23.190.102] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcKNqaChfbWW0CZ_hrc9gAAANE"]
[Mon Jul 27 09:35:18.263944 2026] [:error] [pid 12380:tid 140706886645504] [client 104.23.190.102:10527] [client 104.23.190.102] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcKNqaChfbWW0CZ_hrc9gAAANE"]
[Mon Jul 27 09:35:18.264072 2026] [:error] [pid 12380:tid 140706886645504] [client 104.23.190.102:10527] [client 104.23.190.102] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcKNqaChfbWW0CZ_hrc9gAAANE"]
[Mon Jul 27 09:35:19.456671 2026] [:error] [pid 12275:tid 140706945394432] [client 104.23.253.27:10710] [client 104.23.253.27] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcKN3FwI8r7BFXGkAuExwAAAAo"]
[Mon Jul 27 09:35:19.457600 2026] [:error] [pid 12275:tid 140706945394432] [client 104.23.253.27:10710] [client 104.23.253.27] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcKN3FwI8r7BFXGkAuExwAAAAo"]
[Mon Jul 27 09:35:19.457992 2026] [:error] [pid 12275:tid 140706945394432] [client 104.23.253.27:10710] [client 104.23.253.27] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcKN3FwI8r7BFXGkAuExwAAAAo"]
[Mon Jul 27 09:35:19.458065 2026] [:error] [pid 12275:tid 140706945394432] [client 104.23.253.27:10710] [client 104.23.253.27] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcKN3FwI8r7BFXGkAuExwAAAAo"]
[Mon Jul 27 09:35:19.504290 2026] [:error] [pid 21545:tid 140707004143360] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcKN5hXfYDIcpslIWOdOgAAAYM"]
[Mon Jul 27 09:35:19.504947 2026] [:error] [pid 21545:tid 140707004143360] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcKN5hXfYDIcpslIWOdOgAAAYM"]
[Mon Jul 27 09:35:19.505335 2026] [:error] [pid 21545:tid 140707004143360] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcKN5hXfYDIcpslIWOdOgAAAYM"]
[Mon Jul 27 09:35:19.505422 2026] [:error] [pid 21545:tid 140707004143360] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcKN5hXfYDIcpslIWOdOgAAAYM"]
[Mon Jul 27 09:35:19.695786 2026] [:error] [pid 12276:tid 140707012536064] [client 172.70.46.165:10029] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcKN-csEMuHmMYmk66WGgAAAEI"]
[Mon Jul 27 09:35:19.696422 2026] [:error] [pid 12276:tid 140707012536064] [client 172.70.46.165:10029] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcKN-csEMuHmMYmk66WGgAAAEI"]
[Mon Jul 27 09:35:19.696819 2026] [:error] [pid 12276:tid 140707012536064] [client 172.70.46.165:10029] [client 172.70.46.165] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcKN-csEMuHmMYmk66WGgAAAEI"]
[Mon Jul 27 09:35:19.696903 2026] [:error] [pid 12276:tid 140707012536064] [client 172.70.46.165:10029] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcKN-csEMuHmMYmk66WGgAAAEI"]
[Mon Jul 27 09:35:20.157423 2026] [:error] [pid 12275:tid 140706844681984] [client 104.23.253.27:10710] [client 104.23.253.27] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcKOHFwI8r7BFXGkAuEyQAAABY"]
[Mon Jul 27 09:35:20.158278 2026] [:error] [pid 12275:tid 140706844681984] [client 104.23.253.27:10710] [client 104.23.253.27] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcKOHFwI8r7BFXGkAuEyQAAABY"]
[Mon Jul 27 09:35:20.158802 2026] [:error] [pid 12275:tid 140706844681984] [client 104.23.253.27:10710] [client 104.23.253.27] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcKOHFwI8r7BFXGkAuEyQAAABY"]
[Mon Jul 27 09:35:20.158954 2026] [:error] [pid 12275:tid 140706844681984] [client 104.23.253.27:10710] [client 104.23.253.27] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcKOHFwI8r7BFXGkAuEyQAAABY"]
[Mon Jul 27 09:35:20.579806 2026] [:error] [pid 24106:tid 140706937001728] [client 172.69.22.192:9512] [client 172.69.22.192] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKODs8oMu6f6EYbxSKNAAAAUs"]
[Mon Jul 27 09:35:20.580732 2026] [:error] [pid 24106:tid 140706937001728] [client 172.69.22.192:9512] [client 172.69.22.192] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKODs8oMu6f6EYbxSKNAAAAUs"]
[Mon Jul 27 09:35:20.581309 2026] [:error] [pid 24106:tid 140706937001728] [client 172.69.22.192:9512] [client 172.69.22.192] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua=Google Chrome\\x22;v=\\x22111\\x22, \\x22Not(A:Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22111"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKODs8oMu6f6EYbxSKNAAAAUs"]
[Mon Jul 27 09:35:20.581370 2026] [:error] [pid 24106:tid 140706937001728] [client 172.69.22.192:9512] [client 172.69.22.192] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKODs8oMu6f6EYbxSKNAAAAUs"]
[Mon Jul 27 09:35:20.665759 2026] [:error] [pid 24106:tid 140706911823616] [client 172.71.183.36:12910] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcKODs8oMu6f6EYbxSKNQAAAU4"]
[Mon Jul 27 09:35:20.666636 2026] [:error] [pid 24106:tid 140706911823616] [client 172.71.183.36:12910] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcKODs8oMu6f6EYbxSKNQAAAU4"]
[Mon Jul 27 09:35:20.667056 2026] [:error] [pid 24106:tid 140706911823616] [client 172.71.183.36:12910] [client 172.71.183.36] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcKODs8oMu6f6EYbxSKNQAAAU4"]
[Mon Jul 27 09:35:20.667196 2026] [:error] [pid 24106:tid 140706911823616] [client 172.71.183.36:12910] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcKODs8oMu6f6EYbxSKNQAAAU4"]
[Mon Jul 27 09:35:21.447393 2026] [:error] [pid 12275:tid 140706878252800] [client 172.71.203.17:10766] [client 172.71.203.17] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcKOXFwI8r7BFXGkAuEzQAAABI"]
[Mon Jul 27 09:35:21.448187 2026] [:error] [pid 12275:tid 140706878252800] [client 172.71.203.17:10766] [client 172.71.203.17] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcKOXFwI8r7BFXGkAuEzQAAABI"]
[Mon Jul 27 09:35:21.448493 2026] [:error] [pid 12275:tid 140706878252800] [client 172.71.203.17:10766] [client 172.71.203.17] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcKOXFwI8r7BFXGkAuEzQAAABI"]
[Mon Jul 27 09:35:21.448592 2026] [:error] [pid 12275:tid 140706878252800] [client 172.71.203.17:10766] [client 172.71.203.17] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcKOXFwI8r7BFXGkAuEzQAAABI"]
[Mon Jul 27 09:35:21.716922 2026] [:error] [pid 12276:tid 140707103270656] [client 162.159.113.44:10041] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcKOecsEMuHmMYmk66WIAAAAEA"]
[Mon Jul 27 09:35:21.717846 2026] [:error] [pid 12276:tid 140707103270656] [client 162.159.113.44:10041] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcKOecsEMuHmMYmk66WIAAAAEA"]
[Mon Jul 27 09:35:21.718276 2026] [:error] [pid 12276:tid 140707103270656] [client 162.159.113.44:10041] [client 162.159.113.44] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcKOecsEMuHmMYmk66WIAAAAEA"]
[Mon Jul 27 09:35:21.718381 2026] [:error] [pid 12276:tid 140707103270656] [client 162.159.113.44:10041] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcKOecsEMuHmMYmk66WIAAAAEA"]
[Mon Jul 27 09:35:22.208088 2026] [:error] [pid 12380:tid 140706953787136] [client 162.158.63.138:11773] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcKOqaChfbWW0CZ_hrc9wAAAMk"]
[Mon Jul 27 09:35:22.209058 2026] [:error] [pid 12380:tid 140706953787136] [client 162.158.63.138:11773] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcKOqaChfbWW0CZ_hrc9wAAAMk"]
[Mon Jul 27 09:35:22.209535 2026] [:error] [pid 12380:tid 140706953787136] [client 162.158.63.138:11773] [client 162.158.63.138] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcKOqaChfbWW0CZ_hrc9wAAAMk"]
[Mon Jul 27 09:35:22.209667 2026] [:error] [pid 12380:tid 140706953787136] [client 162.158.63.138:11773] [client 162.158.63.138] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcKOqaChfbWW0CZ_hrc9wAAAMk"]
[Mon Jul 27 09:35:22.492576 2026] [:error] [pid 12275:tid 140706928609024] [client 104.23.253.27:10710] [client 104.23.253.27] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKOnFwI8r7BFXGkAuE0QAAAAw"]
[Mon Jul 27 09:35:22.493506 2026] [:error] [pid 12275:tid 140706928609024] [client 104.23.253.27:10710] [client 104.23.253.27] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKOnFwI8r7BFXGkAuE0QAAAAw"]
[Mon Jul 27 09:35:22.493923 2026] [:error] [pid 12275:tid 140706928609024] [client 104.23.253.27:10710] [client 104.23.253.27] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua=Google Chrome\\x22;v=\\x22111\\x22, \\x22Not(A:Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22111"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKOnFwI8r7BFXGkAuE0QAAAAw"]
[Mon Jul 27 09:35:22.493981 2026] [:error] [pid 12275:tid 140706928609024] [client 104.23.253.27:10710] [client 104.23.253.27] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKOnFwI8r7BFXGkAuE0QAAAAw"]
[Mon Jul 27 09:35:22.674865 2026] [:error] [pid 24106:tid 140706895038208] [client 104.23.172.125:13193] [client 104.23.172.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcKOjs8oMu6f6EYbxSKOQAAAVA"]
[Mon Jul 27 09:35:22.675762 2026] [:error] [pid 24106:tid 140706895038208] [client 104.23.172.125:13193] [client 104.23.172.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcKOjs8oMu6f6EYbxSKOQAAAVA"]
[Mon Jul 27 09:35:22.676211 2026] [:error] [pid 24106:tid 140706895038208] [client 104.23.172.125:13193] [client 104.23.172.125] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcKOjs8oMu6f6EYbxSKOQAAAVA"]
[Mon Jul 27 09:35:22.676315 2026] [:error] [pid 24106:tid 140706895038208] [client 104.23.172.125:13193] [client 104.23.172.125] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcKOjs8oMu6f6EYbxSKOQAAAVA"]
[Mon Jul 27 09:35:23.406297 2026] [:error] [pid 12380:tid 140706970572544] [client 172.71.103.41:13784] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKO6aChfbWW0CZ_hrc-AAAAMc"]
[Mon Jul 27 09:35:23.407304 2026] [:error] [pid 12380:tid 140706970572544] [client 172.71.103.41:13784] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKO6aChfbWW0CZ_hrc-AAAAMc"]
[Mon Jul 27 09:35:23.407876 2026] [:error] [pid 12380:tid 140706970572544] [client 172.71.103.41:13784] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKO6aChfbWW0CZ_hrc-AAAAMc"]
[Mon Jul 27 09:35:23.454532 2026] [:error] [pid 12380:tid 140706853074688] [client 162.158.63.138:11773] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcKO6aChfbWW0CZ_hrc-QAAANU"]
[Mon Jul 27 09:35:23.455956 2026] [:error] [pid 12380:tid 140706853074688] [client 162.158.63.138:11773] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcKO6aChfbWW0CZ_hrc-QAAANU"]
[Mon Jul 27 09:35:23.456527 2026] [:error] [pid 12380:tid 140706853074688] [client 162.158.63.138:11773] [client 162.158.63.138] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcKO6aChfbWW0CZ_hrc-QAAANU"]
[Mon Jul 27 09:35:23.456716 2026] [:error] [pid 12380:tid 140706853074688] [client 162.158.63.138:11773] [client 162.158.63.138] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcKO6aChfbWW0CZ_hrc-QAAANU"]
[Mon Jul 27 09:35:23.634126 2026] [:error] [pid 21545:tid 140706995750656] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config"] [unique_id "amcKO5hXfYDIcpslIWOdQgAAAYQ"]
[Mon Jul 27 09:35:23.634897 2026] [:error] [pid 21545:tid 140706995750656] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config"] [unique_id "amcKO5hXfYDIcpslIWOdQgAAAYQ"]
[Mon Jul 27 09:35:23.635323 2026] [:error] [pid 21545:tid 140706995750656] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config"] [unique_id "amcKO5hXfYDIcpslIWOdQgAAAYQ"]
[Mon Jul 27 09:35:23.707314 2026] [:error] [pid 21545:tid 140706886645504] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcKO5hXfYDIcpslIWOdQwAAAZE"]
[Mon Jul 27 09:35:23.708323 2026] [:error] [pid 21545:tid 140706886645504] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcKO5hXfYDIcpslIWOdQwAAAZE"]
[Mon Jul 27 09:35:23.708829 2026] [:error] [pid 21545:tid 140706886645504] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcKO5hXfYDIcpslIWOdQwAAAZE"]
[Mon Jul 27 09:35:23.708952 2026] [:error] [pid 21545:tid 140706886645504] [client 104.23.170.162:9446] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcKO5hXfYDIcpslIWOdQwAAAZE"]
[Mon Jul 27 09:35:23.823174 2026] [:error] [pid 12380:tid 140706928609024] [client 172.71.103.41:13784] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKO6aChfbWW0CZ_hrc-gAAAMw"]
[Mon Jul 27 09:35:23.824257 2026] [:error] [pid 12380:tid 140706928609024] [client 172.71.103.41:13784] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKO6aChfbWW0CZ_hrc-gAAAMw"]
[Mon Jul 27 09:35:23.824945 2026] [:error] [pid 12380:tid 140706928609024] [client 172.71.103.41:13784] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKO6aChfbWW0CZ_hrc-gAAAMw"]
[Mon Jul 27 09:35:23.825284 2026] [:error] [pid 12380:tid 140706928609024] [client 172.71.103.41:13784] [client 172.71.103.41] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKO6aChfbWW0CZ_hrc-gAAAMw"]
[Mon Jul 27 09:35:24.003269 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcKPJhXfYDIcpslIWOdRAAAAYA"]
[Mon Jul 27 09:35:24.003989 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcKPJhXfYDIcpslIWOdRAAAAYA"]
[Mon Jul 27 09:35:24.004429 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcKPJhXfYDIcpslIWOdRAAAAYA"]
[Mon Jul 27 09:35:24.004660 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcKPJhXfYDIcpslIWOdRAAAAYA"]
[Mon Jul 27 09:35:24.188708 2026] [:error] [pid 21545:tid 140707004143360] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcKPJhXfYDIcpslIWOdSAAAAYM"]
[Mon Jul 27 09:35:24.189799 2026] [:error] [pid 21545:tid 140707004143360] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcKPJhXfYDIcpslIWOdSAAAAYM"]
[Mon Jul 27 09:35:24.190407 2026] [:error] [pid 21545:tid 140707004143360] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcKPJhXfYDIcpslIWOdSAAAAYM"]
[Mon Jul 27 09:35:24.190748 2026] [:error] [pid 21545:tid 140707004143360] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcKPJhXfYDIcpslIWOdSAAAAYM"]
[Mon Jul 27 09:35:24.409380 2026] [:error] [pid 21545:tid 140706869860096] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amcKPJhXfYDIcpslIWOdSgAAAZM"]
[Mon Jul 27 09:35:24.410261 2026] [:error] [pid 21545:tid 140706869860096] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amcKPJhXfYDIcpslIWOdSgAAAZM"]
[Mon Jul 27 09:35:24.410789 2026] [:error] [pid 21545:tid 140706869860096] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amcKPJhXfYDIcpslIWOdSgAAAZM"]
[Mon Jul 27 09:35:24.411164 2026] [:error] [pid 21545:tid 140706869860096] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amcKPJhXfYDIcpslIWOdSgAAAZM"]
[Mon Jul 27 09:35:24.451655 2026] [:error] [pid 12276:tid 140706962179840] [client 162.159.119.40:10616] [client 162.159.119.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcKPOcsEMuHmMYmk66WIgAAAEg"]
[Mon Jul 27 09:35:24.452422 2026] [:error] [pid 12276:tid 140706962179840] [client 162.159.119.40:10616] [client 162.159.119.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcKPOcsEMuHmMYmk66WIgAAAEg"]
[Mon Jul 27 09:35:24.452875 2026] [:error] [pid 12276:tid 140706962179840] [client 162.159.119.40:10616] [client 162.159.119.40] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcKPOcsEMuHmMYmk66WIgAAAEg"]
[Mon Jul 27 09:35:24.452996 2026] [:error] [pid 12276:tid 140706962179840] [client 162.159.119.40:10616] [client 162.159.119.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcKPOcsEMuHmMYmk66WIgAAAEg"]
[Mon Jul 27 09:35:24.631010 2026] [:error] [pid 12276:tid 140706978965248] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amcKPOcsEMuHmMYmk66WIwAAAEY"]
[Mon Jul 27 09:35:24.631954 2026] [:error] [pid 12276:tid 140706978965248] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amcKPOcsEMuHmMYmk66WIwAAAEY"]
[Mon Jul 27 09:35:24.632449 2026] [:error] [pid 12276:tid 140706978965248] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amcKPOcsEMuHmMYmk66WIwAAAEY"]
[Mon Jul 27 09:35:24.632656 2026] [:error] [pid 12276:tid 140706978965248] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amcKPOcsEMuHmMYmk66WIwAAAEY"]
[Mon Jul 27 09:35:24.681879 2026] [:error] [pid 21545:tid 140706911823616] [client 141.101.76.32:13243] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcKPJhXfYDIcpslIWOdTAAAAY4"]
[Mon Jul 27 09:35:24.682680 2026] [:error] [pid 21545:tid 140706911823616] [client 141.101.76.32:13243] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcKPJhXfYDIcpslIWOdTAAAAY4"]
[Mon Jul 27 09:35:24.683070 2026] [:error] [pid 21545:tid 140706911823616] [client 141.101.76.32:13243] [client 141.101.76.32] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcKPJhXfYDIcpslIWOdTAAAAY4"]
[Mon Jul 27 09:35:24.683158 2026] [:error] [pid 21545:tid 140706911823616] [client 141.101.76.32:13243] [client 141.101.76.32] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcKPJhXfYDIcpslIWOdTAAAAY4"]
[Mon Jul 27 09:35:24.795889 2026] [:error] [pid 21545:tid 140706827896576] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amcKPJhXfYDIcpslIWOdTQAAAZg"]
[Mon Jul 27 09:35:24.796537 2026] [:error] [pid 21545:tid 140706827896576] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amcKPJhXfYDIcpslIWOdTQAAAZg"]
[Mon Jul 27 09:35:24.796970 2026] [:error] [pid 21545:tid 140706827896576] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amcKPJhXfYDIcpslIWOdTQAAAZg"]
[Mon Jul 27 09:35:24.797175 2026] [:error] [pid 21545:tid 140706827896576] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amcKPJhXfYDIcpslIWOdTQAAAZg"]
[Mon Jul 27 09:35:24.997676 2026] [:error] [pid 24106:tid 140706995750656] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcKPDs8oMu6f6EYbxSKPAAAAUQ"]
[Mon Jul 27 09:35:24.998540 2026] [:error] [pid 24106:tid 140706995750656] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcKPDs8oMu6f6EYbxSKPAAAAUQ"]
[Mon Jul 27 09:35:24.999058 2026] [:error] [pid 24106:tid 140706995750656] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcKPDs8oMu6f6EYbxSKPAAAAUQ"]
[Mon Jul 27 09:35:24.999379 2026] [:error] [pid 24106:tid 140706995750656] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcKPDs8oMu6f6EYbxSKPAAAAUQ"]
[Mon Jul 27 09:35:25.166501 2026] [:error] [pid 21545:tid 140706978965248] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amcKPZhXfYDIcpslIWOdUAAAAYY"]
[Mon Jul 27 09:35:25.167193 2026] [:error] [pid 21545:tid 140706978965248] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amcKPZhXfYDIcpslIWOdUAAAAYY"]
[Mon Jul 27 09:35:25.167630 2026] [:error] [pid 21545:tid 140706978965248] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amcKPZhXfYDIcpslIWOdUAAAAYY"]
[Mon Jul 27 09:35:25.167813 2026] [:error] [pid 21545:tid 140706978965248] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amcKPZhXfYDIcpslIWOdUAAAAYY"]
[Mon Jul 27 09:35:25.303333 2026] [:error] [pid 24106:tid 140707020928768] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcKPTs8oMu6f6EYbxSKPQAAAUE"]
[Mon Jul 27 09:35:25.304223 2026] [:error] [pid 24106:tid 140707020928768] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcKPTs8oMu6f6EYbxSKPQAAAUE"]
[Mon Jul 27 09:35:25.304728 2026] [:error] [pid 24106:tid 140707020928768] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcKPTs8oMu6f6EYbxSKPQAAAUE"]
[Mon Jul 27 09:35:25.304994 2026] [:error] [pid 24106:tid 140707020928768] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcKPTs8oMu6f6EYbxSKPQAAAUE"]
[Mon Jul 27 09:35:25.431674 2026] [:error] [pid 21545:tid 140706937001728] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcKPZhXfYDIcpslIWOdUgAAAYs"]
[Mon Jul 27 09:35:25.432383 2026] [:error] [pid 21545:tid 140706937001728] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcKPZhXfYDIcpslIWOdUgAAAYs"]
[Mon Jul 27 09:35:25.432953 2026] [:error] [pid 21545:tid 140706937001728] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcKPZhXfYDIcpslIWOdUgAAAYs"]
[Mon Jul 27 09:35:25.433217 2026] [:error] [pid 21545:tid 140706937001728] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcKPZhXfYDIcpslIWOdUgAAAYs"]
[Mon Jul 27 09:35:25.577191 2026] [:error] [pid 24106:tid 140706953787136] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcKPTs8oMu6f6EYbxSKQAAAAUk"]
[Mon Jul 27 09:35:25.578092 2026] [:error] [pid 24106:tid 140706953787136] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcKPTs8oMu6f6EYbxSKQAAAAUk"]
[Mon Jul 27 09:35:25.578582 2026] [:error] [pid 24106:tid 140706953787136] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcKPTs8oMu6f6EYbxSKQAAAAUk"]
[Mon Jul 27 09:35:25.578836 2026] [:error] [pid 24106:tid 140706953787136] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcKPTs8oMu6f6EYbxSKQAAAAUk"]
[Mon Jul 27 09:35:25.692486 2026] [:error] [pid 12276:tid 140707012536064] [client 104.23.168.4:12095] [client 104.23.168.4] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKPecsEMuHmMYmk66WJQAAAEI"]
[Mon Jul 27 09:35:25.693183 2026] [:error] [pid 12276:tid 140707012536064] [client 104.23.168.4:12095] [client 104.23.168.4] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "OPTIONS"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKPecsEMuHmMYmk66WJQAAAEI"]
[Mon Jul 27 09:35:25.693516 2026] [:error] [pid 12276:tid 140707012536064] [client 104.23.168.4:12095] [client 104.23.168.4] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKPecsEMuHmMYmk66WJQAAAEI"]
[Mon Jul 27 09:35:25.714659 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcKPZhXfYDIcpslIWOdUwAAAYE"]
[Mon Jul 27 09:35:25.715719 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcKPZhXfYDIcpslIWOdUwAAAYE"]
[Mon Jul 27 09:35:25.716256 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcKPZhXfYDIcpslIWOdUwAAAYE"]
[Mon Jul 27 09:35:25.716484 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcKPZhXfYDIcpslIWOdUwAAAYE"]
[Mon Jul 27 09:35:25.839902 2026] [:error] [pid 12275:tid 140706962179840] [client 104.23.187.75:10927] [client 104.23.187.75] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcKPXFwI8r7BFXGkAuE1wAAAAg"]
[Mon Jul 27 09:35:25.840649 2026] [:error] [pid 12275:tid 140706962179840] [client 104.23.187.75:10927] [client 104.23.187.75] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcKPXFwI8r7BFXGkAuE1wAAAAg"]
[Mon Jul 27 09:35:25.841087 2026] [:error] [pid 12275:tid 140706962179840] [client 104.23.187.75:10927] [client 104.23.187.75] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcKPXFwI8r7BFXGkAuE1wAAAAg"]
[Mon Jul 27 09:35:25.841211 2026] [:error] [pid 12275:tid 140706962179840] [client 104.23.187.75:10927] [client 104.23.187.75] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcKPXFwI8r7BFXGkAuE1wAAAAg"]
[Mon Jul 27 09:35:25.857542 2026] [:error] [pid 24106:tid 140706970572544] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amcKPTs8oMu6f6EYbxSKQgAAAUc"]
[Mon Jul 27 09:35:25.858430 2026] [:error] [pid 24106:tid 140706970572544] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amcKPTs8oMu6f6EYbxSKQgAAAUc"]
[Mon Jul 27 09:35:25.858903 2026] [:error] [pid 24106:tid 140706970572544] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amcKPTs8oMu6f6EYbxSKQgAAAUc"]
[Mon Jul 27 09:35:25.859156 2026] [:error] [pid 24106:tid 140706970572544] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.tmp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amcKPTs8oMu6f6EYbxSKQgAAAUc"]
[Mon Jul 27 09:35:25.985452 2026] [:error] [pid 21545:tid 140707103270656] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amcKPZhXfYDIcpslIWOdVQAAAYA"]
[Mon Jul 27 09:35:25.986079 2026] [:error] [pid 21545:tid 140707103270656] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amcKPZhXfYDIcpslIWOdVQAAAYA"]
[Mon Jul 27 09:35:25.986496 2026] [:error] [pid 21545:tid 140707103270656] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amcKPZhXfYDIcpslIWOdVQAAAYA"]
[Mon Jul 27 09:35:25.986717 2026] [:error] [pid 21545:tid 140707103270656] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amcKPZhXfYDIcpslIWOdVQAAAYA"]
[Mon Jul 27 09:35:26.113139 2026] [:error] [pid 24106:tid 140706937001728] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "amcKPjs8oMu6f6EYbxSKQwAAAUs"]
[Mon Jul 27 09:35:26.114055 2026] [:error] [pid 24106:tid 140706937001728] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "amcKPjs8oMu6f6EYbxSKQwAAAUs"]
[Mon Jul 27 09:35:26.114417 2026] [:error] [pid 24106:tid 140706937001728] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Pattern match "\\\\.[^.~]+~(?:/.*|)$" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1060"] [id "920500"] [msg "Attempt to access a backup or working file"] [data ".env~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "amcKPjs8oMu6f6EYbxSKQwAAAUs"]
[Mon Jul 27 09:35:26.114689 2026] [:error] [pid 24106:tid 140706937001728] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "amcKPjs8oMu6f6EYbxSKQwAAAUs"]
[Mon Jul 27 09:35:26.114914 2026] [:error] [pid 24106:tid 140706937001728] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "amcKPjs8oMu6f6EYbxSKQwAAAUs"]
[Mon Jul 27 09:35:26.230830 2026] [:error] [pid 12275:tid 140706861467392] [client 172.71.203.17:10766] [client 172.71.203.17] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcKPnFwI8r7BFXGkAuE2QAAABQ"]
[Mon Jul 27 09:35:26.231644 2026] [:error] [pid 12275:tid 140706861467392] [client 172.71.203.17:10766] [client 172.71.203.17] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcKPnFwI8r7BFXGkAuE2QAAABQ"]
[Mon Jul 27 09:35:26.232061 2026] [:error] [pid 12275:tid 140706861467392] [client 172.71.203.17:10766] [client 172.71.203.17] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcKPnFwI8r7BFXGkAuE2QAAABQ"]
[Mon Jul 27 09:35:26.232174 2026] [:error] [pid 12275:tid 140706861467392] [client 172.71.203.17:10766] [client 172.71.203.17] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcKPnFwI8r7BFXGkAuE2QAAABQ"]
[Mon Jul 27 09:35:26.243310 2026] [:error] [pid 21545:tid 140706903430912] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amcKPphXfYDIcpslIWOdVwAAAY8"]
[Mon Jul 27 09:35:26.244401 2026] [:error] [pid 21545:tid 140706903430912] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amcKPphXfYDIcpslIWOdVwAAAY8"]
[Mon Jul 27 09:35:26.244980 2026] [:error] [pid 21545:tid 140706903430912] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amcKPphXfYDIcpslIWOdVwAAAY8"]
[Mon Jul 27 09:35:26.245295 2026] [:error] [pid 21545:tid 140706903430912] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amcKPphXfYDIcpslIWOdVwAAAY8"]
[Mon Jul 27 09:35:26.371913 2026] [:error] [pid 24106:tid 140707004143360] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcKPjs8oMu6f6EYbxSKRQAAAUM"]
[Mon Jul 27 09:35:26.372722 2026] [:error] [pid 24106:tid 140707004143360] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcKPjs8oMu6f6EYbxSKRQAAAUM"]
[Mon Jul 27 09:35:26.373104 2026] [:error] [pid 24106:tid 140707004143360] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcKPjs8oMu6f6EYbxSKRQAAAUM"]
[Mon Jul 27 09:35:26.373300 2026] [:error] [pid 24106:tid 140707004143360] [client 172.71.95.22:13429] [client 172.71.95.22] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcKPjs8oMu6f6EYbxSKRQAAAUM"]
[Mon Jul 27 09:35:26.506929 2026] [:error] [pid 21545:tid 140706869860096] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcKPphXfYDIcpslIWOdWQAAAZM"]
[Mon Jul 27 09:35:26.507920 2026] [:error] [pid 21545:tid 140706869860096] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcKPphXfYDIcpslIWOdWQAAAZM"]
[Mon Jul 27 09:35:26.508422 2026] [:error] [pid 21545:tid 140706869860096] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcKPphXfYDIcpslIWOdWQAAAZM"]
[Mon Jul 27 09:35:26.508749 2026] [:error] [pid 21545:tid 140706869860096] [client 104.23.170.163:11377] [client 104.23.170.163] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcKPphXfYDIcpslIWOdWQAAAZM"]
[Mon Jul 27 09:35:26.644638 2026] [:error] [pid 21545:tid 140706970572544] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.template"] [unique_id "amcKPphXfYDIcpslIWOdWgAAAYc"]
[Mon Jul 27 09:35:26.645363 2026] [:error] [pid 21545:tid 140706970572544] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.template"] [unique_id "amcKPphXfYDIcpslIWOdWgAAAYc"]
[Mon Jul 27 09:35:26.645748 2026] [:error] [pid 21545:tid 140706970572544] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.template"] [unique_id "amcKPphXfYDIcpslIWOdWgAAAYc"]
[Mon Jul 27 09:35:26.645978 2026] [:error] [pid 21545:tid 140706970572544] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.template"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.template"] [unique_id "amcKPphXfYDIcpslIWOdWgAAAYc"]
[Mon Jul 27 09:35:26.804698 2026] [:error] [pid 12276:tid 140706987357952] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcKPucsEMuHmMYmk66WJwAAAEU"]
[Mon Jul 27 09:35:26.805490 2026] [:error] [pid 12276:tid 140706987357952] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcKPucsEMuHmMYmk66WJwAAAEU"]
[Mon Jul 27 09:35:26.805957 2026] [:error] [pid 12276:tid 140706987357952] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcKPucsEMuHmMYmk66WJwAAAEU"]
[Mon Jul 27 09:35:26.806252 2026] [:error] [pid 12276:tid 140706987357952] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcKPucsEMuHmMYmk66WJwAAAEU"]
[Mon Jul 27 09:35:26.963195 2026] [:error] [pid 21545:tid 140706861467392] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcKPphXfYDIcpslIWOdWwAAAZQ"]
[Mon Jul 27 09:35:26.963864 2026] [:error] [pid 21545:tid 140706861467392] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcKPphXfYDIcpslIWOdWwAAAZQ"]
[Mon Jul 27 09:35:26.964272 2026] [:error] [pid 21545:tid 140706861467392] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcKPphXfYDIcpslIWOdWwAAAZQ"]
[Mon Jul 27 09:35:26.964488 2026] [:error] [pid 21545:tid 140706861467392] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcKPphXfYDIcpslIWOdWwAAAZQ"]
[Mon Jul 27 09:35:27.111366 2026] [:error] [pid 12276:tid 140707103270656] [client 104.23.168.4:12095] [client 104.23.168.4] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKP-csEMuHmMYmk66WKQAAAEA"]
[Mon Jul 27 09:35:27.112357 2026] [:error] [pid 12276:tid 140707103270656] [client 104.23.168.4:12095] [client 104.23.168.4] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKP-csEMuHmMYmk66WKQAAAEA"]
[Mon Jul 27 09:35:27.112972 2026] [:error] [pid 12276:tid 140707103270656] [client 104.23.168.4:12095] [client 104.23.168.4] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKP-csEMuHmMYmk66WKQAAAEA"]
[Mon Jul 27 09:35:27.113089 2026] [:error] [pid 12276:tid 140707103270656] [client 104.23.168.4:12095] [client 104.23.168.4] ModSecurity: Warning. Found 4 byte(s) in ARGS:rest_route outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:rest_route=/wp/v2/users/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKP-csEMuHmMYmk66WKQAAAEA"]
[Mon Jul 27 09:35:27.113205 2026] [:error] [pid 12276:tid 140707103270656] [client 104.23.168.4:12095] [client 104.23.168.4] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKP-csEMuHmMYmk66WKQAAAEA"]
[Mon Jul 27 09:35:27.121674 2026] [:error] [pid 12276:tid 140706836289280] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.test.local"] [unique_id "amcKP-csEMuHmMYmk66WKgAAAFc"]
[Mon Jul 27 09:35:27.122430 2026] [:error] [pid 12276:tid 140706836289280] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.test.local"] [unique_id "amcKP-csEMuHmMYmk66WKgAAAFc"]
[Mon Jul 27 09:35:27.122861 2026] [:error] [pid 12276:tid 140706836289280] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.test.local"] [unique_id "amcKP-csEMuHmMYmk66WKgAAAFc"]
[Mon Jul 27 09:35:27.123098 2026] [:error] [pid 12276:tid 140706836289280] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.test.local"] [unique_id "amcKP-csEMuHmMYmk66WKgAAAFc"]
[Mon Jul 27 09:35:27.279062 2026] [:error] [pid 21545:tid 140706911823616] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amcKP5hXfYDIcpslIWOdXgAAAY4"]
[Mon Jul 27 09:35:27.280035 2026] [:error] [pid 21545:tid 140706911823616] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amcKP5hXfYDIcpslIWOdXgAAAY4"]
[Mon Jul 27 09:35:27.280628 2026] [:error] [pid 21545:tid 140706911823616] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amcKP5hXfYDIcpslIWOdXgAAAY4"]
[Mon Jul 27 09:35:27.280909 2026] [:error] [pid 21545:tid 140706911823616] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envrc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amcKP5hXfYDIcpslIWOdXgAAAY4"]
[Mon Jul 27 09:35:27.440007 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.flaskenv"] [unique_id "amcKP-csEMuHmMYmk66WLQAAAFM"]
[Mon Jul 27 09:35:27.440684 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.flaskenv"] [unique_id "amcKP-csEMuHmMYmk66WLQAAAFM"]
[Mon Jul 27 09:35:27.441109 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.flaskenv"] [unique_id "amcKP-csEMuHmMYmk66WLQAAAFM"]
[Mon Jul 27 09:35:27.555230 2026] [:error] [pid 12276:tid 140706827896576] [client 172.70.231.64:10229] [client 172.70.231.64] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKP-csEMuHmMYmk66WLgAAAFg"]
[Mon Jul 27 09:35:27.556206 2026] [:error] [pid 12276:tid 140706827896576] [client 172.70.231.64:10229] [client 172.70.231.64] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "OPTIONS"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKP-csEMuHmMYmk66WLgAAAFg"]
[Mon Jul 27 09:35:27.556690 2026] [:error] [pid 12276:tid 140706827896576] [client 172.70.231.64:10229] [client 172.70.231.64] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKP-csEMuHmMYmk66WLgAAAFg"]
[Mon Jul 27 09:35:27.597056 2026] [:error] [pid 21545:tid 140706895038208] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env"] [unique_id "amcKP5hXfYDIcpslIWOdYAAAAZA"]
[Mon Jul 27 09:35:27.597769 2026] [:error] [pid 21545:tid 140706895038208] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env"] [unique_id "amcKP5hXfYDIcpslIWOdYAAAAZA"]
[Mon Jul 27 09:35:27.598234 2026] [:error] [pid 21545:tid 140706895038208] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/env"] [unique_id "amcKP5hXfYDIcpslIWOdYAAAAZA"]
[Mon Jul 27 09:35:27.791002 2026] [:error] [pid 12276:tid 140706962179840] [client 162.159.113.160:11773] [client 162.159.113.160] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env.js"] [unique_id "amcKP-csEMuHmMYmk66WMAAAAEg"]
[Mon Jul 27 09:35:27.791838 2026] [:error] [pid 12276:tid 140706962179840] [client 162.159.113.160:11773] [client 162.159.113.160] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env.js"] [unique_id "amcKP-csEMuHmMYmk66WMAAAAEg"]
[Mon Jul 27 09:35:27.792361 2026] [:error] [pid 12276:tid 140706962179840] [client 162.159.113.160:11773] [client 162.159.113.160] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/env.js"] [unique_id "amcKP-csEMuHmMYmk66WMAAAAEg"]
[Mon Jul 27 09:35:27.850682 2026] [:error] [pid 12276:tid 140706978965248] [client 172.70.46.165:11941] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcKP-csEMuHmMYmk66WMQAAAEY"]
[Mon Jul 27 09:35:27.851346 2026] [:error] [pid 12276:tid 140706978965248] [client 172.70.46.165:11941] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcKP-csEMuHmMYmk66WMQAAAEY"]
[Mon Jul 27 09:35:27.851752 2026] [:error] [pid 12276:tid 140706978965248] [client 172.70.46.165:11941] [client 172.70.46.165] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcKP-csEMuHmMYmk66WMQAAAEY"]
[Mon Jul 27 09:35:27.851872 2026] [:error] [pid 12276:tid 140706978965248] [client 172.70.46.165:11941] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcKP-csEMuHmMYmk66WMQAAAEY"]
[Mon Jul 27 09:35:27.956067 2026] [:error] [pid 21545:tid 140706945394432] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env.json"] [unique_id "amcKP5hXfYDIcpslIWOdYwAAAYo"]
[Mon Jul 27 09:35:27.956924 2026] [:error] [pid 21545:tid 140706945394432] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env.json"] [unique_id "amcKP5hXfYDIcpslIWOdYwAAAYo"]
[Mon Jul 27 09:35:27.957445 2026] [:error] [pid 21545:tid 140706945394432] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/env.json"] [unique_id "amcKP5hXfYDIcpslIWOdYwAAAYo"]
[Mon Jul 27 09:35:28.124260 2026] [:error] [pid 12276:tid 140706844681984] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amcKQOcsEMuHmMYmk66WMwAAAFY"]
[Mon Jul 27 09:35:28.125157 2026] [:error] [pid 12276:tid 140706844681984] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amcKQOcsEMuHmMYmk66WMwAAAFY"]
[Mon Jul 27 09:35:28.125656 2026] [:error] [pid 12276:tid 140706844681984] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amcKQOcsEMuHmMYmk66WMwAAAFY"]
[Mon Jul 27 09:35:28.125926 2026] [:error] [pid 12276:tid 140706844681984] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amcKQOcsEMuHmMYmk66WMwAAAFY"]
[Mon Jul 27 09:35:28.290969 2026] [:error] [pid 21545:tid 140706844681984] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amcKQJhXfYDIcpslIWOdZAAAAZY"]
[Mon Jul 27 09:35:28.291736 2026] [:error] [pid 21545:tid 140706844681984] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amcKQJhXfYDIcpslIWOdZAAAAZY"]
[Mon Jul 27 09:35:28.292093 2026] [:error] [pid 21545:tid 140706844681984] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amcKQJhXfYDIcpslIWOdZAAAAZY"]
[Mon Jul 27 09:35:28.292298 2026] [:error] [pid 21545:tid 140706844681984] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amcKQJhXfYDIcpslIWOdZAAAAZY"]
[Mon Jul 27 09:35:28.449260 2026] [:error] [pid 24106:tid 140706945394432] [client 162.158.155.59:13581] [client 162.158.155.59] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKQDs8oMu6f6EYbxSKSAAAAUo"]
[Mon Jul 27 09:35:28.450203 2026] [:error] [pid 24106:tid 140706945394432] [client 162.158.155.59:13581] [client 162.158.155.59] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKQDs8oMu6f6EYbxSKSAAAAUo"]
[Mon Jul 27 09:35:28.450664 2026] [:error] [pid 24106:tid 140706945394432] [client 162.158.155.59:13581] [client 162.158.155.59] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKQDs8oMu6f6EYbxSKSAAAAUo"]
[Mon Jul 27 09:35:28.450754 2026] [:error] [pid 24106:tid 140706945394432] [client 162.158.155.59:13581] [client 162.158.155.59] ModSecurity: Warning. Found 4 byte(s) in ARGS:rest_route outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:rest_route=/wp/v2/users/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKQDs8oMu6f6EYbxSKSAAAAUo"]
[Mon Jul 27 09:35:28.450850 2026] [:error] [pid 24106:tid 140706945394432] [client 162.158.155.59:13581] [client 162.158.155.59] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKQDs8oMu6f6EYbxSKSAAAAUo"]
[Mon Jul 27 09:35:28.452898 2026] [:error] [pid 12276:tid 140707012536064] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amcKQOcsEMuHmMYmk66WNAAAAEI"]
[Mon Jul 27 09:35:28.453597 2026] [:error] [pid 12276:tid 140707012536064] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amcKQOcsEMuHmMYmk66WNAAAAEI"]
[Mon Jul 27 09:35:28.454099 2026] [:error] [pid 12276:tid 140707012536064] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amcKQOcsEMuHmMYmk66WNAAAAEI"]
[Mon Jul 27 09:35:28.454357 2026] [:error] [pid 12276:tid 140707012536064] [client 172.71.98.106:10994] [client 172.71.98.106] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amcKQOcsEMuHmMYmk66WNAAAAEI"]
[Mon Jul 27 09:35:28.609657 2026] [:error] [pid 21545:tid 140706995750656] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amcKQJhXfYDIcpslIWOdZgAAAYQ"]
[Mon Jul 27 09:35:28.610711 2026] [:error] [pid 21545:tid 140706995750656] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amcKQJhXfYDIcpslIWOdZgAAAYQ"]
[Mon Jul 27 09:35:28.611297 2026] [:error] [pid 21545:tid 140706995750656] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amcKQJhXfYDIcpslIWOdZgAAAYQ"]
[Mon Jul 27 09:35:28.611612 2026] [:error] [pid 21545:tid 140706995750656] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amcKQJhXfYDIcpslIWOdZgAAAYQ"]
[Mon Jul 27 09:35:28.772096 2026] [:error] [pid 21545:tid 140706903430912] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amcKQJhXfYDIcpslIWOdZwAAAY8"]
[Mon Jul 27 09:35:28.772996 2026] [:error] [pid 21545:tid 140706903430912] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amcKQJhXfYDIcpslIWOdZwAAAY8"]
[Mon Jul 27 09:35:28.773474 2026] [:error] [pid 21545:tid 140706903430912] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amcKQJhXfYDIcpslIWOdZwAAAY8"]
[Mon Jul 27 09:35:28.773731 2026] [:error] [pid 21545:tid 140706903430912] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /frontend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amcKQJhXfYDIcpslIWOdZwAAAY8"]
[Mon Jul 27 09:35:28.955916 2026] [:error] [pid 21545:tid 140706953787136] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amcKQJhXfYDIcpslIWOdaAAAAYk"]
[Mon Jul 27 09:35:28.956851 2026] [:error] [pid 21545:tid 140706953787136] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amcKQJhXfYDIcpslIWOdaAAAAYk"]
[Mon Jul 27 09:35:28.957402 2026] [:error] [pid 21545:tid 140706953787136] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amcKQJhXfYDIcpslIWOdaAAAAYk"]
[Mon Jul 27 09:35:28.957724 2026] [:error] [pid 21545:tid 140706953787136] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amcKQJhXfYDIcpslIWOdaAAAAYk"]
[Mon Jul 27 09:35:29.231723 2026] [:error] [pid 12275:tid 140706920216320] [client 104.23.187.75:10927] [client 104.23.187.75] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcKQXFwI8r7BFXGkAuE3wAAAA0"]
[Mon Jul 27 09:35:29.232935 2026] [:error] [pid 12275:tid 140706920216320] [client 104.23.187.75:10927] [client 104.23.187.75] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcKQXFwI8r7BFXGkAuE3wAAAA0"]
[Mon Jul 27 09:35:29.233643 2026] [:error] [pid 12275:tid 140706920216320] [client 104.23.187.75:10927] [client 104.23.187.75] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcKQXFwI8r7BFXGkAuE3wAAAA0"]
[Mon Jul 27 09:35:29.233833 2026] [:error] [pid 12275:tid 140706920216320] [client 104.23.187.75:10927] [client 104.23.187.75] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcKQXFwI8r7BFXGkAuE3wAAAA0"]
[Mon Jul 27 09:35:29.495954 2026] [:error] [pid 21545:tid 140706970572544] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amcKQZhXfYDIcpslIWOdaQAAAYc"]
[Mon Jul 27 09:35:29.497002 2026] [:error] [pid 21545:tid 140706970572544] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amcKQZhXfYDIcpslIWOdaQAAAYc"]
[Mon Jul 27 09:35:29.497634 2026] [:error] [pid 21545:tid 140706970572544] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amcKQZhXfYDIcpslIWOdaQAAAYc"]
[Mon Jul 27 09:35:29.497924 2026] [:error] [pid 21545:tid 140706970572544] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amcKQZhXfYDIcpslIWOdaQAAAYc"]
[Mon Jul 27 09:35:29.670909 2026] [:error] [pid 21545:tid 140706886645504] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amcKQZhXfYDIcpslIWOdagAAAZE"]
[Mon Jul 27 09:35:29.672018 2026] [:error] [pid 21545:tid 140706886645504] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amcKQZhXfYDIcpslIWOdagAAAZE"]
[Mon Jul 27 09:35:29.672941 2026] [:error] [pid 21545:tid 140706886645504] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amcKQZhXfYDIcpslIWOdagAAAZE"]
[Mon Jul 27 09:35:29.673123 2026] [:error] [pid 21545:tid 140706886645504] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /client/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amcKQZhXfYDIcpslIWOdagAAAZE"]
[Mon Jul 27 09:35:29.829905 2026] [:error] [pid 21545:tid 140707012536064] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amcKQZhXfYDIcpslIWOdawAAAYI"]
[Mon Jul 27 09:35:29.830790 2026] [:error] [pid 21545:tid 140707012536064] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amcKQZhXfYDIcpslIWOdawAAAYI"]
[Mon Jul 27 09:35:29.831274 2026] [:error] [pid 21545:tid 140707012536064] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amcKQZhXfYDIcpslIWOdawAAAYI"]
[Mon Jul 27 09:35:29.831535 2026] [:error] [pid 21545:tid 140707012536064] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amcKQZhXfYDIcpslIWOdawAAAYI"]
[Mon Jul 27 09:35:30.004357 2026] [:error] [pid 21545:tid 140706978965248] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amcKQphXfYDIcpslIWOdbgAAAYY"]
[Mon Jul 27 09:35:30.005246 2026] [:error] [pid 21545:tid 140706978965248] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amcKQphXfYDIcpslIWOdbgAAAYY"]
[Mon Jul 27 09:35:30.005686 2026] [:error] [pid 21545:tid 140706978965248] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amcKQphXfYDIcpslIWOdbgAAAYY"]
[Mon Jul 27 09:35:30.005908 2026] [:error] [pid 21545:tid 140706978965248] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amcKQphXfYDIcpslIWOdbgAAAYY"]
[Mon Jul 27 09:35:30.159191 2026] [:error] [pid 21545:tid 140706895038208] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amcKQphXfYDIcpslIWOdbwAAAZA"]
[Mon Jul 27 09:35:30.160118 2026] [:error] [pid 21545:tid 140706895038208] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amcKQphXfYDIcpslIWOdbwAAAZA"]
[Mon Jul 27 09:35:30.160676 2026] [:error] [pid 21545:tid 140706895038208] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amcKQphXfYDIcpslIWOdbwAAAZA"]
[Mon Jul 27 09:35:30.160948 2026] [:error] [pid 21545:tid 140706895038208] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /private/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amcKQphXfYDIcpslIWOdbwAAAZA"]
[Mon Jul 27 09:35:30.329251 2026] [:error] [pid 21545:tid 140706844681984] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/var/.env"] [unique_id "amcKQphXfYDIcpslIWOdcAAAAZY"]
[Mon Jul 27 09:35:30.329971 2026] [:error] [pid 21545:tid 140706844681984] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/var/.env"] [unique_id "amcKQphXfYDIcpslIWOdcAAAAZY"]
[Mon Jul 27 09:35:30.330385 2026] [:error] [pid 21545:tid 140706844681984] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/var/.env"] [unique_id "amcKQphXfYDIcpslIWOdcAAAAZY"]
[Mon Jul 27 09:35:30.330581 2026] [:error] [pid 21545:tid 140706844681984] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /var/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/var/.env"] [unique_id "amcKQphXfYDIcpslIWOdcAAAAZY"]
[Mon Jul 27 09:35:30.482136 2026] [:error] [pid 21545:tid 140706878252800] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.yml"] [unique_id "amcKQphXfYDIcpslIWOdcQAAAZI"]
[Mon Jul 27 09:35:30.483011 2026] [:error] [pid 21545:tid 140706878252800] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.yml"] [unique_id "amcKQphXfYDIcpslIWOdcQAAAZI"]
[Mon Jul 27 09:35:30.483535 2026] [:error] [pid 21545:tid 140706878252800] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.yml"] [unique_id "amcKQphXfYDIcpslIWOdcQAAAZI"]
[Mon Jul 27 09:35:30.656962 2026] [:error] [pid 21545:tid 140706962179840] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.yaml"] [unique_id "amcKQphXfYDIcpslIWOdcwAAAYg"]
[Mon Jul 27 09:35:30.657739 2026] [:error] [pid 21545:tid 140706962179840] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.yaml"] [unique_id "amcKQphXfYDIcpslIWOdcwAAAYg"]
[Mon Jul 27 09:35:30.658261 2026] [:error] [pid 21545:tid 140706962179840] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.yaml"] [unique_id "amcKQphXfYDIcpslIWOdcwAAAYg"]
[Mon Jul 27 09:35:30.813990 2026] [:error] [pid 21545:tid 140706987357952] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.override.yml"] [unique_id "amcKQphXfYDIcpslIWOddQAAAYU"]
[Mon Jul 27 09:35:30.814908 2026] [:error] [pid 21545:tid 140706987357952] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.override.yml"] [unique_id "amcKQphXfYDIcpslIWOddQAAAYU"]
[Mon Jul 27 09:35:30.815506 2026] [:error] [pid 21545:tid 140706987357952] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.override.yml"] [unique_id "amcKQphXfYDIcpslIWOddQAAAYU"]
[Mon Jul 27 09:35:30.989506 2026] [:error] [pid 21545:tid 140706903430912] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.dev.yml"] [unique_id "amcKQphXfYDIcpslIWOddgAAAY8"]
[Mon Jul 27 09:35:30.990425 2026] [:error] [pid 21545:tid 140706903430912] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.dev.yml"] [unique_id "amcKQphXfYDIcpslIWOddgAAAY8"]
[Mon Jul 27 09:35:30.990996 2026] [:error] [pid 21545:tid 140706903430912] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.dev.yml"] [unique_id "amcKQphXfYDIcpslIWOddgAAAY8"]
[Mon Jul 27 09:35:31.158253 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.prod.yml"] [unique_id "amcKQ5hXfYDIcpslIWOddwAAAYs"]
[Mon Jul 27 09:35:31.159340 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.prod.yml"] [unique_id "amcKQ5hXfYDIcpslIWOddwAAAYs"]
[Mon Jul 27 09:35:31.159935 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.prod.yml"] [unique_id "amcKQ5hXfYDIcpslIWOddwAAAYs"]
[Mon Jul 27 09:35:31.392757 2026] [:error] [pid 21545:tid 140707004143360] [client 172.71.99.40:12737] [client 172.71.99.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amcKQ5hXfYDIcpslIWOdegAAAYM"]
[Mon Jul 27 09:35:31.393977 2026] [:error] [pid 21545:tid 140707004143360] [client 172.71.99.40:12737] [client 172.71.99.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amcKQ5hXfYDIcpslIWOdegAAAYM"]
[Mon Jul 27 09:35:31.394658 2026] [:error] [pid 21545:tid 140707004143360] [client 172.71.99.40:12737] [client 172.71.99.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amcKQ5hXfYDIcpslIWOdegAAAYM"]
[Mon Jul 27 09:35:31.560544 2026] [:error] [pid 21545:tid 140706861467392] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcKQ5hXfYDIcpslIWOdewAAAZQ"]
[Mon Jul 27 09:35:31.561587 2026] [:error] [pid 21545:tid 140706861467392] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcKQ5hXfYDIcpslIWOdewAAAZQ"]
[Mon Jul 27 09:35:31.562126 2026] [:error] [pid 21545:tid 140706861467392] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcKQ5hXfYDIcpslIWOdewAAAZQ"]
[Mon Jul 27 09:35:31.782724 2026] [:error] [pid 21545:tid 140706911823616] [client 104.23.170.61:14315] [client 104.23.170.61] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/settings.js"] [unique_id "amcKQ5hXfYDIcpslIWOdfAAAAY4"]
[Mon Jul 27 09:35:31.783377 2026] [:error] [pid 21545:tid 140706911823616] [client 104.23.170.61:14315] [client 104.23.170.61] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/settings.js"] [unique_id "amcKQ5hXfYDIcpslIWOdfAAAAY4"]
[Mon Jul 27 09:35:31.783906 2026] [:error] [pid 21545:tid 140706911823616] [client 104.23.170.61:14315] [client 104.23.170.61] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/settings.js"] [unique_id "amcKQ5hXfYDIcpslIWOdfAAAAY4"]
[Mon Jul 27 09:35:31.948323 2026] [:error] [pid 21545:tid 140706836289280] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "amcKQ5hXfYDIcpslIWOdfQAAAZc"]
[Mon Jul 27 09:35:31.949275 2026] [:error] [pid 21545:tid 140706836289280] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "amcKQ5hXfYDIcpslIWOdfQAAAZc"]
[Mon Jul 27 09:35:31.949825 2026] [:error] [pid 21545:tid 140706836289280] [client 172.71.102.114:11751] [client 172.71.102.114] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "amcKQ5hXfYDIcpslIWOdfQAAAZc"]
[Mon Jul 27 09:35:32.127134 2026] [:error] [pid 21545:tid 140706920216320] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcKRJhXfYDIcpslIWOdfgAAAY0"]
[Mon Jul 27 09:35:32.127884 2026] [:error] [pid 21545:tid 140706920216320] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcKRJhXfYDIcpslIWOdfgAAAY0"]
[Mon Jul 27 09:35:32.128373 2026] [:error] [pid 21545:tid 140706920216320] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcKRJhXfYDIcpslIWOdfgAAAY0"]
[Mon Jul 27 09:35:32.292133 2026] [:error] [pid 21545:tid 140706844681984] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/credentials.json"] [unique_id "amcKRJhXfYDIcpslIWOdfwAAAZY"]
[Mon Jul 27 09:35:32.293098 2026] [:error] [pid 21545:tid 140706844681984] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/credentials.json"] [unique_id "amcKRJhXfYDIcpslIWOdfwAAAZY"]
[Mon Jul 27 09:35:32.293775 2026] [:error] [pid 21545:tid 140706844681984] [client 172.71.103.42:10103] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/credentials.json"] [unique_id "amcKRJhXfYDIcpslIWOdfwAAAZY"]
[Mon Jul 27 09:35:32.476577 2026] [:error] [pid 21545:tid 140706878252800] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cdp_api_key.json"] [unique_id "amcKRJhXfYDIcpslIWOdgQAAAZI"]
[Mon Jul 27 09:35:32.477478 2026] [:error] [pid 21545:tid 140706878252800] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cdp_api_key.json"] [unique_id "amcKRJhXfYDIcpslIWOdgQAAAZI"]
[Mon Jul 27 09:35:32.477925 2026] [:error] [pid 21545:tid 140706878252800] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cdp_api_key.json"] [unique_id "amcKRJhXfYDIcpslIWOdgQAAAZI"]
[Mon Jul 27 09:35:32.681171 2026] [:error] [pid 12276:tid 140706861467392] [client 172.71.183.224:11008] [client 172.71.183.224] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/app.js"] [unique_id "amcKROcsEMuHmMYmk66WNwAAAFQ"]
[Mon Jul 27 09:35:32.682007 2026] [:error] [pid 12276:tid 140706861467392] [client 172.71.183.224:11008] [client 172.71.183.224] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/app.js"] [unique_id "amcKROcsEMuHmMYmk66WNwAAAFQ"]
[Mon Jul 27 09:35:32.682488 2026] [:error] [pid 12276:tid 140706861467392] [client 172.71.183.224:11008] [client 172.71.183.224] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app.js"] [unique_id "amcKROcsEMuHmMYmk66WNwAAAFQ"]
[Mon Jul 27 09:35:32.905117 2026] [:error] [pid 12276:tid 140706853074688] [client 172.71.182.178:12368] [client 172.71.182.178] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/main.js"] [unique_id "amcKROcsEMuHmMYmk66WOAAAAFU"]
[Mon Jul 27 09:35:32.905917 2026] [:error] [pid 12276:tid 140706853074688] [client 172.71.182.178:12368] [client 172.71.182.178] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/main.js"] [unique_id "amcKROcsEMuHmMYmk66WOAAAAFU"]
[Mon Jul 27 09:35:32.906414 2026] [:error] [pid 12276:tid 140706853074688] [client 172.71.182.178:12368] [client 172.71.182.178] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/main.js"] [unique_id "amcKROcsEMuHmMYmk66WOAAAAFU"]
[Mon Jul 27 09:35:33.103440 2026] [:error] [pid 12276:tid 140706978965248] [client 172.70.46.152:12557] [client 172.70.46.152] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.js"] [unique_id "amcKRecsEMuHmMYmk66WOQAAAEY"]
[Mon Jul 27 09:35:33.104372 2026] [:error] [pid 12276:tid 140706978965248] [client 172.70.46.152:12557] [client 172.70.46.152] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.js"] [unique_id "amcKRecsEMuHmMYmk66WOQAAAEY"]
[Mon Jul 27 09:35:33.105031 2026] [:error] [pid 12276:tid 140706978965248] [client 172.70.46.152:12557] [client 172.70.46.152] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.js"] [unique_id "amcKRecsEMuHmMYmk66WOQAAAEY"]
[Mon Jul 27 09:35:33.336269 2026] [:error] [pid 21545:tid 140706903430912] [client 172.71.103.46:10261] [client 172.71.103.46] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server.js"] [unique_id "amcKRZhXfYDIcpslIWOdhAAAAY8"]
[Mon Jul 27 09:35:33.336950 2026] [:error] [pid 21545:tid 140706903430912] [client 172.71.103.46:10261] [client 172.71.103.46] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/server.js"] [unique_id "amcKRZhXfYDIcpslIWOdhAAAAY8"]
[Mon Jul 27 09:35:33.337347 2026] [:error] [pid 21545:tid 140706903430912] [client 172.71.103.46:10261] [client 172.71.103.46] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/server.js"] [unique_id "amcKRZhXfYDIcpslIWOdhAAAAY8"]
[Mon Jul 27 09:35:33.944609 2026] [:error] [pid 24106:tid 140706836289280] [client 104.23.168.2:9386] [client 104.23.168.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bundle.js"] [unique_id "amcKRTs8oMu6f6EYbxSKTgAAAVc"]
[Mon Jul 27 09:35:33.945453 2026] [:error] [pid 24106:tid 140706836289280] [client 104.23.168.2:9386] [client 104.23.168.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bundle.js"] [unique_id "amcKRTs8oMu6f6EYbxSKTgAAAVc"]
[Mon Jul 27 09:35:33.945918 2026] [:error] [pid 24106:tid 140706836289280] [client 104.23.168.2:9386] [client 104.23.168.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bundle.js"] [unique_id "amcKRTs8oMu6f6EYbxSKTgAAAVc"]
[Mon Jul 27 09:35:34.139397 2026] [:error] [pid 12276:tid 140706878252800] [client 172.71.99.136:9603] [client 172.71.99.136] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/app.bundle.js"] [unique_id "amcKRucsEMuHmMYmk66WOwAAAFI"]
[Mon Jul 27 09:35:34.140409 2026] [:error] [pid 12276:tid 140706878252800] [client 172.71.99.136:9603] [client 172.71.99.136] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/app.bundle.js"] [unique_id "amcKRucsEMuHmMYmk66WOwAAAFI"]
[Mon Jul 27 09:35:34.140963 2026] [:error] [pid 12276:tid 140706878252800] [client 172.71.99.136:9603] [client 172.71.99.136] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app.bundle.js"] [unique_id "amcKRucsEMuHmMYmk66WOwAAAFI"]
[Mon Jul 27 09:35:34.350844 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.182.130:12542] [client 172.71.182.130] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/main.bundle.js"] [unique_id "amcKRphXfYDIcpslIWOdhgAAAYs"]
[Mon Jul 27 09:35:34.351514 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.182.130:12542] [client 172.71.182.130] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/main.bundle.js"] [unique_id "amcKRphXfYDIcpslIWOdhgAAAYs"]
[Mon Jul 27 09:35:34.351970 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.182.130:12542] [client 172.71.182.130] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/main.bundle.js"] [unique_id "amcKRphXfYDIcpslIWOdhgAAAYs"]
[Mon Jul 27 09:35:34.561062 2026] [:error] [pid 21545:tid 140706970572544] [client 162.159.113.95:13465] [client 162.159.113.95] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/vendor.js"] [unique_id "amcKRphXfYDIcpslIWOdhwAAAYc"]
[Mon Jul 27 09:35:34.562233 2026] [:error] [pid 21545:tid 140706970572544] [client 162.159.113.95:13465] [client 162.159.113.95] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/vendor.js"] [unique_id "amcKRphXfYDIcpslIWOdhwAAAYc"]
[Mon Jul 27 09:35:34.562812 2026] [:error] [pid 21545:tid 140706970572544] [client 162.159.113.95:13465] [client 162.159.113.95] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/vendor.js"] [unique_id "amcKRphXfYDIcpslIWOdhwAAAYc"]
[Mon Jul 27 09:35:34.779715 2026] [:error] [pid 12276:tid 140707012536064] [client 104.23.168.71:10955] [client 104.23.168.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/chunk.js"] [unique_id "amcKRucsEMuHmMYmk66WPQAAAEI"]
[Mon Jul 27 09:35:34.780609 2026] [:error] [pid 12276:tid 140707012536064] [client 104.23.168.71:10955] [client 104.23.168.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/chunk.js"] [unique_id "amcKRucsEMuHmMYmk66WPQAAAEI"]
[Mon Jul 27 09:35:34.781108 2026] [:error] [pid 12276:tid 140707012536064] [client 104.23.168.71:10955] [client 104.23.168.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/chunk.js"] [unique_id "amcKRucsEMuHmMYmk66WPQAAAEI"]
[Mon Jul 27 09:35:34.978696 2026] [:error] [pid 21545:tid 140706911823616] [client 104.23.166.181:9776] [client 104.23.166.181] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/static/js/main.js"] [unique_id "amcKRphXfYDIcpslIWOdiQAAAY4"]
[Mon Jul 27 09:35:34.979503 2026] [:error] [pid 21545:tid 140706911823616] [client 104.23.166.181:9776] [client 104.23.166.181] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/static/js/main.js"] [unique_id "amcKRphXfYDIcpslIWOdiQAAAY4"]
[Mon Jul 27 09:35:34.980066 2026] [:error] [pid 21545:tid 140706911823616] [client 104.23.166.181:9776] [client 104.23.166.181] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/static/js/main.js"] [unique_id "amcKRphXfYDIcpslIWOdiQAAAY4"]
[Mon Jul 27 09:35:35.175086 2026] [:error] [pid 12276:tid 140706945394432] [client 162.159.113.42:12797] [client 162.159.113.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/static/js/app.js"] [unique_id "amcKR-csEMuHmMYmk66WPwAAAEo"]
[Mon Jul 27 09:35:35.176127 2026] [:error] [pid 12276:tid 140706945394432] [client 162.159.113.42:12797] [client 162.159.113.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/static/js/app.js"] [unique_id "amcKR-csEMuHmMYmk66WPwAAAEo"]
[Mon Jul 27 09:35:35.176714 2026] [:error] [pid 12276:tid 140706945394432] [client 162.159.113.42:12797] [client 162.159.113.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/static/js/app.js"] [unique_id "amcKR-csEMuHmMYmk66WPwAAAEo"]
[Mon Jul 27 09:35:35.373992 2026] [:error] [pid 24106:tid 140707004143360] [client 104.23.170.103:13508] [client 104.23.170.103] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/static/js/bundle.js"] [unique_id "amcKRzs8oMu6f6EYbxSKTwAAAUM"]
[Mon Jul 27 09:35:35.374886 2026] [:error] [pid 24106:tid 140707004143360] [client 104.23.170.103:13508] [client 104.23.170.103] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/static/js/bundle.js"] [unique_id "amcKRzs8oMu6f6EYbxSKTwAAAUM"]
[Mon Jul 27 09:35:35.375543 2026] [:error] [pid 24106:tid 140707004143360] [client 104.23.170.103:13508] [client 104.23.170.103] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/static/js/bundle.js"] [unique_id "amcKRzs8oMu6f6EYbxSKTwAAAUM"]
[Mon Jul 27 09:35:35.567169 2026] [:error] [pid 21545:tid 140706844681984] [client 104.23.170.88:10286] [client 104.23.170.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dist/main.js"] [unique_id "amcKR5hXfYDIcpslIWOdjQAAAZY"]
[Mon Jul 27 09:35:35.568289 2026] [:error] [pid 21545:tid 140706844681984] [client 104.23.170.88:10286] [client 104.23.170.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dist/main.js"] [unique_id "amcKR5hXfYDIcpslIWOdjQAAAZY"]
[Mon Jul 27 09:35:35.568896 2026] [:error] [pid 21545:tid 140706844681984] [client 104.23.170.88:10286] [client 104.23.170.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dist/main.js"] [unique_id "amcKR5hXfYDIcpslIWOdjQAAAZY"]
[Mon Jul 27 09:35:35.767444 2026] [:error] [pid 12276:tid 140706869860096] [client 172.70.47.186:9253] [client 172.70.47.186] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dist/app.js"] [unique_id "amcKR-csEMuHmMYmk66WQAAAAFM"]
[Mon Jul 27 09:35:35.768175 2026] [:error] [pid 12276:tid 140706869860096] [client 172.70.47.186:9253] [client 172.70.47.186] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dist/app.js"] [unique_id "amcKR-csEMuHmMYmk66WQAAAAFM"]
[Mon Jul 27 09:35:35.768598 2026] [:error] [pid 12276:tid 140706869860096] [client 172.70.47.186:9253] [client 172.70.47.186] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dist/app.js"] [unique_id "amcKR-csEMuHmMYmk66WQAAAAFM"]
[Mon Jul 27 09:35:35.928977 2026] [:error] [pid 21545:tid 140706878252800] [client 162.158.63.138:9781] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKR5hXfYDIcpslIWOdjwAAAZI"]
[Mon Jul 27 09:35:35.929852 2026] [:error] [pid 21545:tid 140706878252800] [client 162.158.63.138:9781] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKR5hXfYDIcpslIWOdjwAAAZI"]
[Mon Jul 27 09:35:35.930395 2026] [:error] [pid 21545:tid 140706878252800] [client 162.158.63.138:9781] [client 162.158.63.138] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua=Google Chrome\\x22;v=\\x22111\\x22, \\x22Not(A:Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22111"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKR5hXfYDIcpslIWOdjwAAAZI"]
[Mon Jul 27 09:35:35.930448 2026] [:error] [pid 21545:tid 140706878252800] [client 162.158.63.138:9781] [client 162.158.63.138] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKR5hXfYDIcpslIWOdjwAAAZI"]
[Mon Jul 27 09:35:35.970078 2026] [:error] [pid 24106:tid 140706978965248] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dist/bundle.js"] [unique_id "amcKRzs8oMu6f6EYbxSKUAAAAUY"]
[Mon Jul 27 09:35:35.970691 2026] [:error] [pid 24106:tid 140706978965248] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dist/bundle.js"] [unique_id "amcKRzs8oMu6f6EYbxSKUAAAAUY"]
[Mon Jul 27 09:35:35.971044 2026] [:error] [pid 24106:tid 140706978965248] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dist/bundle.js"] [unique_id "amcKRzs8oMu6f6EYbxSKUAAAAUY"]
[Mon Jul 27 09:35:36.168542 2026] [:error] [pid 12276:tid 140706953787136] [client 104.23.168.25:9990] [client 104.23.168.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/build/static/js/main.js"] [unique_id "amcKSOcsEMuHmMYmk66WSQAAAEk"]
[Mon Jul 27 09:35:36.169443 2026] [:error] [pid 12276:tid 140706953787136] [client 104.23.168.25:9990] [client 104.23.168.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/build/static/js/main.js"] [unique_id "amcKSOcsEMuHmMYmk66WSQAAAEk"]
[Mon Jul 27 09:35:36.169976 2026] [:error] [pid 12276:tid 140706953787136] [client 104.23.168.25:9990] [client 104.23.168.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/build/static/js/main.js"] [unique_id "amcKSOcsEMuHmMYmk66WSQAAAEk"]
[Mon Jul 27 09:35:36.371342 2026] [:error] [pid 21545:tid 140706945394432] [client 172.71.103.22:9682] [client 172.71.103.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/assets/index.js"] [unique_id "amcKSJhXfYDIcpslIWOdkQAAAYo"]
[Mon Jul 27 09:35:36.372071 2026] [:error] [pid 21545:tid 140706945394432] [client 172.71.103.22:9682] [client 172.71.103.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/assets/index.js"] [unique_id "amcKSJhXfYDIcpslIWOdkQAAAYo"]
[Mon Jul 27 09:35:36.372442 2026] [:error] [pid 21545:tid 140706945394432] [client 172.71.103.22:9682] [client 172.71.103.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/assets/index.js"] [unique_id "amcKSJhXfYDIcpslIWOdkQAAAYo"]
[Mon Jul 27 09:35:36.580137 2026] [:error] [pid 12276:tid 140707020928768] [client 172.71.102.215:11586] [client 172.71.102.215] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/assets/app.js"] [unique_id "amcKSOcsEMuHmMYmk66WXgAAAEE"]
[Mon Jul 27 09:35:36.581074 2026] [:error] [pid 12276:tid 140707020928768] [client 172.71.102.215:11586] [client 172.71.102.215] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/assets/app.js"] [unique_id "amcKSOcsEMuHmMYmk66WXgAAAEE"]
[Mon Jul 27 09:35:36.581576 2026] [:error] [pid 12276:tid 140707020928768] [client 172.71.102.215:11586] [client 172.71.102.215] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/assets/app.js"] [unique_id "amcKSOcsEMuHmMYmk66WXgAAAEE"]
[Mon Jul 27 09:35:36.787351 2026] [:error] [pid 24106:tid 140706886645504] [client 172.71.99.90:9753] [client 172.71.99.90] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/js/app.js"] [unique_id "amcKSDs8oMu6f6EYbxSKUgAAAVE"]
[Mon Jul 27 09:35:36.788191 2026] [:error] [pid 24106:tid 140706886645504] [client 172.71.99.90:9753] [client 172.71.99.90] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/js/app.js"] [unique_id "amcKSDs8oMu6f6EYbxSKUgAAAVE"]
[Mon Jul 27 09:35:36.788714 2026] [:error] [pid 24106:tid 140706886645504] [client 172.71.99.90:9753] [client 172.71.99.90] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/js/app.js"] [unique_id "amcKSDs8oMu6f6EYbxSKUgAAAVE"]
[Mon Jul 27 09:35:36.991667 2026] [:error] [pid 21545:tid 140706970572544] [client 104.23.170.180:14299] [client 104.23.170.180] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/js/main.js"] [unique_id "amcKSJhXfYDIcpslIWOdlAAAAYc"]
[Mon Jul 27 09:35:36.992576 2026] [:error] [pid 21545:tid 140706970572544] [client 104.23.170.180:14299] [client 104.23.170.180] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/js/main.js"] [unique_id "amcKSJhXfYDIcpslIWOdlAAAAYc"]
[Mon Jul 27 09:35:36.992988 2026] [:error] [pid 21545:tid 140706970572544] [client 104.23.170.180:14299] [client 104.23.170.180] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/js/main.js"] [unique_id "amcKSJhXfYDIcpslIWOdlAAAAYc"]
[Mon Jul 27 09:35:37.155116 2026] [:error] [pid 21545:tid 140706861467392] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/settings.py"] [unique_id "amcKSZhXfYDIcpslIWOdlQAAAZQ"]
[Mon Jul 27 09:35:37.156201 2026] [:error] [pid 21545:tid 140706861467392] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/settings.py"] [unique_id "amcKSZhXfYDIcpslIWOdlQAAAZQ"]
[Mon Jul 27 09:35:37.156756 2026] [:error] [pid 21545:tid 140706861467392] [client 172.70.46.165:13684] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/settings.py"] [unique_id "amcKSZhXfYDIcpslIWOdlQAAAZQ"]
[Mon Jul 27 09:35:37.359365 2026] [:error] [pid 21545:tid 140706886645504] [client 104.23.172.124:10899] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.py"] [unique_id "amcKSZhXfYDIcpslIWOdlgAAAZE"]
[Mon Jul 27 09:35:37.360273 2026] [:error] [pid 21545:tid 140706886645504] [client 104.23.172.124:10899] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.py"] [unique_id "amcKSZhXfYDIcpslIWOdlgAAAZE"]
[Mon Jul 27 09:35:37.360779 2026] [:error] [pid 21545:tid 140706886645504] [client 104.23.172.124:10899] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.py"] [unique_id "amcKSZhXfYDIcpslIWOdlgAAAZE"]
[Mon Jul 27 09:35:37.567800 2026] [:error] [pid 12275:tid 140706895038208] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/secrets.py"] [unique_id "amcKSXFwI8r7BFXGkAuE5wAAABA"]
[Mon Jul 27 09:35:37.568466 2026] [:error] [pid 12275:tid 140706895038208] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/secrets.py"] [unique_id "amcKSXFwI8r7BFXGkAuE5wAAABA"]
[Mon Jul 27 09:35:37.568885 2026] [:error] [pid 12275:tid 140706895038208] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets.py"] [unique_id "amcKSXFwI8r7BFXGkAuE5wAAABA"]
[Mon Jul 27 09:35:37.731859 2026] [:error] [pid 21545:tid 140706920216320] [client 104.23.172.124:10899] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/secrets.yml"] [unique_id "amcKSZhXfYDIcpslIWOdmAAAAY0"]
[Mon Jul 27 09:35:37.732832 2026] [:error] [pid 21545:tid 140706920216320] [client 104.23.172.124:10899] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/secrets.yml"] [unique_id "amcKSZhXfYDIcpslIWOdmAAAAY0"]
[Mon Jul 27 09:35:37.733395 2026] [:error] [pid 21545:tid 140706920216320] [client 104.23.172.124:10899] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/secrets.yml"] [unique_id "amcKSZhXfYDIcpslIWOdmAAAAY0"]
[Mon Jul 27 09:35:37.904817 2026] [:error] [pid 12275:tid 140706962179840] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/master.key"] [unique_id "amcKSXFwI8r7BFXGkAuE6AAAAAg"]
[Mon Jul 27 09:35:37.905782 2026] [:error] [pid 12275:tid 140706962179840] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/master.key"] [unique_id "amcKSXFwI8r7BFXGkAuE6AAAAAg"]
[Mon Jul 27 09:35:37.906427 2026] [:error] [pid 12275:tid 140706962179840] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/master.key"] [unique_id "amcKSXFwI8r7BFXGkAuE6AAAAAg"]
[Mon Jul 27 09:35:39.838402 2026] [:error] [pid 21545:tid 140707004143360] [client 172.71.118.225:9280] [client 172.71.118.225] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKS5hXfYDIcpslIWOdngAAAYM"]
[Mon Jul 27 09:35:39.839413 2026] [:error] [pid 21545:tid 140707004143360] [client 172.71.118.225:9280] [client 172.71.118.225] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKS5hXfYDIcpslIWOdngAAAYM"]
[Mon Jul 27 09:35:39.840017 2026] [:error] [pid 21545:tid 140707004143360] [client 172.71.118.225:9280] [client 172.71.118.225] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKS5hXfYDIcpslIWOdngAAAYM"]
[Mon Jul 27 09:35:39.840293 2026] [:error] [pid 21545:tid 140707004143360] [client 172.71.118.225:9280] [client 172.71.118.225] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKS5hXfYDIcpslIWOdngAAAYM"]
[Mon Jul 27 09:35:40.769188 2026] [:error] [pid 12275:tid 140706844681984] [client 172.71.232.34:9694] [client 172.71.232.34] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKTHFwI8r7BFXGkAuE7wAAABY"]
[Mon Jul 27 09:35:40.770376 2026] [:error] [pid 12275:tid 140706844681984] [client 172.71.232.34:9694] [client 172.71.232.34] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKTHFwI8r7BFXGkAuE7wAAABY"]
[Mon Jul 27 09:35:40.771098 2026] [:error] [pid 12275:tid 140706844681984] [client 172.71.232.34:9694] [client 172.71.232.34] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKTHFwI8r7BFXGkAuE7wAAABY"]
[Mon Jul 27 09:35:40.771353 2026] [:error] [pid 12275:tid 140706844681984] [client 172.71.232.34:9694] [client 172.71.232.34] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKTHFwI8r7BFXGkAuE7wAAABY"]
[Mon Jul 27 09:35:40.875289 2026] [:error] [pid 24106:tid 140706995750656] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/app.php"] [unique_id "amcKTDs8oMu6f6EYbxSKVgAAAUQ"]
[Mon Jul 27 09:35:40.876187 2026] [:error] [pid 24106:tid 140706995750656] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/app.php"] [unique_id "amcKTDs8oMu6f6EYbxSKVgAAAUQ"]
[Mon Jul 27 09:35:40.876755 2026] [:error] [pid 24106:tid 140706995750656] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/app.php"] [unique_id "amcKTDs8oMu6f6EYbxSKVgAAAUQ"]
[Mon Jul 27 09:35:41.041888 2026] [:error] [pid 24106:tid 140707020928768] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application.properties"] [unique_id "amcKTTs8oMu6f6EYbxSKVwAAAUE"]
[Mon Jul 27 09:35:41.042861 2026] [:error] [pid 24106:tid 140707020928768] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application.properties"] [unique_id "amcKTTs8oMu6f6EYbxSKVwAAAUE"]
[Mon Jul 27 09:35:41.043461 2026] [:error] [pid 24106:tid 140707020928768] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application.properties"] [unique_id "amcKTTs8oMu6f6EYbxSKVwAAAUE"]
[Mon Jul 27 09:35:41.214249 2026] [:error] [pid 24106:tid 140706953787136] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application.yml"] [unique_id "amcKTTs8oMu6f6EYbxSKWQAAAUk"]
[Mon Jul 27 09:35:41.214997 2026] [:error] [pid 24106:tid 140706953787136] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application.yml"] [unique_id "amcKTTs8oMu6f6EYbxSKWQAAAUk"]
[Mon Jul 27 09:35:41.215468 2026] [:error] [pid 24106:tid 140706953787136] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application.yml"] [unique_id "amcKTTs8oMu6f6EYbxSKWQAAAUk"]
[Mon Jul 27 09:35:41.390649 2026] [:error] [pid 24106:tid 140706928609024] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application.yaml"] [unique_id "amcKTTs8oMu6f6EYbxSKWgAAAUw"]
[Mon Jul 27 09:35:41.391323 2026] [:error] [pid 24106:tid 140706928609024] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application.yaml"] [unique_id "amcKTTs8oMu6f6EYbxSKWgAAAUw"]
[Mon Jul 27 09:35:41.391754 2026] [:error] [pid 24106:tid 140706928609024] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application.yaml"] [unique_id "amcKTTs8oMu6f6EYbxSKWgAAAUw"]
[Mon Jul 27 09:35:41.565387 2026] [:error] [pid 24106:tid 140706844681984] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application-dev.properties"] [unique_id "amcKTTs8oMu6f6EYbxSKWwAAAVY"]
[Mon Jul 27 09:35:41.566276 2026] [:error] [pid 24106:tid 140706844681984] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application-dev.properties"] [unique_id "amcKTTs8oMu6f6EYbxSKWwAAAVY"]
[Mon Jul 27 09:35:41.566768 2026] [:error] [pid 24106:tid 140706844681984] [client 172.71.183.35:11177] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application-dev.properties"] [unique_id "amcKTTs8oMu6f6EYbxSKWwAAAVY"]
[Mon Jul 27 09:35:41.777212 2026] [:error] [pid 12275:tid 140706836289280] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application-prod.properties"] [unique_id "amcKTXFwI8r7BFXGkAuE8gAAABc"]
[Mon Jul 27 09:35:41.777863 2026] [:error] [pid 12275:tid 140706836289280] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application-prod.properties"] [unique_id "amcKTXFwI8r7BFXGkAuE8gAAABc"]
[Mon Jul 27 09:35:41.778349 2026] [:error] [pid 12275:tid 140706836289280] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application-prod.properties"] [unique_id "amcKTXFwI8r7BFXGkAuE8gAAABc"]
[Mon Jul 27 09:35:41.982365 2026] [:error] [pid 12276:tid 140706911823616] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/appsettings.json"] [unique_id "amcKTecsEMuHmMYmk66WbgAAAE4"]
[Mon Jul 27 09:35:41.983085 2026] [:error] [pid 12276:tid 140706911823616] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/appsettings.json"] [unique_id "amcKTecsEMuHmMYmk66WbgAAAE4"]
[Mon Jul 27 09:35:41.983486 2026] [:error] [pid 12276:tid 140706911823616] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/appsettings.json"] [unique_id "amcKTecsEMuHmMYmk66WbgAAAE4"]
[Mon Jul 27 09:35:42.107892 2026] [:error] [pid 12275:tid 140707103270656] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/appsettings.Development.json"] [unique_id "amcKTnFwI8r7BFXGkAuE8wAAAAA"]
[Mon Jul 27 09:35:42.108771 2026] [:error] [pid 12275:tid 140707103270656] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/appsettings.Development.json"] [unique_id "amcKTnFwI8r7BFXGkAuE8wAAAAA"]
[Mon Jul 27 09:35:42.109195 2026] [:error] [pid 12275:tid 140707103270656] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/appsettings.Development.json"] [unique_id "amcKTnFwI8r7BFXGkAuE8wAAAAA"]
[Mon Jul 27 09:35:42.286594 2026] [:error] [pid 12275:tid 140706995750656] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/appsettings.Production.json"] [unique_id "amcKTnFwI8r7BFXGkAuE9QAAAAQ"]
[Mon Jul 27 09:35:42.287494 2026] [:error] [pid 12275:tid 140706995750656] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/appsettings.Production.json"] [unique_id "amcKTnFwI8r7BFXGkAuE9QAAAAQ"]
[Mon Jul 27 09:35:42.288032 2026] [:error] [pid 12275:tid 140706995750656] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/appsettings.Production.json"] [unique_id "amcKTnFwI8r7BFXGkAuE9QAAAAQ"]
[Mon Jul 27 09:35:42.455773 2026] [:error] [pid 12275:tid 140706853074688] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amcKTnFwI8r7BFXGkAuE9gAAABU"]
[Mon Jul 27 09:35:42.456425 2026] [:error] [pid 12275:tid 140706853074688] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amcKTnFwI8r7BFXGkAuE9gAAABU"]
[Mon Jul 27 09:35:42.456793 2026] [:error] [pid 12275:tid 140706853074688] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amcKTnFwI8r7BFXGkAuE9gAAABU"]
[Mon Jul 27 09:35:42.622735 2026] [:error] [pid 12275:tid 140706978965248] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amcKTnFwI8r7BFXGkAuE9wAAAAY"]
[Mon Jul 27 09:35:42.623755 2026] [:error] [pid 12275:tid 140706978965248] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amcKTnFwI8r7BFXGkAuE9wAAAAY"]
[Mon Jul 27 09:35:42.624326 2026] [:error] [pid 12275:tid 140706978965248] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amcKTnFwI8r7BFXGkAuE9wAAAAY"]
[Mon Jul 27 09:35:42.792908 2026] [:error] [pid 12275:tid 140706827896576] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.toml"] [unique_id "amcKTnFwI8r7BFXGkAuE-AAAABg"]
[Mon Jul 27 09:35:42.793545 2026] [:error] [pid 12275:tid 140706827896576] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.toml"] [unique_id "amcKTnFwI8r7BFXGkAuE-AAAABg"]
[Mon Jul 27 09:35:42.793911 2026] [:error] [pid 12275:tid 140706827896576] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.toml"] [unique_id "amcKTnFwI8r7BFXGkAuE-AAAABg"]
[Mon Jul 27 09:35:42.963947 2026] [:error] [pid 12275:tid 140706895038208] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/serverless.yml"] [unique_id "amcKTnFwI8r7BFXGkAuE-gAAABA"]
[Mon Jul 27 09:35:42.964795 2026] [:error] [pid 12275:tid 140706895038208] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/serverless.yml"] [unique_id "amcKTnFwI8r7BFXGkAuE-gAAABA"]
[Mon Jul 27 09:35:42.965343 2026] [:error] [pid 12275:tid 140706895038208] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/serverless.yml"] [unique_id "amcKTnFwI8r7BFXGkAuE-gAAABA"]
[Mon Jul 27 09:35:43.135588 2026] [:error] [pid 12275:tid 140706869860096] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/serverless.yaml"] [unique_id "amcKT3FwI8r7BFXGkAuE-wAAABM"]
[Mon Jul 27 09:35:43.136507 2026] [:error] [pid 12275:tid 140706869860096] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/serverless.yaml"] [unique_id "amcKT3FwI8r7BFXGkAuE-wAAABM"]
[Mon Jul 27 09:35:43.137064 2026] [:error] [pid 12275:tid 140706869860096] [client 104.23.170.162:13336] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/serverless.yaml"] [unique_id "amcKT3FwI8r7BFXGkAuE-wAAABM"]
[Mon Jul 27 09:35:43.307303 2026] [:error] [pid 12275:tid 140706962179840] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/production.json"] [unique_id "amcKT3FwI8r7BFXGkAuE_AAAAAg"]
[Mon Jul 27 09:35:43.308037 2026] [:error] [pid 12275:tid 140706962179840] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/production.json"] [unique_id "amcKT3FwI8r7BFXGkAuE_AAAAAg"]
[Mon Jul 27 09:35:43.308506 2026] [:error] [pid 12275:tid 140706962179840] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/production.json"] [unique_id "amcKT3FwI8r7BFXGkAuE_AAAAAg"]
[Mon Jul 27 09:35:43.479715 2026] [:error] [pid 12276:tid 140706878252800] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/development.json"] [unique_id "amcKT-csEMuHmMYmk66WcwAAAFI"]
[Mon Jul 27 09:35:43.480646 2026] [:error] [pid 12276:tid 140706878252800] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/development.json"] [unique_id "amcKT-csEMuHmMYmk66WcwAAAFI"]
[Mon Jul 27 09:35:43.481192 2026] [:error] [pid 12276:tid 140706878252800] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/development.json"] [unique_id "amcKT-csEMuHmMYmk66WcwAAAFI"]
[Mon Jul 27 09:35:43.654161 2026] [:error] [pid 12276:tid 140707012536064] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/default.json"] [unique_id "amcKT-csEMuHmMYmk66WdAAAAEI"]
[Mon Jul 27 09:35:43.654965 2026] [:error] [pid 12276:tid 140707012536064] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/default.json"] [unique_id "amcKT-csEMuHmMYmk66WdAAAAEI"]
[Mon Jul 27 09:35:43.655471 2026] [:error] [pid 12276:tid 140707012536064] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/default.json"] [unique_id "amcKT-csEMuHmMYmk66WdAAAAEI"]
[Mon Jul 27 09:35:43.798771 2026] [:error] [pid 12276:tid 140706869860096] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/local.json"] [unique_id "amcKT-csEMuHmMYmk66WdQAAAFM"]
[Mon Jul 27 09:35:43.799949 2026] [:error] [pid 12276:tid 140706869860096] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/local.json"] [unique_id "amcKT-csEMuHmMYmk66WdQAAAFM"]
[Mon Jul 27 09:35:43.800718 2026] [:error] [pid 12276:tid 140706869860096] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/local.json"] [unique_id "amcKT-csEMuHmMYmk66WdQAAAFM"]
[Mon Jul 27 09:35:43.926756 2026] [:error] [pid 12276:tid 140707103270656] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/conf/settings.json"] [unique_id "amcKT-csEMuHmMYmk66WdgAAAEA"]
[Mon Jul 27 09:35:43.927663 2026] [:error] [pid 12276:tid 140707103270656] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/conf/settings.json"] [unique_id "amcKT-csEMuHmMYmk66WdgAAAEA"]
[Mon Jul 27 09:35:43.928178 2026] [:error] [pid 12276:tid 140707103270656] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/conf/settings.json"] [unique_id "amcKT-csEMuHmMYmk66WdgAAAEA"]
[Mon Jul 27 09:35:44.058404 2026] [:error] [pid 12276:tid 140706836289280] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/data/config.json"] [unique_id "amcKUOcsEMuHmMYmk66WdwAAAFc"]
[Mon Jul 27 09:35:44.059342 2026] [:error] [pid 12276:tid 140706836289280] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/data/config.json"] [unique_id "amcKUOcsEMuHmMYmk66WdwAAAFc"]
[Mon Jul 27 09:35:44.059925 2026] [:error] [pid 12276:tid 140706836289280] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/data/config.json"] [unique_id "amcKUOcsEMuHmMYmk66WdwAAAFc"]
[Mon Jul 27 09:35:44.174892 2026] [:error] [pid 12276:tid 140706827896576] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcKUOcsEMuHmMYmk66WeAAAAFg"]
[Mon Jul 27 09:35:44.175530 2026] [:error] [pid 12276:tid 140706827896576] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcKUOcsEMuHmMYmk66WeAAAAFg"]
[Mon Jul 27 09:35:44.175886 2026] [:error] [pid 12276:tid 140706827896576] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcKUOcsEMuHmMYmk66WeAAAAFg"]
[Mon Jul 27 09:35:44.301283 2026] [:error] [pid 12276:tid 140706987357952] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/actuator/configprops"] [unique_id "amcKUOcsEMuHmMYmk66WegAAAEU"]
[Mon Jul 27 09:35:44.302240 2026] [:error] [pid 12276:tid 140706987357952] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/actuator/configprops"] [unique_id "amcKUOcsEMuHmMYmk66WegAAAEU"]
[Mon Jul 27 09:35:44.302820 2026] [:error] [pid 12276:tid 140706987357952] [client 104.23.168.5:13891] [client 104.23.168.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/actuator/configprops"] [unique_id "amcKUOcsEMuHmMYmk66WegAAAEU"]
[Mon Jul 27 09:35:44.418308 2026] [:error] [pid 12276:tid 140706903430912] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amcKUOcsEMuHmMYmk66WewAAAE8"]
[Mon Jul 27 09:35:44.419321 2026] [:error] [pid 12276:tid 140706903430912] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amcKUOcsEMuHmMYmk66WewAAAE8"]
[Mon Jul 27 09:35:44.420115 2026] [:error] [pid 12276:tid 140706903430912] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amcKUOcsEMuHmMYmk66WewAAAE8"]
[Mon Jul 27 09:35:44.545728 2026] [:error] [pid 12275:tid 140706903430912] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/settings"] [unique_id "amcKUHFwI8r7BFXGkAuE_wAAAA8"]
[Mon Jul 27 09:35:44.546756 2026] [:error] [pid 12275:tid 140706903430912] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/settings"] [unique_id "amcKUHFwI8r7BFXGkAuE_wAAAA8"]
[Mon Jul 27 09:35:44.547316 2026] [:error] [pid 12275:tid 140706903430912] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/settings"] [unique_id "amcKUHFwI8r7BFXGkAuE_wAAAA8"]
[Mon Jul 27 09:35:44.707822 2026] [:error] [pid 12276:tid 140707020928768] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/env"] [unique_id "amcKUOcsEMuHmMYmk66WfAAAAEE"]
[Mon Jul 27 09:35:44.708471 2026] [:error] [pid 12276:tid 140707020928768] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/env"] [unique_id "amcKUOcsEMuHmMYmk66WfAAAAEE"]
[Mon Jul 27 09:35:44.708844 2026] [:error] [pid 12276:tid 140707020928768] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/env"] [unique_id "amcKUOcsEMuHmMYmk66WfAAAAEE"]
[Mon Jul 27 09:35:44.838116 2026] [:error] [pid 12275:tid 140707012536064] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amcKUHFwI8r7BFXGkAuFAQAAAAI"]
[Mon Jul 27 09:35:44.839045 2026] [:error] [pid 12275:tid 140707012536064] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amcKUHFwI8r7BFXGkAuFAQAAAAI"]
[Mon Jul 27 09:35:44.839616 2026] [:error] [pid 12275:tid 140707012536064] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amcKUHFwI8r7BFXGkAuFAQAAAAI"]
[Mon Jul 27 09:35:44.839882 2026] [:error] [pid 12275:tid 140707012536064] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backup/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amcKUHFwI8r7BFXGkAuFAQAAAAI"]
[Mon Jul 27 09:35:45.007661 2026] [:error] [pid 12276:tid 140706928609024] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amcKUecsEMuHmMYmk66WfQAAAEw"]
[Mon Jul 27 09:35:45.011133 2026] [:error] [pid 12276:tid 140706928609024] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amcKUecsEMuHmMYmk66WfQAAAEw"]
[Mon Jul 27 09:35:45.011669 2026] [:error] [pid 12276:tid 140706928609024] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amcKUecsEMuHmMYmk66WfQAAAEw"]
[Mon Jul 27 09:35:45.011920 2026] [:error] [pid 12276:tid 140706928609024] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backups/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amcKUecsEMuHmMYmk66WfQAAAEw"]
[Mon Jul 27 09:35:45.143672 2026] [:error] [pid 12275:tid 140706945394432] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amcKUXFwI8r7BFXGkAuFAgAAAAo"]
[Mon Jul 27 09:35:45.144442 2026] [:error] [pid 12275:tid 140706945394432] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amcKUXFwI8r7BFXGkAuFAgAAAAo"]
[Mon Jul 27 09:35:45.144847 2026] [:error] [pid 12275:tid 140706945394432] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amcKUXFwI8r7BFXGkAuFAgAAAAo"]
[Mon Jul 27 09:35:45.145025 2026] [:error] [pid 12275:tid 140706945394432] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /old/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amcKUXFwI8r7BFXGkAuFAgAAAAo"]
[Mon Jul 27 09:35:45.313473 2026] [:error] [pid 12276:tid 140706978965248] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amcKUecsEMuHmMYmk66WfwAAAEY"]
[Mon Jul 27 09:35:45.314456 2026] [:error] [pid 12276:tid 140706978965248] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amcKUecsEMuHmMYmk66WfwAAAEY"]
[Mon Jul 27 09:35:45.315003 2026] [:error] [pid 12276:tid 140706978965248] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amcKUecsEMuHmMYmk66WfwAAAEY"]
[Mon Jul 27 09:35:45.315257 2026] [:error] [pid 12276:tid 140706978965248] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /temp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amcKUecsEMuHmMYmk66WfwAAAEY"]
[Mon Jul 27 09:35:45.450930 2026] [:error] [pid 12275:tid 140706844681984] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amcKUXFwI8r7BFXGkAuFBQAAABY"]
[Mon Jul 27 09:35:45.451869 2026] [:error] [pid 12275:tid 140706844681984] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amcKUXFwI8r7BFXGkAuFBQAAABY"]
[Mon Jul 27 09:35:45.452377 2026] [:error] [pid 12275:tid 140706844681984] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amcKUXFwI8r7BFXGkAuFBQAAABY"]
[Mon Jul 27 09:35:45.452660 2026] [:error] [pid 12275:tid 140706844681984] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tmp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amcKUXFwI8r7BFXGkAuFBQAAABY"]
[Mon Jul 27 09:35:45.622656 2026] [:error] [pid 12276:tid 140706844681984] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.streamlit/secrets.toml"] [unique_id "amcKUecsEMuHmMYmk66WgAAAAFY"]
[Mon Jul 27 09:35:45.623492 2026] [:error] [pid 12276:tid 140706844681984] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.streamlit/secrets.toml"] [unique_id "amcKUecsEMuHmMYmk66WgAAAAFY"]
[Mon Jul 27 09:35:45.623896 2026] [:error] [pid 12276:tid 140706844681984] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.streamlit/secrets.toml"] [unique_id "amcKUecsEMuHmMYmk66WgAAAAFY"]
[Mon Jul 27 09:35:45.665352 2026] [:error] [pid 24106:tid 140706886645504] [client 104.22.64.160:13383] [client 104.22.64.160] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKUTs8oMu6f6EYbxSKYQAAAVE"]
[Mon Jul 27 09:35:45.666405 2026] [:error] [pid 24106:tid 140706886645504] [client 104.22.64.160:13383] [client 104.22.64.160] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKUTs8oMu6f6EYbxSKYQAAAVE"]
[Mon Jul 27 09:35:45.667211 2026] [:error] [pid 24106:tid 140706886645504] [client 104.22.64.160:13383] [client 104.22.64.160] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKUTs8oMu6f6EYbxSKYQAAAVE"]
[Mon Jul 27 09:35:45.762085 2026] [:error] [pid 12275:tid 140706987357952] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/root/.streamlit/secrets.toml"] [unique_id "amcKUXFwI8r7BFXGkAuFBgAAAAU"]
[Mon Jul 27 09:35:45.763010 2026] [:error] [pid 12275:tid 140706987357952] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/root/.streamlit/secrets.toml"] [unique_id "amcKUXFwI8r7BFXGkAuFBgAAAAU"]
[Mon Jul 27 09:35:45.763506 2026] [:error] [pid 12275:tid 140706987357952] [client 162.159.113.44:11771] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/root/.streamlit/secrets.toml"] [unique_id "amcKUXFwI8r7BFXGkAuFBgAAAAU"]
[Mon Jul 27 09:35:45.931737 2026] [:error] [pid 12276:tid 140706920216320] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/root/.aws/credentials"] [unique_id "amcKUecsEMuHmMYmk66WggAAAE0"]
[Mon Jul 27 09:35:45.932633 2026] [:error] [pid 12276:tid 140706920216320] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/root/.aws/credentials"] [unique_id "amcKUecsEMuHmMYmk66WggAAAE0"]
[Mon Jul 27 09:35:45.933179 2026] [:error] [pid 12276:tid 140706920216320] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/root/.aws/credentials"] [unique_id "amcKUecsEMuHmMYmk66WggAAAE0"]
[Mon Jul 27 09:35:45.933475 2026] [:error] [pid 12276:tid 140706920216320] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/root/.aws/credentials"] [unique_id "amcKUecsEMuHmMYmk66WggAAAE0"]
[Mon Jul 27 09:35:46.114524 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.103.41:13992] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.aws/credentials"] [unique_id "amcKUucsEMuHmMYmk66WhQAAAEg"]
[Mon Jul 27 09:35:46.115469 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.103.41:13992] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.aws/credentials"] [unique_id "amcKUucsEMuHmMYmk66WhQAAAEg"]
[Mon Jul 27 09:35:46.115973 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.103.41:13992] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.aws/credentials"] [unique_id "amcKUucsEMuHmMYmk66WhQAAAEg"]
[Mon Jul 27 09:35:46.116258 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.103.41:13992] [client 172.71.103.41] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /home/ubuntu/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.aws/credentials"] [unique_id "amcKUucsEMuHmMYmk66WhQAAAEg"]
[Mon Jul 27 09:35:46.297205 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/home/ec2-user/.aws/credentials"] [unique_id "amcKUucsEMuHmMYmk66WhwAAAFM"]
[Mon Jul 27 09:35:46.298120 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/home/ec2-user/.aws/credentials"] [unique_id "amcKUucsEMuHmMYmk66WhwAAAFM"]
[Mon Jul 27 09:35:46.298647 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/home/ec2-user/.aws/credentials"] [unique_id "amcKUucsEMuHmMYmk66WhwAAAFM"]
[Mon Jul 27 09:35:46.298909 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.98.107:13204] [client 172.71.98.107] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /home/ec2-user/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/home/ec2-user/.aws/credentials"] [unique_id "amcKUucsEMuHmMYmk66WhwAAAFM"]
[Mon Jul 27 09:35:46.444756 2026] [:error] [pid 12276:tid 140707103270656] [client 172.71.103.41:13992] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/home/node/.aws/credentials"] [unique_id "amcKUucsEMuHmMYmk66WiQAAAEA"]
[Mon Jul 27 09:35:46.445687 2026] [:error] [pid 12276:tid 140707103270656] [client 172.71.103.41:13992] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/home/node/.aws/credentials"] [unique_id "amcKUucsEMuHmMYmk66WiQAAAEA"]
[Mon Jul 27 09:35:46.446209 2026] [:error] [pid 12276:tid 140707103270656] [client 172.71.103.41:13992] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/home/node/.aws/credentials"] [unique_id "amcKUucsEMuHmMYmk66WiQAAAEA"]
[Mon Jul 27 09:35:46.446445 2026] [:error] [pid 12276:tid 140707103270656] [client 172.71.103.41:13992] [client 172.71.103.41] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /home/node/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/home/node/.aws/credentials"] [unique_id "amcKUucsEMuHmMYmk66WiQAAAEA"]
[Mon Jul 27 09:35:46.613349 2026] [:error] [pid 12276:tid 140706836289280] [client 172.71.232.155:13042] [client 172.71.232.155] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKUucsEMuHmMYmk66WigAAAFc"]
[Mon Jul 27 09:35:46.614335 2026] [:error] [pid 12276:tid 140706836289280] [client 172.71.232.155:13042] [client 172.71.232.155] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKUucsEMuHmMYmk66WigAAAFc"]
[Mon Jul 27 09:35:46.614828 2026] [:error] [pid 12276:tid 140706836289280] [client 172.71.232.155:13042] [client 172.71.232.155] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKUucsEMuHmMYmk66WigAAAFc"]
[Mon Jul 27 09:35:46.614945 2026] [:error] [pid 12276:tid 140706836289280] [client 172.71.232.155:13042] [client 172.71.232.155] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKUucsEMuHmMYmk66WigAAAFc"]
[Mon Jul 27 09:35:46.615218 2026] [:error] [pid 12276:tid 140706836289280] [client 172.71.232.155:13042] [client 172.71.232.155] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcKUucsEMuHmMYmk66WigAAAFc"]
[Mon Jul 27 09:35:46.649294 2026] [:error] [pid 12276:tid 140706827896576] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/terraform.tfvars"] [unique_id "amcKUucsEMuHmMYmk66WiwAAAFg"]
[Mon Jul 27 09:35:46.650298 2026] [:error] [pid 12276:tid 140706827896576] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/terraform.tfvars"] [unique_id "amcKUucsEMuHmMYmk66WiwAAAFg"]
[Mon Jul 27 09:35:46.650857 2026] [:error] [pid 12276:tid 140706827896576] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/terraform.tfvars"] [unique_id "amcKUucsEMuHmMYmk66WiwAAAFg"]
[Mon Jul 27 09:35:46.810634 2026] [:error] [pid 12276:tid 140706895038208] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/terraform.tfstate"] [unique_id "amcKUucsEMuHmMYmk66WjAAAAFA"]
[Mon Jul 27 09:35:46.812090 2026] [:error] [pid 12276:tid 140706895038208] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/terraform.tfstate"] [unique_id "amcKUucsEMuHmMYmk66WjAAAAFA"]
[Mon Jul 27 09:35:46.812580 2026] [:error] [pid 12276:tid 140706895038208] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/terraform.tfstate"] [unique_id "amcKUucsEMuHmMYmk66WjAAAAFA"]
[Mon Jul 27 09:35:46.868185 2026] [:error] [pid 12276:tid 140706987357952] [client 172.71.232.155:13042] [client 172.71.232.155] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKUucsEMuHmMYmk66WjQAAAEU"]
[Mon Jul 27 09:35:46.869346 2026] [:error] [pid 12276:tid 140706987357952] [client 172.71.232.155:13042] [client 172.71.232.155] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKUucsEMuHmMYmk66WjQAAAEU"]
[Mon Jul 27 09:35:46.871756 2026] [:error] [pid 12276:tid 140706987357952] [client 172.71.232.155:13042] [client 172.71.232.155] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKUucsEMuHmMYmk66WjQAAAEU"]
[Mon Jul 27 09:35:46.871937 2026] [:error] [pid 12276:tid 140706987357952] [client 172.71.232.155:13042] [client 172.71.232.155] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKUucsEMuHmMYmk66WjQAAAEU"]
[Mon Jul 27 09:35:46.872797 2026] [:error] [pid 12276:tid 140706987357952] [client 172.71.232.155:13042] [client 172.71.232.155] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcKUucsEMuHmMYmk66WjQAAAEU"]
[Mon Jul 27 09:35:47.013882 2026] [:error] [pid 12276:tid 140706953787136] [client 104.23.170.51:13257] [client 104.23.170.51] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ecosystem.config.js"] [unique_id "amcKU-csEMuHmMYmk66WjgAAAEk"]
[Mon Jul 27 09:35:47.014847 2026] [:error] [pid 12276:tid 140706953787136] [client 104.23.170.51:13257] [client 104.23.170.51] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ecosystem.config.js"] [unique_id "amcKU-csEMuHmMYmk66WjgAAAEk"]
[Mon Jul 27 09:35:47.015360 2026] [:error] [pid 12276:tid 140706953787136] [client 104.23.170.51:13257] [client 104.23.170.51] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ecosystem.config.js"] [unique_id "amcKU-csEMuHmMYmk66WjgAAAEk"]
[Mon Jul 27 09:35:47.190828 2026] [:error] [pid 12276:tid 140707020928768] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/secrets.yaml"] [unique_id "amcKU-csEMuHmMYmk66WjwAAAEE"]
[Mon Jul 27 09:35:47.191444 2026] [:error] [pid 12276:tid 140707020928768] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/secrets.yaml"] [unique_id "amcKU-csEMuHmMYmk66WjwAAAEE"]
[Mon Jul 27 09:35:47.191809 2026] [:error] [pid 12276:tid 140707020928768] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets.yaml"] [unique_id "amcKU-csEMuHmMYmk66WjwAAAEE"]
[Mon Jul 27 09:35:47.367113 2026] [:error] [pid 12276:tid 140706978965248] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/secrets.yml"] [unique_id "amcKU-csEMuHmMYmk66WkAAAAEY"]
[Mon Jul 27 09:35:47.367823 2026] [:error] [pid 12276:tid 140706978965248] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/secrets.yml"] [unique_id "amcKU-csEMuHmMYmk66WkAAAAEY"]
[Mon Jul 27 09:35:47.368216 2026] [:error] [pid 12276:tid 140706978965248] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets.yml"] [unique_id "amcKU-csEMuHmMYmk66WkAAAAEY"]
[Mon Jul 27 09:35:47.532411 2026] [:error] [pid 12276:tid 140706911823616] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.secrets"] [unique_id "amcKU-csEMuHmMYmk66WkQAAAE4"]
[Mon Jul 27 09:35:47.533431 2026] [:error] [pid 12276:tid 140706911823616] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.secrets"] [unique_id "amcKU-csEMuHmMYmk66WkQAAAE4"]
[Mon Jul 27 09:35:47.533959 2026] [:error] [pid 12276:tid 140706911823616] [client 172.71.183.36:12159] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.secrets"] [unique_id "amcKU-csEMuHmMYmk66WkQAAAE4"]
[Mon Jul 27 09:35:47.728128 2026] [:error] [pid 21545:tid 140706844681984] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.vault"] [unique_id "amcKU5hXfYDIcpslIWOdqQAAAZY"]
[Mon Jul 27 09:35:47.728936 2026] [:error] [pid 21545:tid 140706844681984] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.vault"] [unique_id "amcKU5hXfYDIcpslIWOdqQAAAZY"]
[Mon Jul 27 09:35:47.729590 2026] [:error] [pid 21545:tid 140706844681984] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.vault"] [unique_id "amcKU5hXfYDIcpslIWOdqQAAAZY"]
[Mon Jul 27 09:35:47.729803 2026] [:error] [pid 21545:tid 140706844681984] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.vault"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.vault"] [unique_id "amcKU5hXfYDIcpslIWOdqQAAAZY"]
[Mon Jul 27 09:35:47.959919 2026] [:error] [pid 12276:tid 140706886645504] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amcKU-csEMuHmMYmk66WlAAAAFE"]
[Mon Jul 27 09:35:47.961195 2026] [:error] [pid 12276:tid 140706886645504] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amcKU-csEMuHmMYmk66WlAAAAFE"]
[Mon Jul 27 09:35:47.961754 2026] [:error] [pid 12276:tid 140706886645504] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amcKU-csEMuHmMYmk66WlAAAAFE"]
[Mon Jul 27 09:35:47.962063 2026] [:error] [pid 12276:tid 140706886645504] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amcKU-csEMuHmMYmk66WlAAAAFE"]
[Mon Jul 27 09:35:48.133376 2026] [:error] [pid 21545:tid 140706995750656] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.aws/config"] [unique_id "amcKVJhXfYDIcpslIWOdrAAAAYQ"]
[Mon Jul 27 09:35:48.134303 2026] [:error] [pid 21545:tid 140706995750656] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.aws/config"] [unique_id "amcKVJhXfYDIcpslIWOdrAAAAYQ"]
[Mon Jul 27 09:35:48.134840 2026] [:error] [pid 21545:tid 140706995750656] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.aws/config"] [unique_id "amcKVJhXfYDIcpslIWOdrAAAAYQ"]
[Mon Jul 27 09:35:48.135138 2026] [:error] [pid 21545:tid 140706995750656] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.aws/config"] [unique_id "amcKVJhXfYDIcpslIWOdrAAAAYQ"]
[Mon Jul 27 09:35:48.314154 2026] [:error] [pid 21545:tid 140706903430912] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amcKVJhXfYDIcpslIWOdrQAAAY8"]
[Mon Jul 27 09:35:48.315111 2026] [:error] [pid 21545:tid 140706903430912] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amcKVJhXfYDIcpslIWOdrQAAAY8"]
[Mon Jul 27 09:35:48.315678 2026] [:error] [pid 21545:tid 140706903430912] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amcKVJhXfYDIcpslIWOdrQAAAY8"]
[Mon Jul 27 09:35:48.315992 2026] [:error] [pid 21545:tid 140706903430912] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amcKVJhXfYDIcpslIWOdrQAAAY8"]
[Mon Jul 27 09:35:48.453430 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/storage/framework/.env"] [unique_id "amcKVJhXfYDIcpslIWOdrgAAAYs"]
[Mon Jul 27 09:35:48.454245 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/storage/framework/.env"] [unique_id "amcKVJhXfYDIcpslIWOdrgAAAYs"]
[Mon Jul 27 09:35:48.454816 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/storage/framework/.env"] [unique_id "amcKVJhXfYDIcpslIWOdrgAAAYs"]
[Mon Jul 27 09:35:48.455029 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/framework/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/storage/framework/.env"] [unique_id "amcKVJhXfYDIcpslIWOdrgAAAYs"]
[Mon Jul 27 09:35:48.631247 2026] [:error] [pid 21545:tid 140706911823616] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amcKVJhXfYDIcpslIWOdrwAAAY4"]
[Mon Jul 27 09:35:48.632486 2026] [:error] [pid 21545:tid 140706911823616] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amcKVJhXfYDIcpslIWOdrwAAAY4"]
[Mon Jul 27 09:35:48.633204 2026] [:error] [pid 21545:tid 140706911823616] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amcKVJhXfYDIcpslIWOdrwAAAY4"]
[Mon Jul 27 09:35:48.633516 2026] [:error] [pid 21545:tid 140706911823616] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amcKVJhXfYDIcpslIWOdrwAAAY4"]
[Mon Jul 27 09:35:48.821199 2026] [:error] [pid 12276:tid 140707012536064] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/debug/vars"] [unique_id "amcKVOcsEMuHmMYmk66WlwAAAEI"]
[Mon Jul 27 09:35:48.822082 2026] [:error] [pid 12276:tid 140707012536064] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/debug/vars"] [unique_id "amcKVOcsEMuHmMYmk66WlwAAAEI"]
[Mon Jul 27 09:35:48.822739 2026] [:error] [pid 12276:tid 140707012536064] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/debug/vars"] [unique_id "amcKVOcsEMuHmMYmk66WlwAAAEI"]
[Mon Jul 27 09:35:48.972959 2026] [:error] [pid 21545:tid 140707004143360] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.gcp/credentials.json"] [unique_id "amcKVJhXfYDIcpslIWOdsAAAAYM"]
[Mon Jul 27 09:35:48.973855 2026] [:error] [pid 21545:tid 140707004143360] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.gcp/credentials.json"] [unique_id "amcKVJhXfYDIcpslIWOdsAAAAYM"]
[Mon Jul 27 09:35:48.974378 2026] [:error] [pid 21545:tid 140707004143360] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.gcp/credentials.json"] [unique_id "amcKVJhXfYDIcpslIWOdsAAAAYM"]
[Mon Jul 27 09:35:49.118865 2026] [:error] [pid 12276:tid 140706937001728] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.gcp/service-account.json"] [unique_id "amcKVecsEMuHmMYmk66WmAAAAEs"]
[Mon Jul 27 09:35:49.119777 2026] [:error] [pid 12276:tid 140706937001728] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.gcp/service-account.json"] [unique_id "amcKVecsEMuHmMYmk66WmAAAAEs"]
[Mon Jul 27 09:35:49.120360 2026] [:error] [pid 12276:tid 140706937001728] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.gcp/service-account.json"] [unique_id "amcKVecsEMuHmMYmk66WmAAAAEs"]
[Mon Jul 27 09:35:49.272378 2026] [:error] [pid 21545:tid 140706861467392] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gcp-credentials.json"] [unique_id "amcKVZhXfYDIcpslIWOdsgAAAZQ"]
[Mon Jul 27 09:35:49.273060 2026] [:error] [pid 21545:tid 140706861467392] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gcp-credentials.json"] [unique_id "amcKVZhXfYDIcpslIWOdsgAAAZQ"]
[Mon Jul 27 09:35:49.273468 2026] [:error] [pid 21545:tid 140706861467392] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gcp-credentials.json"] [unique_id "amcKVZhXfYDIcpslIWOdsgAAAZQ"]
[Mon Jul 27 09:35:49.413914 2026] [:error] [pid 12276:tid 140706836289280] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gcp-service-account.json"] [unique_id "amcKVecsEMuHmMYmk66WmQAAAFc"]
[Mon Jul 27 09:35:49.414478 2026] [:error] [pid 12276:tid 140706836289280] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gcp-service-account.json"] [unique_id "amcKVecsEMuHmMYmk66WmQAAAFc"]
[Mon Jul 27 09:35:49.415095 2026] [:error] [pid 12276:tid 140706836289280] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gcp-service-account.json"] [unique_id "amcKVecsEMuHmMYmk66WmQAAAFc"]
[Mon Jul 27 09:35:49.557375 2026] [:error] [pid 21545:tid 140706970572544] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/service-account.json"] [unique_id "amcKVZhXfYDIcpslIWOdtAAAAYc"]
[Mon Jul 27 09:35:49.558118 2026] [:error] [pid 21545:tid 140706970572544] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/service-account.json"] [unique_id "amcKVZhXfYDIcpslIWOdtAAAAYc"]
[Mon Jul 27 09:35:49.558634 2026] [:error] [pid 21545:tid 140706970572544] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/service-account.json"] [unique_id "amcKVZhXfYDIcpslIWOdtAAAAYc"]
[Mon Jul 27 09:35:49.697573 2026] [:error] [pid 12276:tid 140706987357952] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/google-credentials.json"] [unique_id "amcKVecsEMuHmMYmk66WmgAAAEU"]
[Mon Jul 27 09:35:49.698444 2026] [:error] [pid 12276:tid 140706987357952] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/google-credentials.json"] [unique_id "amcKVecsEMuHmMYmk66WmgAAAEU"]
[Mon Jul 27 09:35:49.698996 2026] [:error] [pid 12276:tid 140706987357952] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/google-credentials.json"] [unique_id "amcKVecsEMuHmMYmk66WmgAAAEU"]
[Mon Jul 27 09:35:49.839753 2026] [:error] [pid 21545:tid 140706886645504] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/google-cloud-key.json"] [unique_id "amcKVZhXfYDIcpslIWOdtgAAAZE"]
[Mon Jul 27 09:35:49.840639 2026] [:error] [pid 21545:tid 140706886645504] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/google-cloud-key.json"] [unique_id "amcKVZhXfYDIcpslIWOdtgAAAZE"]
[Mon Jul 27 09:35:49.841055 2026] [:error] [pid 21545:tid 140706886645504] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/google-cloud-key.json"] [unique_id "amcKVZhXfYDIcpslIWOdtgAAAZE"]
[Mon Jul 27 09:35:49.980254 2026] [:error] [pid 12276:tid 140707020928768] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/firebase-adminsdk.json"] [unique_id "amcKVecsEMuHmMYmk66WnAAAAEE"]
[Mon Jul 27 09:35:49.981177 2026] [:error] [pid 12276:tid 140707020928768] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/firebase-adminsdk.json"] [unique_id "amcKVecsEMuHmMYmk66WnAAAAEE"]
[Mon Jul 27 09:35:49.981729 2026] [:error] [pid 12276:tid 140707020928768] [client 141.101.76.32:10102] [client 141.101.76.32] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/firebase-adminsdk.json"] [unique_id "amcKVecsEMuHmMYmk66WnAAAAEE"]
[Mon Jul 27 09:35:50.130958 2026] [:error] [pid 21545:tid 140706920216320] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/firebase-credentials.json"] [unique_id "amcKVphXfYDIcpslIWOdtwAAAY0"]
[Mon Jul 27 09:35:50.131808 2026] [:error] [pid 21545:tid 140706920216320] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/firebase-credentials.json"] [unique_id "amcKVphXfYDIcpslIWOdtwAAAY0"]
[Mon Jul 27 09:35:50.132302 2026] [:error] [pid 21545:tid 140706920216320] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/firebase-credentials.json"] [unique_id "amcKVphXfYDIcpslIWOdtwAAAY0"]
[Mon Jul 27 09:35:50.274434 2026] [:error] [pid 21545:tid 140706953787136] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/root/.config/gcloud/application_default_credentials.json"] [unique_id "amcKVphXfYDIcpslIWOduAAAAYk"]
[Mon Jul 27 09:35:50.275302 2026] [:error] [pid 21545:tid 140706953787136] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/root/.config/gcloud/application_default_credentials.json"] [unique_id "amcKVphXfYDIcpslIWOduAAAAYk"]
[Mon Jul 27 09:35:50.275824 2026] [:error] [pid 21545:tid 140706953787136] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/root/.config/gcloud/application_default_credentials.json"] [unique_id "amcKVphXfYDIcpslIWOduAAAAYk"]
[Mon Jul 27 09:35:50.445052 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/root/.config/gcloud/credentials.db"] [unique_id "amcKVphXfYDIcpslIWOduQAAAYA"]
[Mon Jul 27 09:35:50.445971 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/root/.config/gcloud/credentials.db"] [unique_id "amcKVphXfYDIcpslIWOduQAAAYA"]
[Mon Jul 27 09:35:50.446513 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.183.35:10773] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/root/.config/gcloud/credentials.db"] [unique_id "amcKVphXfYDIcpslIWOduQAAAYA"]
[Mon Jul 27 09:35:50.586829 2026] [:error] [pid 12276:tid 140707004143360] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.config/gcloud/application_default_credentials.json"] [unique_id "amcKVucsEMuHmMYmk66WngAAAEM"]
[Mon Jul 27 09:35:50.587717 2026] [:error] [pid 12276:tid 140707004143360] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.config/gcloud/application_default_credentials.json"] [unique_id "amcKVucsEMuHmMYmk66WngAAAEM"]
[Mon Jul 27 09:35:50.588196 2026] [:error] [pid 12276:tid 140707004143360] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.config/gcloud/application_default_credentials.json"] [unique_id "amcKVucsEMuHmMYmk66WngAAAEM"]
[Mon Jul 27 09:35:50.760601 2026] [:error] [pid 12276:tid 140706886645504] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/home/node/.config/gcloud/application_default_credentials.json"] [unique_id "amcKVucsEMuHmMYmk66WnwAAAFE"]
[Mon Jul 27 09:35:50.761318 2026] [:error] [pid 12276:tid 140706886645504] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/home/node/.config/gcloud/application_default_credentials.json"] [unique_id "amcKVucsEMuHmMYmk66WnwAAAFE"]
[Mon Jul 27 09:35:50.761752 2026] [:error] [pid 12276:tid 140706886645504] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/home/node/.config/gcloud/application_default_credentials.json"] [unique_id "amcKVucsEMuHmMYmk66WnwAAAFE"]
[Mon Jul 27 09:35:50.934639 2026] [:error] [pid 12276:tid 140707012536064] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/app/credentials.json"] [unique_id "amcKVucsEMuHmMYmk66WoAAAAEI"]
[Mon Jul 27 09:35:50.935490 2026] [:error] [pid 12276:tid 140707012536064] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/app/credentials.json"] [unique_id "amcKVucsEMuHmMYmk66WoAAAAEI"]
[Mon Jul 27 09:35:50.935998 2026] [:error] [pid 12276:tid 140707012536064] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app/credentials.json"] [unique_id "amcKVucsEMuHmMYmk66WoAAAAEI"]
[Mon Jul 27 09:35:51.116749 2026] [:error] [pid 12276:tid 140706962179840] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/app/service-account.json"] [unique_id "amcKV-csEMuHmMYmk66WoQAAAEg"]
[Mon Jul 27 09:35:51.117609 2026] [:error] [pid 12276:tid 140706962179840] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/app/service-account.json"] [unique_id "amcKV-csEMuHmMYmk66WoQAAAEg"]
[Mon Jul 27 09:35:51.118099 2026] [:error] [pid 12276:tid 140706962179840] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app/service-account.json"] [unique_id "amcKV-csEMuHmMYmk66WoQAAAEg"]
[Mon Jul 27 09:35:51.256387 2026] [:error] [pid 12276:tid 140706869860096] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/gcp.json"] [unique_id "amcKV-csEMuHmMYmk66WogAAAFM"]
[Mon Jul 27 09:35:51.257239 2026] [:error] [pid 12276:tid 140706869860096] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/gcp.json"] [unique_id "amcKV-csEMuHmMYmk66WogAAAFM"]
[Mon Jul 27 09:35:51.257750 2026] [:error] [pid 12276:tid 140706869860096] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/gcp.json"] [unique_id "amcKV-csEMuHmMYmk66WogAAAFM"]
[Mon Jul 27 09:35:51.427359 2026] [:error] [pid 12276:tid 140706928609024] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/root/.config/hcloud/cli.toml"] [unique_id "amcKV-csEMuHmMYmk66WpAAAAEw"]
[Mon Jul 27 09:35:51.427955 2026] [:error] [pid 12276:tid 140706928609024] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/root/.config/hcloud/cli.toml"] [unique_id "amcKV-csEMuHmMYmk66WpAAAAEw"]
[Mon Jul 27 09:35:51.428332 2026] [:error] [pid 12276:tid 140706928609024] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/root/.config/hcloud/cli.toml"] [unique_id "amcKV-csEMuHmMYmk66WpAAAAEw"]
[Mon Jul 27 09:35:51.561402 2026] [:error] [pid 12276:tid 140706987357952] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.config/hcloud/cli.toml"] [unique_id "amcKV-csEMuHmMYmk66WpgAAAEU"]
[Mon Jul 27 09:35:51.562084 2026] [:error] [pid 12276:tid 140706987357952] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.config/hcloud/cli.toml"] [unique_id "amcKV-csEMuHmMYmk66WpgAAAEU"]
[Mon Jul 27 09:35:51.562458 2026] [:error] [pid 12276:tid 140706987357952] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.config/hcloud/cli.toml"] [unique_id "amcKV-csEMuHmMYmk66WpgAAAEU"]
[Mon Jul 27 09:35:51.731521 2026] [:error] [pid 12276:tid 140707020928768] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.hcloud.toml"] [unique_id "amcKV-csEMuHmMYmk66WpwAAAEE"]
[Mon Jul 27 09:35:51.732391 2026] [:error] [pid 12276:tid 140707020928768] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.hcloud.toml"] [unique_id "amcKV-csEMuHmMYmk66WpwAAAEE"]
[Mon Jul 27 09:35:51.732901 2026] [:error] [pid 12276:tid 140707020928768] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.hcloud.toml"] [unique_id "amcKV-csEMuHmMYmk66WpwAAAEE"]
[Mon Jul 27 09:35:51.872049 2026] [:error] [pid 12276:tid 140706853074688] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/hcloud.yml"] [unique_id "amcKV-csEMuHmMYmk66WqQAAAFU"]
[Mon Jul 27 09:35:51.872661 2026] [:error] [pid 12276:tid 140706853074688] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/hcloud.yml"] [unique_id "amcKV-csEMuHmMYmk66WqQAAAFU"]
[Mon Jul 27 09:35:51.873008 2026] [:error] [pid 12276:tid 140706853074688] [client 104.23.166.83:9409] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/hcloud.yml"] [unique_id "amcKV-csEMuHmMYmk66WqQAAAFU"]
[Mon Jul 27 09:35:53.027599 2026] [:error] [pid 21545:tid 140706903430912] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/root/.config/linode-cli"] [unique_id "amcKWZhXfYDIcpslIWOdwAAAAY8"]
[Mon Jul 27 09:35:53.028246 2026] [:error] [pid 21545:tid 140706903430912] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/root/.config/linode-cli"] [unique_id "amcKWZhXfYDIcpslIWOdwAAAAY8"]
[Mon Jul 27 09:35:53.028705 2026] [:error] [pid 21545:tid 140706903430912] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/root/.config/linode-cli"] [unique_id "amcKWZhXfYDIcpslIWOdwAAAAY8"]
[Mon Jul 27 09:35:53.175111 2026] [:error] [pid 21545:tid 140706911823616] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.config/linode-cli"] [unique_id "amcKWZhXfYDIcpslIWOdwQAAAY4"]
[Mon Jul 27 09:35:53.175804 2026] [:error] [pid 21545:tid 140706911823616] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.config/linode-cli"] [unique_id "amcKWZhXfYDIcpslIWOdwQAAAY4"]
[Mon Jul 27 09:35:53.176201 2026] [:error] [pid 21545:tid 140706911823616] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.config/linode-cli"] [unique_id "amcKWZhXfYDIcpslIWOdwQAAAY4"]
[Mon Jul 27 09:35:53.322241 2026] [:error] [pid 21545:tid 140706861467392] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.linode-cli"] [unique_id "amcKWZhXfYDIcpslIWOdwwAAAZQ"]
[Mon Jul 27 09:35:53.322912 2026] [:error] [pid 21545:tid 140706861467392] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.linode-cli"] [unique_id "amcKWZhXfYDIcpslIWOdwwAAAZQ"]
[Mon Jul 27 09:35:53.323283 2026] [:error] [pid 21545:tid 140706861467392] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.linode-cli"] [unique_id "amcKWZhXfYDIcpslIWOdwwAAAZQ"]
[Mon Jul 27 09:35:53.469079 2026] [:error] [pid 21545:tid 140706970572544] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/root/.vultr-cli.yaml"] [unique_id "amcKWZhXfYDIcpslIWOdxQAAAYc"]
[Mon Jul 27 09:35:53.470170 2026] [:error] [pid 21545:tid 140706970572544] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/root/.vultr-cli.yaml"] [unique_id "amcKWZhXfYDIcpslIWOdxQAAAYc"]
[Mon Jul 27 09:35:53.470843 2026] [:error] [pid 21545:tid 140706970572544] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/root/.vultr-cli.yaml"] [unique_id "amcKWZhXfYDIcpslIWOdxQAAAYc"]
[Mon Jul 27 09:35:53.603875 2026] [:error] [pid 21545:tid 140706869860096] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.vultr-cli.yaml"] [unique_id "amcKWZhXfYDIcpslIWOdxgAAAZM"]
[Mon Jul 27 09:35:53.605204 2026] [:error] [pid 21545:tid 140706869860096] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.vultr-cli.yaml"] [unique_id "amcKWZhXfYDIcpslIWOdxgAAAZM"]
[Mon Jul 27 09:35:53.605857 2026] [:error] [pid 21545:tid 140706869860096] [client 172.71.103.42:11975] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/home/ubuntu/.vultr-cli.yaml"] [unique_id "amcKWZhXfYDIcpslIWOdxgAAAZM"]
[Mon Jul 27 09:35:53.970403 2026] [:error] [pid 12275:tid 140706853074688] [client 172.71.95.21:12920] [client 172.71.95.21] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.vultr-cli.yaml"] [unique_id "amcKWXFwI8r7BFXGkAuFFQAAABU"]
[Mon Jul 27 09:35:53.971250 2026] [:error] [pid 12275:tid 140706853074688] [client 172.71.95.21:12920] [client 172.71.95.21] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.vultr-cli.yaml"] [unique_id "amcKWXFwI8r7BFXGkAuFFQAAABU"]
[Mon Jul 27 09:35:53.971724 2026] [:error] [pid 12275:tid 140706853074688] [client 172.71.95.21:12920] [client 172.71.95.21] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.vultr-cli.yaml"] [unique_id "amcKWXFwI8r7BFXGkAuFFQAAABU"]
[Mon Jul 27 09:36:13.612979 2026] [:error] [pid 12380:tid 140707012536064] [client 104.23.253.26:10021] [client 104.23.253.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKbaaChfbWW0CZ_hrdAwAAAMI"]
[Mon Jul 27 09:36:13.613935 2026] [:error] [pid 12380:tid 140707012536064] [client 104.23.253.26:10021] [client 104.23.253.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKbaaChfbWW0CZ_hrdAwAAAMI"]
[Mon Jul 27 09:36:13.614725 2026] [:error] [pid 12380:tid 140707012536064] [client 104.23.253.26:10021] [client 104.23.253.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKbaaChfbWW0CZ_hrdAwAAAMI"]
[Mon Jul 27 09:36:14.082134 2026] [:error] [pid 12276:tid 140706836289280] [client 104.22.17.232:12433] [client 104.22.17.232] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKbucsEMuHmMYmk66W_gAAAFc"]
[Mon Jul 27 09:36:14.082771 2026] [:error] [pid 12276:tid 140706836289280] [client 104.22.17.232:12433] [client 104.22.17.232] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKbucsEMuHmMYmk66W_gAAAFc"]
[Mon Jul 27 09:36:14.083220 2026] [:error] [pid 12276:tid 140706836289280] [client 104.22.17.232:12433] [client 104.22.17.232] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKbucsEMuHmMYmk66W_gAAAFc"]
[Mon Jul 27 09:36:31.350118 2026] [:error] [pid 12276:tid 140707103270656] [client 172.70.123.118:9997] [client 172.70.123.118] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKf-csEMuHmMYmk66XYAAAAEA"]
[Mon Jul 27 09:36:31.350900 2026] [:error] [pid 12276:tid 140707103270656] [client 172.70.123.118:9997] [client 172.70.123.118] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKf-csEMuHmMYmk66XYAAAAEA"]
[Mon Jul 27 09:36:31.351241 2026] [:error] [pid 12276:tid 140707103270656] [client 172.70.123.118:9997] [client 172.70.123.118] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKf-csEMuHmMYmk66XYAAAAEA"]
[Mon Jul 27 09:36:31.351306 2026] [:error] [pid 12276:tid 140707103270656] [client 172.70.123.118:9997] [client 172.70.123.118] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKf-csEMuHmMYmk66XYAAAAEA"]
[Mon Jul 27 09:36:40.905630 2026] [:error] [pid 12380:tid 140706861467392] [client 172.71.203.17:12653] [client 172.71.203.17] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKiKaChfbWW0CZ_hrdBwAAANQ"]
[Mon Jul 27 09:36:40.906357 2026] [:error] [pid 12380:tid 140706861467392] [client 172.71.203.17:12653] [client 172.71.203.17] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKiKaChfbWW0CZ_hrdBwAAANQ"]
[Mon Jul 27 09:36:40.906867 2026] [:error] [pid 12380:tid 140706861467392] [client 172.71.203.17:12653] [client 172.71.203.17] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua=Google Chrome\\x22;v=\\x22111\\x22, \\x22Not(A:Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22111"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKiKaChfbWW0CZ_hrdBwAAANQ"]
[Mon Jul 27 09:36:40.906925 2026] [:error] [pid 12380:tid 140706861467392] [client 172.71.203.17:12653] [client 172.71.203.17] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKiKaChfbWW0CZ_hrdBwAAANQ"]
[Mon Jul 27 09:36:40.907723 2026] [:error] [pid 12275:tid 140706895038208] [client 162.158.63.138:14073] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKiHFwI8r7BFXGkAuFIQAAABA"]
[Mon Jul 27 09:36:40.908210 2026] [:error] [pid 12275:tid 140706895038208] [client 162.158.63.138:14073] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKiHFwI8r7BFXGkAuFIQAAABA"]
[Mon Jul 27 09:36:40.908618 2026] [:error] [pid 12275:tid 140706895038208] [client 162.158.63.138:14073] [client 162.158.63.138] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua=Google Chrome\\x22;v=\\x22111\\x22, \\x22Not(A:Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22111"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKiHFwI8r7BFXGkAuFIQAAABA"]
[Mon Jul 27 09:36:40.908675 2026] [:error] [pid 12275:tid 140706895038208] [client 162.158.63.138:14073] [client 162.158.63.138] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKiHFwI8r7BFXGkAuFIQAAABA"]
[Mon Jul 27 09:36:48.020080 2026] [:error] [pid 12276:tid 140706886645504] [client 172.70.123.117:10838] [client 172.70.123.117] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKkOcsEMuHmMYmk66XkQAAAFE"], referer: https://sbf-consultancy.com/
[Mon Jul 27 09:36:48.020773 2026] [:error] [pid 12276:tid 140706886645504] [client 172.70.123.117:10838] [client 172.70.123.117] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKkOcsEMuHmMYmk66XkQAAAFE"], referer: https://sbf-consultancy.com/
[Mon Jul 27 09:36:48.021262 2026] [:error] [pid 12276:tid 140706886645504] [client 172.70.123.117:10838] [client 172.70.123.117] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKkOcsEMuHmMYmk66XkQAAAFE"], referer: https://sbf-consultancy.com/
[Mon Jul 27 09:36:58.708856 2026] [:error] [pid 21545:tid 140707012536064] [client 104.23.190.102:12275] [client 104.23.190.102] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKmphXfYDIcpslIWOelAAAAYI"]
[Mon Jul 27 09:36:58.709811 2026] [:error] [pid 21545:tid 140707012536064] [client 104.23.190.102:12275] [client 104.23.190.102] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKmphXfYDIcpslIWOelAAAAYI"]
[Mon Jul 27 09:36:58.710460 2026] [:error] [pid 21545:tid 140707012536064] [client 104.23.190.102:12275] [client 104.23.190.102] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua=Google Chrome\\x22;v=\\x22111\\x22, \\x22Not(A:Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22111"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKmphXfYDIcpslIWOelAAAAYI"]
[Mon Jul 27 09:36:58.710540 2026] [:error] [pid 21545:tid 140707012536064] [client 104.23.190.102:12275] [client 104.23.190.102] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKmphXfYDIcpslIWOelAAAAYI"]
[Mon Jul 27 09:37:02.101082 2026] [:error] [pid 12276:tid 140706945394432] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKnucsEMuHmMYmk66XvQAAAEo"]
[Mon Jul 27 09:37:02.101836 2026] [:error] [pid 12276:tid 140706945394432] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKnucsEMuHmMYmk66XvQAAAEo"]
[Mon Jul 27 09:37:02.102244 2026] [:error] [pid 12276:tid 140706945394432] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcKnucsEMuHmMYmk66XvQAAAEo"]
[Mon Jul 27 09:37:02.296115 2026] [:error] [pid 21545:tid 140706861467392] [client 172.71.99.99:11346] [client 172.71.99.99] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/assets/js/telegram_redirect.js"] [unique_id "amcKnphXfYDIcpslIWOengAAAZQ"]
[Mon Jul 27 09:37:02.296782 2026] [:error] [pid 21545:tid 140706861467392] [client 172.71.99.99:11346] [client 172.71.99.99] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/assets/js/telegram_redirect.js"] [unique_id "amcKnphXfYDIcpslIWOengAAAZQ"]
[Mon Jul 27 09:37:02.297161 2026] [:error] [pid 21545:tid 140706861467392] [client 172.71.99.99:11346] [client 172.71.99.99] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/assets/js/telegram_redirect.js"] [unique_id "amcKnphXfYDIcpslIWOengAAAZQ"]
[Mon Jul 27 09:37:02.364206 2026] [:error] [pid 12276:tid 140706853074688] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/setup/"] [unique_id "amcKnucsEMuHmMYmk66XwAAAAFU"]
[Mon Jul 27 09:37:02.365033 2026] [:error] [pid 12276:tid 140706853074688] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/setup/"] [unique_id "amcKnucsEMuHmMYmk66XwAAAAFU"]
[Mon Jul 27 09:37:02.365585 2026] [:error] [pid 12276:tid 140706853074688] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/setup/"] [unique_id "amcKnucsEMuHmMYmk66XwAAAAFU"]
[Mon Jul 27 09:37:02.409493 2026] [:error] [pid 12276:tid 140707004143360] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_internal/api/setup.php"] [unique_id "amcKnucsEMuHmMYmk66XwgAAAEM"]
[Mon Jul 27 09:37:02.410217 2026] [:error] [pid 12276:tid 140707004143360] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_internal/api/setup.php"] [unique_id "amcKnucsEMuHmMYmk66XwgAAAEM"]
[Mon Jul 27 09:37:02.410498 2026] [:error] [pid 12276:tid 140707004143360] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_internal/api/setup.php"] [unique_id "amcKnucsEMuHmMYmk66XwgAAAEM"]
[Mon Jul 27 09:37:02.410855 2026] [:error] [pid 12276:tid 140707004143360] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_internal/api/setup.php"] [unique_id "amcKnucsEMuHmMYmk66XwgAAAEM"]
[Mon Jul 27 09:37:02.445388 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_internal/api/setup.php"] [unique_id "amcKnucsEMuHmMYmk66XwwAAAFM"]
[Mon Jul 27 09:37:02.446253 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_internal/api/setup.php"] [unique_id "amcKnucsEMuHmMYmk66XwwAAAFM"]
[Mon Jul 27 09:37:02.446540 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_internal/api/setup.php"] [unique_id "amcKnucsEMuHmMYmk66XwwAAAFM"]
[Mon Jul 27 09:37:02.446846 2026] [:error] [pid 12276:tid 140706869860096] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_internal/api/setup.php"] [unique_id "amcKnucsEMuHmMYmk66XwwAAAFM"]
[Mon Jul 27 09:37:02.481827 2026] [:error] [pid 12276:tid 140706903430912] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/user/"] [unique_id "amcKnucsEMuHmMYmk66XxAAAAE8"]
[Mon Jul 27 09:37:02.482437 2026] [:error] [pid 12276:tid 140706903430912] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/user/"] [unique_id "amcKnucsEMuHmMYmk66XxAAAAE8"]
[Mon Jul 27 09:37:02.482798 2026] [:error] [pid 12276:tid 140706903430912] [client 172.71.103.42:10448] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/user/"] [unique_id "amcKnucsEMuHmMYmk66XxAAAAE8"]
[Mon Jul 27 09:39:17.398489 2026] [:error] [pid 12276:tid 140706827896576] [client 172.71.126.166:13217] [client 172.71.126.166] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJecsEMuHmMYmk66Z-gAAAFg"]
[Mon Jul 27 09:39:17.399352 2026] [:error] [pid 12276:tid 140706827896576] [client 172.71.126.166:13217] [client 172.71.126.166] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJecsEMuHmMYmk66Z-gAAAFg"]
[Mon Jul 27 09:39:17.399724 2026] [:error] [pid 12276:tid 140706827896576] [client 172.71.126.166:13217] [client 172.71.126.166] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJecsEMuHmMYmk66Z-gAAAFg"]
[Mon Jul 27 09:39:17.417485 2026] [:error] [pid 21545:tid 140706962179840] [client 104.23.225.35:9949] [client 104.23.225.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJZhXfYDIcpslIWOgSgAAAYg"]
[Mon Jul 27 09:39:17.418388 2026] [:error] [pid 21545:tid 140706962179840] [client 104.23.225.35:9949] [client 104.23.225.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJZhXfYDIcpslIWOgSgAAAYg"]
[Mon Jul 27 09:39:17.418920 2026] [:error] [pid 21545:tid 140706962179840] [client 104.23.225.35:9949] [client 104.23.225.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJZhXfYDIcpslIWOgSgAAAYg"]
[Mon Jul 27 09:39:18.059005 2026] [:error] [pid 12276:tid 140706895038208] [client 141.101.98.192:11269] [client 141.101.98.192] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJucsEMuHmMYmk66aAAAAAFA"]
[Mon Jul 27 09:39:18.059818 2026] [:error] [pid 12276:tid 140706895038208] [client 141.101.98.192:11269] [client 141.101.98.192] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJucsEMuHmMYmk66aAAAAAFA"]
[Mon Jul 27 09:39:18.060398 2026] [:error] [pid 12276:tid 140706895038208] [client 141.101.98.192:11269] [client 141.101.98.192] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJucsEMuHmMYmk66aAAAAAFA"]
[Mon Jul 27 09:39:18.129476 2026] [:error] [pid 21545:tid 140707012536064] [client 172.71.241.17:13886] [client 172.71.241.17] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcLJphXfYDIcpslIWOgTAAAAYI"], referer: http://sbf-consultancy.com/
[Mon Jul 27 09:39:18.130427 2026] [:error] [pid 21545:tid 140707012536064] [client 172.71.241.17:13886] [client 172.71.241.17] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcLJphXfYDIcpslIWOgTAAAAYI"], referer: http://sbf-consultancy.com/
[Mon Jul 27 09:39:18.131054 2026] [:error] [pid 21545:tid 140707012536064] [client 172.71.241.17:13886] [client 172.71.241.17] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcLJphXfYDIcpslIWOgTAAAAYI"], referer: http://sbf-consultancy.com/
[Mon Jul 27 09:39:18.264893 2026] [:error] [pid 12275:tid 140706920216320] [client 172.68.229.18:14160] [client 172.68.229.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJnFwI8r7BFXGkAuFZgAAAA0"]
[Mon Jul 27 09:39:18.265538 2026] [:error] [pid 12275:tid 140706920216320] [client 172.68.229.18:14160] [client 172.68.229.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJnFwI8r7BFXGkAuFZgAAAA0"]
[Mon Jul 27 09:39:18.266083 2026] [:error] [pid 12275:tid 140706920216320] [client 172.68.229.18:14160] [client 172.68.229.18] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJnFwI8r7BFXGkAuFZgAAAA0"]
[Mon Jul 27 09:39:18.266135 2026] [:error] [pid 12275:tid 140706920216320] [client 172.68.229.18:14160] [client 172.68.229.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJnFwI8r7BFXGkAuFZgAAAA0"]
[Mon Jul 27 09:39:18.506084 2026] [:error] [pid 21545:tid 140706911823616] [client 172.71.241.16:12389] [client 172.71.241.16] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcLJphXfYDIcpslIWOgTgAAAY4"], referer: https://sbf-consultancy.com/
[Mon Jul 27 09:39:18.506752 2026] [:error] [pid 21545:tid 140706911823616] [client 172.71.241.16:12389] [client 172.71.241.16] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcLJphXfYDIcpslIWOgTgAAAY4"], referer: https://sbf-consultancy.com/
[Mon Jul 27 09:39:18.507491 2026] [:error] [pid 21545:tid 140706911823616] [client 172.71.241.16:12389] [client 172.71.241.16] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcLJphXfYDIcpslIWOgTgAAAY4"], referer: https://sbf-consultancy.com/
[Mon Jul 27 09:39:18.507591 2026] [:error] [pid 21545:tid 140706911823616] [client 172.71.241.16:12389] [client 172.71.241.16] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcLJphXfYDIcpslIWOgTgAAAY4"], referer: https://sbf-consultancy.com/
[Mon Jul 27 09:39:19.513017 2026] [:error] [pid 21545:tid 140706827896576] [client 172.70.86.152:9261] [client 172.70.86.152] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJ5hXfYDIcpslIWOgUAAAAZg"]
[Mon Jul 27 09:39:19.513683 2026] [:error] [pid 21545:tid 140706827896576] [client 172.70.86.152:9261] [client 172.70.86.152] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJ5hXfYDIcpslIWOgUAAAAZg"]
[Mon Jul 27 09:39:19.514083 2026] [:error] [pid 21545:tid 140706827896576] [client 172.70.86.152:9261] [client 172.70.86.152] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJ5hXfYDIcpslIWOgUAAAAZg"]
[Mon Jul 27 09:39:19.665391 2026] [:error] [pid 12275:tid 140707012536064] [client 172.71.178.43:11015] [client 172.71.178.43] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJ3FwI8r7BFXGkAuFZwAAAAI"]
[Mon Jul 27 09:39:19.666370 2026] [:error] [pid 12275:tid 140707012536064] [client 172.71.178.43:11015] [client 172.71.178.43] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJ3FwI8r7BFXGkAuFZwAAAAI"]
[Mon Jul 27 09:39:19.667292 2026] [:error] [pid 12275:tid 140707012536064] [client 172.71.178.43:11015] [client 172.71.178.43] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJ3FwI8r7BFXGkAuFZwAAAAI"]
[Mon Jul 27 09:39:19.667364 2026] [:error] [pid 12275:tid 140707012536064] [client 172.71.178.43:11015] [client 172.71.178.43] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLJ3FwI8r7BFXGkAuFZwAAAAI"]
[Mon Jul 27 09:40:10.853505 2026] [:error] [pid 21545:tid 140706827896576] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLWphXfYDIcpslIWOhTgAAAZg"]
[Mon Jul 27 09:40:10.854510 2026] [:error] [pid 21545:tid 140706827896576] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLWphXfYDIcpslIWOhTgAAAZg"]
[Mon Jul 27 09:40:10.854928 2026] [:error] [pid 21545:tid 140706827896576] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLWphXfYDIcpslIWOhTgAAAZg"]
[Mon Jul 27 09:40:10.855057 2026] [:error] [pid 21545:tid 140706827896576] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLWphXfYDIcpslIWOhTgAAAZg"]
[Mon Jul 27 09:40:10.865374 2026] [:error] [pid 12275:tid 140706903430912] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLWnFwI8r7BFXGkAuF7QAAAA8"]
[Mon Jul 27 09:40:10.866346 2026] [:error] [pid 12275:tid 140706903430912] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLWnFwI8r7BFXGkAuF7QAAAA8"]
[Mon Jul 27 09:40:10.866802 2026] [:error] [pid 12275:tid 140706903430912] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLWnFwI8r7BFXGkAuF7QAAAA8"]
[Mon Jul 27 09:40:10.866927 2026] [:error] [pid 12275:tid 140706903430912] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLWnFwI8r7BFXGkAuF7QAAAA8"]
[Mon Jul 27 09:40:10.867069 2026] [:error] [pid 12276:tid 140706844681984] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLWucsEMuHmMYmk66a0AAAAFY"]
[Mon Jul 27 09:40:10.867668 2026] [:error] [pid 12276:tid 140706844681984] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLWucsEMuHmMYmk66a0AAAAFY"]
[Mon Jul 27 09:40:10.868002 2026] [:error] [pid 12276:tid 140706844681984] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLWucsEMuHmMYmk66a0AAAAFY"]
[Mon Jul 27 09:40:10.868078 2026] [:error] [pid 12276:tid 140706844681984] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLWucsEMuHmMYmk66a0AAAAFY"]
[Mon Jul 27 09:40:10.948362 2026] [:error] [pid 21545:tid 140706953787136] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcLWphXfYDIcpslIWOhTwAAAYk"]
[Mon Jul 27 09:40:10.948736 2026] [:error] [pid 12275:tid 140706995750656] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/storage/logs/laravel.log"] [unique_id "amcLWnFwI8r7BFXGkAuF7gAAAAQ"]
[Mon Jul 27 09:40:10.949191 2026] [:error] [pid 12275:tid 140706995750656] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/storage/logs/laravel.log"] [unique_id "amcLWnFwI8r7BFXGkAuF7gAAAAQ"]
[Mon Jul 27 09:40:10.949213 2026] [:error] [pid 21545:tid 140706953787136] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcLWphXfYDIcpslIWOhTwAAAYk"]
[Mon Jul 27 09:40:10.949610 2026] [:error] [pid 12275:tid 140706995750656] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/storage/logs/laravel.log"] [unique_id "amcLWnFwI8r7BFXGkAuF7gAAAAQ"]
[Mon Jul 27 09:40:10.949654 2026] [:error] [pid 21545:tid 140706953787136] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcLWphXfYDIcpslIWOhTwAAAYk"]
[Mon Jul 27 09:40:10.949652 2026] [:error] [pid 12276:tid 140706836289280] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/user_secrets.yml"] [unique_id "amcLWucsEMuHmMYmk66a0QAAAFc"]
[Mon Jul 27 09:40:10.949707 2026] [:error] [pid 12275:tid 140706995750656] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/storage/logs/laravel.log"] [unique_id "amcLWnFwI8r7BFXGkAuF7gAAAAQ"]
[Mon Jul 27 09:40:10.949745 2026] [:error] [pid 21545:tid 140706953787136] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcLWphXfYDIcpslIWOhTwAAAYk"]
[Mon Jul 27 09:40:10.949947 2026] [:error] [pid 21545:tid 140706953787136] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcLWphXfYDIcpslIWOhTwAAAYk"]
[Mon Jul 27 09:40:10.950144 2026] [:error] [pid 12276:tid 140706836289280] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/user_secrets.yml"] [unique_id "amcLWucsEMuHmMYmk66a0QAAAFc"]
[Mon Jul 27 09:40:10.950395 2026] [:error] [pid 12276:tid 140706836289280] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/user_secrets.yml"] [unique_id "amcLWucsEMuHmMYmk66a0QAAAFc"]
[Mon Jul 27 09:40:10.950451 2026] [:error] [pid 12276:tid 140706836289280] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/user_secrets.yml"] [unique_id "amcLWucsEMuHmMYmk66a0QAAAFc"]
[Mon Jul 27 09:40:10.979982 2026] [:error] [pid 21545:tid 140707103270656] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/database_backup.sql"] [unique_id "amcLWphXfYDIcpslIWOhUAAAAYA"]
[Mon Jul 27 09:40:10.980805 2026] [:error] [pid 21545:tid 140707103270656] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/database_backup.sql"] [unique_id "amcLWphXfYDIcpslIWOhUAAAAYA"]
[Mon Jul 27 09:40:10.981175 2026] [:error] [pid 21545:tid 140707103270656] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/database_backup.sql"] [unique_id "amcLWphXfYDIcpslIWOhUAAAAYA"]
[Mon Jul 27 09:40:10.981283 2026] [:error] [pid 21545:tid 140707103270656] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/database_backup.sql"] [unique_id "amcLWphXfYDIcpslIWOhUAAAAYA"]
[Mon Jul 27 09:40:10.986223 2026] [:error] [pid 12275:tid 140706978965248] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dump.sql"] [unique_id "amcLWnFwI8r7BFXGkAuF8AAAAAY"]
[Mon Jul 27 09:40:10.986958 2026] [:error] [pid 12275:tid 140706978965248] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dump.sql"] [unique_id "amcLWnFwI8r7BFXGkAuF8AAAAAY"]
[Mon Jul 27 09:40:10.987108 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.xml"] [unique_id "amcLWucsEMuHmMYmk66a0gAAAEg"]
[Mon Jul 27 09:40:10.987321 2026] [:error] [pid 12275:tid 140706978965248] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/dump.sql"] [unique_id "amcLWnFwI8r7BFXGkAuF8AAAAAY"]
[Mon Jul 27 09:40:10.987391 2026] [:error] [pid 12275:tid 140706978965248] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dump.sql"] [unique_id "amcLWnFwI8r7BFXGkAuF8AAAAAY"]
[Mon Jul 27 09:40:10.987573 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.xml"] [unique_id "amcLWucsEMuHmMYmk66a0gAAAEg"]
[Mon Jul 27 09:40:10.987784 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/config.xml"] [unique_id "amcLWucsEMuHmMYmk66a0gAAAEg"]
[Mon Jul 27 09:40:10.987840 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.xml"] [unique_id "amcLWucsEMuHmMYmk66a0gAAAEg"]
[Mon Jul 27 09:40:10.997039 2026] [:error] [pid 12275:tid 140706878252800] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.ssh/id_ecdsa"] [unique_id "amcLWnFwI8r7BFXGkAuF8QAAABI"]
[Mon Jul 27 09:40:10.997794 2026] [:error] [pid 12275:tid 140706878252800] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.ssh/id_ecdsa"] [unique_id "amcLWnFwI8r7BFXGkAuF8QAAABI"]
[Mon Jul 27 09:40:10.998160 2026] [:error] [pid 12275:tid 140706878252800] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.ssh/id_ecdsa"] [unique_id "amcLWnFwI8r7BFXGkAuF8QAAABI"]
[Mon Jul 27 09:40:10.998276 2026] [:error] [pid 12275:tid 140706878252800] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.ssh/id_ecdsa"] [unique_id "amcLWnFwI8r7BFXGkAuF8QAAABI"]
[Mon Jul 27 09:40:11.011266 2026] [:error] [pid 21545:tid 140706937001728] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.php"] [unique_id "amcLW5hXfYDIcpslIWOhUQAAAYs"]
[Mon Jul 27 09:40:11.012118 2026] [:error] [pid 21545:tid 140706937001728] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.php"] [unique_id "amcLW5hXfYDIcpslIWOhUQAAAYs"]
[Mon Jul 27 09:40:11.012485 2026] [:error] [pid 21545:tid 140706937001728] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/config.php"] [unique_id "amcLW5hXfYDIcpslIWOhUQAAAYs"]
[Mon Jul 27 09:40:11.012586 2026] [:error] [pid 21545:tid 140706937001728] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.php"] [unique_id "amcLW5hXfYDIcpslIWOhUQAAAYs"]
[Mon Jul 27 09:40:11.021538 2026] [:error] [pid 12275:tid 140706836289280] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amcLW3FwI8r7BFXGkAuF8gAAABc"]
[Mon Jul 27 09:40:11.022388 2026] [:error] [pid 12275:tid 140706836289280] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amcLW3FwI8r7BFXGkAuF8gAAABc"]
[Mon Jul 27 09:40:11.022724 2026] [:error] [pid 12275:tid 140706836289280] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amcLW3FwI8r7BFXGkAuF8gAAABc"]
[Mon Jul 27 09:40:11.022816 2026] [:error] [pid 12275:tid 140706836289280] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amcLW3FwI8r7BFXGkAuF8gAAABc"]
[Mon Jul 27 09:40:11.022983 2026] [:error] [pid 12275:tid 140706836289280] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amcLW3FwI8r7BFXGkAuF8gAAABc"]
[Mon Jul 27 09:40:11.023239 2026] [:error] [pid 12276:tid 140706945394432] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.ssh/id_rsa"] [unique_id "amcLW-csEMuHmMYmk66a0wAAAEo"]
[Mon Jul 27 09:40:11.024006 2026] [:error] [pid 12276:tid 140706945394432] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.ssh/id_rsa"] [unique_id "amcLW-csEMuHmMYmk66a0wAAAEo"]
[Mon Jul 27 09:40:11.024299 2026] [:error] [pid 12276:tid 140706945394432] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.ssh/id_rsa"] [unique_id "amcLW-csEMuHmMYmk66a0wAAAEo"]
[Mon Jul 27 09:40:11.024399 2026] [:error] [pid 12276:tid 140706945394432] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.ssh/id_rsa"] [unique_id "amcLW-csEMuHmMYmk66a0wAAAEo"]
[Mon Jul 27 09:40:11.024595 2026] [:error] [pid 12276:tid 140706945394432] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Matched phrase ".ssh/id_rsa" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/id_rsa found within REQUEST_FILENAME: /.ssh/id_rsa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.ssh/id_rsa"] [unique_id "amcLW-csEMuHmMYmk66a0wAAAEo"]
[Mon Jul 27 09:40:11.029673 2026] [:error] [pid 12275:tid 140706853074688] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "amcLW3FwI8r7BFXGkAuF9AAAABU"]
[Mon Jul 27 09:40:11.030442 2026] [:error] [pid 12275:tid 140706853074688] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "amcLW3FwI8r7BFXGkAuF9AAAABU"]
[Mon Jul 27 09:40:11.030976 2026] [:error] [pid 12275:tid 140706853074688] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "amcLW3FwI8r7BFXGkAuF9AAAABU"]
[Mon Jul 27 09:40:11.031087 2026] [:error] [pid 12275:tid 140706853074688] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "amcLW3FwI8r7BFXGkAuF9AAAABU"]
[Mon Jul 27 09:40:11.044152 2026] [:error] [pid 21545:tid 140706836289280] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/setup-config.php"] [unique_id "amcLW5hXfYDIcpslIWOhUgAAAZc"]
[Mon Jul 27 09:40:11.044742 2026] [:error] [pid 21545:tid 140706836289280] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/setup-config.php"] [unique_id "amcLW5hXfYDIcpslIWOhUgAAAZc"]
[Mon Jul 27 09:40:11.045036 2026] [:error] [pid 21545:tid 140706836289280] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/setup-config.php"] [unique_id "amcLW5hXfYDIcpslIWOhUgAAAZc"]
[Mon Jul 27 09:40:11.045117 2026] [:error] [pid 21545:tid 140706836289280] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/setup-config.php"] [unique_id "amcLW5hXfYDIcpslIWOhUgAAAZc"]
[Mon Jul 27 09:40:11.059599 2026] [:error] [pid 12276:tid 140706853074688] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/etc/ssl/private/server.key"] [unique_id "amcLW-csEMuHmMYmk66a1AAAAFU"]
[Mon Jul 27 09:40:11.060415 2026] [:error] [pid 12276:tid 140706853074688] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/etc/ssl/private/server.key"] [unique_id "amcLW-csEMuHmMYmk66a1AAAAFU"]
[Mon Jul 27 09:40:11.060795 2026] [:error] [pid 12276:tid 140706853074688] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/etc/ssl/private/server.key"] [unique_id "amcLW-csEMuHmMYmk66a1AAAAFU"]
[Mon Jul 27 09:40:11.060882 2026] [:error] [pid 12276:tid 140706853074688] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/etc/ssl/private/server.key"] [unique_id "amcLW-csEMuHmMYmk66a1AAAAFU"]
[Mon Jul 27 09:40:11.067108 2026] [:error] [pid 12275:tid 140706987357952] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcLW3FwI8r7BFXGkAuF9wAAAAU"]
[Mon Jul 27 09:40:11.067099 2026] [:error] [pid 12275:tid 140706970572544] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server.key"] [unique_id "amcLW3FwI8r7BFXGkAuF9gAAAAc"]
[Mon Jul 27 09:40:11.068236 2026] [:error] [pid 12275:tid 140706987357952] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcLW3FwI8r7BFXGkAuF9wAAAAU"]
[Mon Jul 27 09:40:11.068240 2026] [:error] [pid 12275:tid 140706970572544] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/server.key"] [unique_id "amcLW3FwI8r7BFXGkAuF9gAAAAc"]
[Mon Jul 27 09:40:11.068846 2026] [:error] [pid 12275:tid 140706970572544] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/server.key"] [unique_id "amcLW3FwI8r7BFXGkAuF9gAAAAc"]
[Mon Jul 27 09:40:11.068867 2026] [:error] [pid 12275:tid 140706987357952] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcLW3FwI8r7BFXGkAuF9wAAAAU"]
[Mon Jul 27 09:40:11.068958 2026] [:error] [pid 12275:tid 140706970572544] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/server.key"] [unique_id "amcLW3FwI8r7BFXGkAuF9gAAAAc"]
[Mon Jul 27 09:40:11.069022 2026] [:error] [pid 12275:tid 140706987357952] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcLW3FwI8r7BFXGkAuF9wAAAAU"]
[Mon Jul 27 09:40:11.081282 2026] [:error] [pid 21545:tid 140706895038208] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/production.json"] [unique_id "amcLW5hXfYDIcpslIWOhVAAAAZA"]
[Mon Jul 27 09:40:11.082322 2026] [:error] [pid 21545:tid 140706895038208] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/production.json"] [unique_id "amcLW5hXfYDIcpslIWOhVAAAAZA"]
[Mon Jul 27 09:40:11.082675 2026] [:error] [pid 21545:tid 140706895038208] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/config/production.json"] [unique_id "amcLW5hXfYDIcpslIWOhVAAAAZA"]
[Mon Jul 27 09:40:11.082748 2026] [:error] [pid 21545:tid 140706895038208] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/production.json"] [unique_id "amcLW5hXfYDIcpslIWOhVAAAAZA"]
[Mon Jul 27 09:40:11.096568 2026] [:error] [pid 12276:tid 140707103270656] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.npmrc"] [unique_id "amcLW-csEMuHmMYmk66a1QAAAEA"]
[Mon Jul 27 09:40:11.097491 2026] [:error] [pid 12276:tid 140707103270656] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.npmrc"] [unique_id "amcLW-csEMuHmMYmk66a1QAAAEA"]
[Mon Jul 27 09:40:11.097914 2026] [:error] [pid 12276:tid 140707103270656] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.npmrc"] [unique_id "amcLW-csEMuHmMYmk66a1QAAAEA"]
[Mon Jul 27 09:40:11.098030 2026] [:error] [pid 12276:tid 140707103270656] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.npmrc"] [unique_id "amcLW-csEMuHmMYmk66a1QAAAEA"]
[Mon Jul 27 09:40:11.100848 2026] [:error] [pid 12275:tid 140706962179840] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcLW3FwI8r7BFXGkAuF-AAAAAg"]
[Mon Jul 27 09:40:11.102012 2026] [:error] [pid 12275:tid 140706962179840] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcLW3FwI8r7BFXGkAuF-AAAAAg"]
[Mon Jul 27 09:40:11.102989 2026] [:error] [pid 12275:tid 140706962179840] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcLW3FwI8r7BFXGkAuF-AAAAAg"]
[Mon Jul 27 09:40:11.103181 2026] [:error] [pid 12275:tid 140706962179840] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcLW3FwI8r7BFXGkAuF-AAAAAg"]
[Mon Jul 27 09:40:11.108029 2026] [:error] [pid 12275:tid 140706928609024] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.bash_history"] [unique_id "amcLW3FwI8r7BFXGkAuF-QAAAAw"]
[Mon Jul 27 09:40:11.109041 2026] [:error] [pid 12275:tid 140706928609024] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.bash_history"] [unique_id "amcLW3FwI8r7BFXGkAuF-QAAAAw"]
[Mon Jul 27 09:40:11.109530 2026] [:error] [pid 12275:tid 140706928609024] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.bash_history"] [unique_id "amcLW3FwI8r7BFXGkAuF-QAAAAw"]
[Mon Jul 27 09:40:11.109666 2026] [:error] [pid 12275:tid 140706928609024] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.bash_history"] [unique_id "amcLW3FwI8r7BFXGkAuF-QAAAAw"]
[Mon Jul 27 09:40:11.109930 2026] [:error] [pid 12275:tid 140706928609024] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Matched phrase ".bash_history" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .bash_history found within REQUEST_FILENAME: /.bash_history"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.bash_history"] [unique_id "amcLW3FwI8r7BFXGkAuF-QAAAAw"]
[Mon Jul 27 09:40:11.116109 2026] [:error] [pid 21545:tid 140706861467392] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backup.sql"] [unique_id "amcLW5hXfYDIcpslIWOhVQAAAZQ"]
[Mon Jul 27 09:40:11.116998 2026] [:error] [pid 21545:tid 140706861467392] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backup.sql"] [unique_id "amcLW5hXfYDIcpslIWOhVQAAAZQ"]
[Mon Jul 27 09:40:11.117390 2026] [:error] [pid 21545:tid 140706861467392] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/backup.sql"] [unique_id "amcLW5hXfYDIcpslIWOhVQAAAZQ"]
[Mon Jul 27 09:40:11.117481 2026] [:error] [pid 21545:tid 140706861467392] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backup.sql"] [unique_id "amcLW5hXfYDIcpslIWOhVQAAAZQ"]
[Mon Jul 27 09:40:11.133109 2026] [:error] [pid 12276:tid 140706886645504] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amcLW-csEMuHmMYmk66a1gAAAFE"]
[Mon Jul 27 09:40:11.133992 2026] [:error] [pid 12276:tid 140706886645504] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amcLW-csEMuHmMYmk66a1gAAAFE"]
[Mon Jul 27 09:40:11.134424 2026] [:error] [pid 12276:tid 140706886645504] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amcLW-csEMuHmMYmk66a1gAAAFE"]
[Mon Jul 27 09:40:11.134539 2026] [:error] [pid 12276:tid 140706886645504] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amcLW-csEMuHmMYmk66a1gAAAFE"]
[Mon Jul 27 09:40:11.134762 2026] [:error] [pid 12276:tid 140706886645504] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amcLW-csEMuHmMYmk66a1gAAAFE"]
[Mon Jul 27 09:40:11.135445 2026] [:error] [pid 12275:tid 140706953787136] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcLW3FwI8r7BFXGkAuF-gAAAAk"]
[Mon Jul 27 09:40:11.135978 2026] [:error] [pid 12275:tid 140706953787136] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcLW3FwI8r7BFXGkAuF-gAAAAk"]
[Mon Jul 27 09:40:11.136322 2026] [:error] [pid 12275:tid 140706953787136] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcLW3FwI8r7BFXGkAuF-gAAAAk"]
[Mon Jul 27 09:40:11.136422 2026] [:error] [pid 12275:tid 140706953787136] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcLW3FwI8r7BFXGkAuF-gAAAAk"]
[Mon Jul 27 09:40:11.136638 2026] [:error] [pid 12275:tid 140706953787136] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcLW3FwI8r7BFXGkAuF-gAAAAk"]
[Mon Jul 27 09:40:11.144035 2026] [:error] [pid 12275:tid 140706844681984] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amcLW3FwI8r7BFXGkAuF-wAAABY"]
[Mon Jul 27 09:40:11.144812 2026] [:error] [pid 12275:tid 140706844681984] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amcLW3FwI8r7BFXGkAuF-wAAABY"]
[Mon Jul 27 09:40:11.145224 2026] [:error] [pid 12275:tid 140706844681984] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amcLW3FwI8r7BFXGkAuF-wAAABY"]
[Mon Jul 27 09:40:11.145315 2026] [:error] [pid 12275:tid 140706844681984] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amcLW3FwI8r7BFXGkAuF-wAAABY"]
[Mon Jul 27 09:40:11.148086 2026] [:error] [pid 21545:tid 140706886645504] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/database.sql"] [unique_id "amcLW5hXfYDIcpslIWOhVgAAAZE"]
[Mon Jul 27 09:40:11.148812 2026] [:error] [pid 21545:tid 140706886645504] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/database.sql"] [unique_id "amcLW5hXfYDIcpslIWOhVgAAAZE"]
[Mon Jul 27 09:40:11.149253 2026] [:error] [pid 21545:tid 140706886645504] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/database.sql"] [unique_id "amcLW5hXfYDIcpslIWOhVgAAAZE"]
[Mon Jul 27 09:40:11.149356 2026] [:error] [pid 21545:tid 140706886645504] [client 104.23.166.83:11579] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/database.sql"] [unique_id "amcLW5hXfYDIcpslIWOhVgAAAZE"]
[Mon Jul 27 09:40:11.168457 2026] [:error] [pid 12275:tid 140706911823616] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.yml"] [unique_id "amcLW3FwI8r7BFXGkAuF_AAAAA4"]
[Mon Jul 27 09:40:11.169277 2026] [:error] [pid 12275:tid 140706911823616] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.yml"] [unique_id "amcLW3FwI8r7BFXGkAuF_AAAAA4"]
[Mon Jul 27 09:40:11.169691 2026] [:error] [pid 12275:tid 140706911823616] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.yml"] [unique_id "amcLW3FwI8r7BFXGkAuF_AAAAA4"]
[Mon Jul 27 09:40:11.169793 2026] [:error] [pid 12275:tid 140706911823616] [client 104.23.170.162:11104] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/docker-compose.yml"] [unique_id "amcLW3FwI8r7BFXGkAuF_AAAAA4"]
[Mon Jul 27 09:40:11.170427 2026] [:error] [pid 12276:tid 140706911823616] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.svn/wc.db"] [unique_id "amcLW-csEMuHmMYmk66a1wAAAE4"]
[Mon Jul 27 09:40:11.170985 2026] [:error] [pid 12276:tid 140706911823616] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.svn/wc.db"] [unique_id "amcLW-csEMuHmMYmk66a1wAAAE4"]
[Mon Jul 27 09:40:11.171810 2026] [:error] [pid 12276:tid 140706911823616] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.svn/wc.db"] [unique_id "amcLW-csEMuHmMYmk66a1wAAAE4"]
[Mon Jul 27 09:40:11.171913 2026] [:error] [pid 12276:tid 140706911823616] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.svn/wc.db"] [unique_id "amcLW-csEMuHmMYmk66a1wAAAE4"]
[Mon Jul 27 09:40:11.172099 2026] [:error] [pid 12276:tid 140706911823616] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Matched phrase "/.svn/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.svn/ found within REQUEST_FILENAME: /.svn/wc.db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.svn/wc.db"] [unique_id "amcLW-csEMuHmMYmk66a1wAAAE4"]
[Mon Jul 27 09:40:11.199011 2026] [:error] [pid 12275:tid 140706861467392] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/actuator/heapdump"] [unique_id "amcLW3FwI8r7BFXGkAuF_QAAABQ"]
[Mon Jul 27 09:40:11.199922 2026] [:error] [pid 12275:tid 140706861467392] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/actuator/heapdump"] [unique_id "amcLW3FwI8r7BFXGkAuF_QAAABQ"]
[Mon Jul 27 09:40:11.200358 2026] [:error] [pid 12275:tid 140706861467392] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/actuator/heapdump"] [unique_id "amcLW3FwI8r7BFXGkAuF_QAAABQ"]
[Mon Jul 27 09:40:11.200472 2026] [:error] [pid 12275:tid 140706861467392] [client 172.71.95.22:14090] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/actuator/heapdump"] [unique_id "amcLW3FwI8r7BFXGkAuF_QAAABQ"]
[Mon Jul 27 09:40:11.207538 2026] [:error] [pid 12276:tid 140706861467392] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.ssh/id_ed25519"] [unique_id "amcLW-csEMuHmMYmk66a2AAAAFQ"]
[Mon Jul 27 09:40:11.208495 2026] [:error] [pid 12276:tid 140706861467392] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.ssh/id_ed25519"] [unique_id "amcLW-csEMuHmMYmk66a2AAAAFQ"]
[Mon Jul 27 09:40:11.208966 2026] [:error] [pid 12276:tid 140706861467392] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.ssh/id_ed25519"] [unique_id "amcLW-csEMuHmMYmk66a2AAAAFQ"]
[Mon Jul 27 09:40:11.209083 2026] [:error] [pid 12276:tid 140706861467392] [client 172.71.103.41:9258] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.ssh/id_ed25519"] [unique_id "amcLW-csEMuHmMYmk66a2AAAAFQ"]
[Mon Jul 27 09:40:11.217726 2026] [:error] [pid 21545:tid 140706978965248] [client 104.23.172.80:14243] [client 104.23.172.80] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backup.zip"] [unique_id "amcLW5hXfYDIcpslIWOhVwAAAYY"]
[Mon Jul 27 09:40:11.218605 2026] [:error] [pid 21545:tid 140706978965248] [client 104.23.172.80:14243] [client 104.23.172.80] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backup.zip"] [unique_id "amcLW5hXfYDIcpslIWOhVwAAAYY"]
[Mon Jul 27 09:40:11.219077 2026] [:error] [pid 21545:tid 140706978965248] [client 104.23.172.80:14243] [client 104.23.172.80] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/backup.zip"] [unique_id "amcLW5hXfYDIcpslIWOhVwAAAYY"]
[Mon Jul 27 09:40:11.219166 2026] [:error] [pid 21545:tid 140706978965248] [client 104.23.172.80:14243] [client 104.23.172.80] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backup.zip"] [unique_id "amcLW5hXfYDIcpslIWOhVwAAAYY"]
[Mon Jul 27 09:40:11.236475 2026] [:error] [pid 21545:tid 140706970572544] [client 104.23.168.67:13439] [client 104.23.168.67] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backup.tar.gz"] [unique_id "amcLW5hXfYDIcpslIWOhWAAAAYc"]
[Mon Jul 27 09:40:11.237243 2026] [:error] [pid 21545:tid 140706970572544] [client 104.23.168.67:13439] [client 104.23.168.67] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backup.tar.gz"] [unique_id "amcLW5hXfYDIcpslIWOhWAAAAYc"]
[Mon Jul 27 09:40:11.237671 2026] [:error] [pid 21545:tid 140706970572544] [client 104.23.168.67:13439] [client 104.23.168.67] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/backup.tar.gz"] [unique_id "amcLW5hXfYDIcpslIWOhWAAAAYc"]
[Mon Jul 27 09:40:11.237776 2026] [:error] [pid 21545:tid 140706970572544] [client 104.23.168.67:13439] [client 104.23.168.67] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backup.tar.gz"] [unique_id "amcLW5hXfYDIcpslIWOhWAAAAYc"]
[Mon Jul 27 09:40:37.145115 2026] [:error] [pid 21545:tid 140706953787136] [client 162.158.79.90:14335] [client 162.158.79.90] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLdZhXfYDIcpslIWOhlwAAAYk"]
[Mon Jul 27 09:40:37.145759 2026] [:error] [pid 21545:tid 140706953787136] [client 162.158.79.90:14335] [client 162.158.79.90] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLdZhXfYDIcpslIWOhlwAAAYk"]
[Mon Jul 27 09:40:37.146149 2026] [:error] [pid 21545:tid 140706953787136] [client 162.158.79.90:14335] [client 162.158.79.90] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLdZhXfYDIcpslIWOhlwAAAYk"]
[Mon Jul 27 09:40:48.802047 2026] [:error] [pid 12275:tid 140707012536064] [client 162.159.106.33:13657] [client 162.159.106.33] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLgHFwI8r7BFXGkAuGSAAAAAI"]
[Mon Jul 27 09:40:48.802834 2026] [:error] [pid 12275:tid 140707012536064] [client 162.159.106.33:13657] [client 162.159.106.33] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLgHFwI8r7BFXGkAuGSAAAAAI"]
[Mon Jul 27 09:40:48.803517 2026] [:error] [pid 12275:tid 140707012536064] [client 162.159.106.33:13657] [client 162.159.106.33] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLgHFwI8r7BFXGkAuGSAAAAAI"]
[Mon Jul 27 09:40:48.803614 2026] [:error] [pid 12275:tid 140707012536064] [client 162.159.106.33:13657] [client 162.159.106.33] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLgHFwI8r7BFXGkAuGSAAAAAI"]
[Mon Jul 27 09:40:50.057059 2026] [:error] [pid 12275:tid 140706928609024] [client 162.158.175.12:9794] [client 162.158.175.12] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/assets/sbf-logo-BYChYlIs.png"] [unique_id "amcLgnFwI8r7BFXGkAuGSwAAAAw"]
[Mon Jul 27 09:40:50.057657 2026] [:error] [pid 12275:tid 140706928609024] [client 162.158.175.12:9794] [client 162.158.175.12] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/assets/sbf-logo-BYChYlIs.png"] [unique_id "amcLgnFwI8r7BFXGkAuGSwAAAAw"]
[Mon Jul 27 09:40:50.058107 2026] [:error] [pid 12275:tid 140706928609024] [client 162.158.175.12:9794] [client 162.158.175.12] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/assets/sbf-logo-BYChYlIs.png"] [unique_id "amcLgnFwI8r7BFXGkAuGSwAAAAw"]
[Mon Jul 27 09:40:50.058139 2026] [:error] [pid 12275:tid 140706928609024] [client 162.158.175.12:9794] [client 162.158.175.12] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/assets/sbf-logo-BYChYlIs.png"] [unique_id "amcLgnFwI8r7BFXGkAuGSwAAAAw"]
[Mon Jul 27 09:41:18.605628 2026] [:error] [pid 24106:tid 140706869860096] [client 198.41.227.118:10921] [client 198.41.227.118] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcLnjs8oMu6f6EYbxSM0AAAAVM"]
[Mon Jul 27 09:41:18.606595 2026] [:error] [pid 24106:tid 140706869860096] [client 198.41.227.118:10921] [client 198.41.227.118] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcLnjs8oMu6f6EYbxSM0AAAAVM"]
[Mon Jul 27 09:41:18.607337 2026] [:error] [pid 24106:tid 140706869860096] [client 198.41.227.118:10921] [client 198.41.227.118] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcLnjs8oMu6f6EYbxSM0AAAAVM"]
[Mon Jul 27 09:41:18.607395 2026] [:error] [pid 24106:tid 140706869860096] [client 198.41.227.118:10921] [client 198.41.227.118] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcLnjs8oMu6f6EYbxSM0AAAAVM"]
[Mon Jul 27 09:41:21.775095 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.38.36:9288] [client 162.158.38.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLoecsEMuHmMYmk66bNgAAAFY"]
[Mon Jul 27 09:41:21.775826 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.38.36:9288] [client 162.158.38.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLoecsEMuHmMYmk66bNgAAAFY"]
[Mon Jul 27 09:41:21.776178 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.38.36:9288] [client 162.158.38.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcLoecsEMuHmMYmk66bNgAAAFY"]
[Mon Jul 27 09:43:45.298502 2026] [:error] [pid 12380:tid 140706844681984] [client 162.158.155.60:13151] [client 162.158.155.60] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcMMaaChfbWW0CZ_hrd8wAAANY"]
[Mon Jul 27 09:43:45.299366 2026] [:error] [pid 12380:tid 140706844681984] [client 162.158.155.60:13151] [client 162.158.155.60] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcMMaaChfbWW0CZ_hrd8wAAANY"]
[Mon Jul 27 09:43:45.299721 2026] [:error] [pid 12380:tid 140706844681984] [client 162.158.155.60:13151] [client 162.158.155.60] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcMMaaChfbWW0CZ_hrd8wAAANY"]
[Mon Jul 27 09:43:45.299799 2026] [:error] [pid 12380:tid 140706844681984] [client 162.158.155.60:13151] [client 162.158.155.60] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcMMaaChfbWW0CZ_hrd8wAAANY"]
[Mon Jul 27 09:45:37.672903 2026] [:error] [pid 12380:tid 140706995750656] [client 104.22.10.16:13324] [client 104.22.10.16] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcMoaaChfbWW0CZ_hrgNAAAAMQ"]
[Mon Jul 27 09:45:37.673675 2026] [:error] [pid 12380:tid 140706995750656] [client 104.22.10.16:13324] [client 104.22.10.16] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcMoaaChfbWW0CZ_hrgNAAAAMQ"]
[Mon Jul 27 09:45:37.674371 2026] [:error] [pid 12380:tid 140706995750656] [client 104.22.10.16:13324] [client 104.22.10.16] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcMoaaChfbWW0CZ_hrgNAAAAMQ"]
[Mon Jul 27 09:45:37.674426 2026] [:error] [pid 12380:tid 140706995750656] [client 104.22.10.16:13324] [client 104.22.10.16] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcMoaaChfbWW0CZ_hrgNAAAAMQ"]
[Mon Jul 27 09:50:15.864845 2026] [:error] [pid 24106:tid 140706937001728] [client 172.69.138.103:10071] [client 172.69.138.103] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcNtzs8oMu6f6EYbxSUDAAAAUs"]
[Mon Jul 27 09:50:15.865755 2026] [:error] [pid 24106:tid 140706937001728] [client 172.69.138.103:10071] [client 172.69.138.103] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcNtzs8oMu6f6EYbxSUDAAAAUs"]
[Mon Jul 27 09:50:15.866397 2026] [:error] [pid 24106:tid 140706937001728] [client 172.69.138.103:10071] [client 172.69.138.103] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcNtzs8oMu6f6EYbxSUDAAAAUs"]
[Mon Jul 27 09:50:15.866447 2026] [:error] [pid 24106:tid 140706937001728] [client 172.69.138.103:10071] [client 172.69.138.103] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcNtzs8oMu6f6EYbxSUDAAAAUs"]
[Mon Jul 27 09:54:26.743697 2026] [:error] [pid 24106:tid 140706987357952] [client 172.71.239.90:12927] [client 172.71.239.90] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcOsjs8oMu6f6EYbxSZCQAAAUU"]
[Mon Jul 27 09:54:26.744727 2026] [:error] [pid 24106:tid 140706987357952] [client 172.71.239.90:12927] [client 172.71.239.90] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcOsjs8oMu6f6EYbxSZCQAAAUU"]
[Mon Jul 27 09:54:26.745593 2026] [:error] [pid 24106:tid 140706987357952] [client 172.71.239.90:12927] [client 172.71.239.90] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcOsjs8oMu6f6EYbxSZCQAAAUU"]
[Mon Jul 27 09:54:26.745679 2026] [:error] [pid 24106:tid 140706987357952] [client 172.71.239.90:12927] [client 172.71.239.90] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcOsjs8oMu6f6EYbxSZCQAAAUU"]
[Mon Jul 27 09:57:38.650953 2026] [:error] [pid 24106:tid 140706920216320] [client 172.69.138.102:9773] [client 172.69.138.102] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcPcjs8oMu6f6EYbxSb_QAAAU0"]
[Mon Jul 27 09:57:38.651822 2026] [:error] [pid 24106:tid 140706920216320] [client 172.69.138.102:9773] [client 172.69.138.102] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcPcjs8oMu6f6EYbxSb_QAAAU0"]
[Mon Jul 27 09:57:38.652507 2026] [:error] [pid 24106:tid 140706920216320] [client 172.69.138.102:9773] [client 172.69.138.102] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcPcjs8oMu6f6EYbxSb_QAAAU0"]
[Mon Jul 27 09:57:38.652586 2026] [:error] [pid 24106:tid 140706920216320] [client 172.69.138.102:9773] [client 172.69.138.102] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcPcjs8oMu6f6EYbxSb_QAAAU0"]
[Mon Jul 27 09:59:55.345132 2026] [:error] [pid 12380:tid 140706970572544] [client 162.158.217.35:14324] [client 162.158.217.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcP-6aChfbWW0CZ_hru9QAAAMc"]
[Mon Jul 27 09:59:55.346063 2026] [:error] [pid 12380:tid 140706970572544] [client 162.158.217.35:14324] [client 162.158.217.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcP-6aChfbWW0CZ_hru9QAAAMc"]
[Mon Jul 27 09:59:55.346663 2026] [:error] [pid 12380:tid 140706970572544] [client 162.158.217.35:14324] [client 162.158.217.35] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcP-6aChfbWW0CZ_hru9QAAAMc"]
[Mon Jul 27 09:59:55.346711 2026] [:error] [pid 12380:tid 140706970572544] [client 162.158.217.35:14324] [client 162.158.217.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcP-6aChfbWW0CZ_hru9QAAAMc"]
[Mon Jul 27 10:05:15.912119 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.86.82:11424] [client 162.158.86.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amcRO6aChfbWW0CZ_hrzVQAAAM0"]
[Mon Jul 27 10:05:15.913141 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.86.82:11424] [client 162.158.86.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amcRO6aChfbWW0CZ_hrzVQAAAM0"]
[Mon Jul 27 10:05:15.913780 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.86.82:11424] [client 162.158.86.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amcRO6aChfbWW0CZ_hrzVQAAAM0"]
[Mon Jul 27 10:05:15.966597 2026] [:error] [pid 24106:tid 140706995750656] [client 104.23.239.16:9548] [client 104.23.239.16] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcROzs8oMu6f6EYbxSi-QAAAUQ"]
[Mon Jul 27 10:05:15.967271 2026] [:error] [pid 24106:tid 140706995750656] [client 104.23.239.16:9548] [client 104.23.239.16] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcROzs8oMu6f6EYbxSi-QAAAUQ"]
[Mon Jul 27 10:05:15.967746 2026] [:error] [pid 24106:tid 140706995750656] [client 104.23.239.16:9548] [client 104.23.239.16] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcROzs8oMu6f6EYbxSi-QAAAUQ"]
[Mon Jul 27 10:05:15.991721 2026] [:error] [pid 24106:tid 140706962179840] [client 104.23.239.16:9548] [client 104.23.239.16] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcROzs8oMu6f6EYbxSi-gAAAUg"]
[Mon Jul 27 10:05:15.992847 2026] [:error] [pid 24106:tid 140706962179840] [client 104.23.239.16:9548] [client 104.23.239.16] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcROzs8oMu6f6EYbxSi-gAAAUg"]
[Mon Jul 27 10:05:15.993613 2026] [:error] [pid 24106:tid 140706962179840] [client 104.23.239.16:9548] [client 104.23.239.16] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcROzs8oMu6f6EYbxSi-gAAAUg"]
[Mon Jul 27 10:05:15.993924 2026] [:error] [pid 24106:tid 140706962179840] [client 104.23.239.16:9548] [client 104.23.239.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcROzs8oMu6f6EYbxSi-gAAAUg"]
[Mon Jul 27 10:05:16.045070 2026] [:error] [pid 24106:tid 140706886645504] [client 104.23.239.123:10561] [client 104.23.239.123] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcRPDs8oMu6f6EYbxSi-wAAAVE"]
[Mon Jul 27 10:05:16.045956 2026] [:error] [pid 24106:tid 140706886645504] [client 104.23.239.123:10561] [client 104.23.239.123] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcRPDs8oMu6f6EYbxSi-wAAAVE"]
[Mon Jul 27 10:05:16.046506 2026] [:error] [pid 24106:tid 140706886645504] [client 104.23.239.123:10561] [client 104.23.239.123] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcRPDs8oMu6f6EYbxSi-wAAAVE"]
[Mon Jul 27 10:05:16.046798 2026] [:error] [pid 24106:tid 140706886645504] [client 104.23.239.123:10561] [client 104.23.239.123] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcRPDs8oMu6f6EYbxSi-wAAAVE"]
[Mon Jul 27 10:05:16.048854 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.95.215:10655] [client 162.158.95.215] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/js/config.js"] [unique_id "amcRPHFwI8r7BFXGkAuPgwAAABM"]
[Mon Jul 27 10:05:16.049339 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.95.215:10655] [client 162.158.95.215] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/js/config.js"] [unique_id "amcRPHFwI8r7BFXGkAuPgwAAABM"]
[Mon Jul 27 10:05:16.049748 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.95.215:10655] [client 162.158.95.215] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/js/config.js"] [unique_id "amcRPHFwI8r7BFXGkAuPgwAAABM"]
[Mon Jul 27 10:05:16.060661 2026] [:error] [pid 24106:tid 140707012536064] [client 104.23.239.123:10561] [client 104.23.239.123] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcRPDs8oMu6f6EYbxSi_AAAAUI"]
[Mon Jul 27 10:05:16.061485 2026] [:error] [pid 24106:tid 140707012536064] [client 104.23.239.123:10561] [client 104.23.239.123] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcRPDs8oMu6f6EYbxSi_AAAAUI"]
[Mon Jul 27 10:05:16.062006 2026] [:error] [pid 24106:tid 140707012536064] [client 104.23.239.123:10561] [client 104.23.239.123] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcRPDs8oMu6f6EYbxSi_AAAAUI"]
[Mon Jul 27 10:05:16.062263 2026] [:error] [pid 24106:tid 140707012536064] [client 104.23.239.123:10561] [client 104.23.239.123] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcRPDs8oMu6f6EYbxSi_AAAAUI"]
[Mon Jul 27 10:05:16.076354 2026] [:error] [pid 24106:tid 140706937001728] [client 104.23.239.16:9548] [client 104.23.239.16] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcRPDs8oMu6f6EYbxSi_QAAAUs"]
[Mon Jul 27 10:05:16.077206 2026] [:error] [pid 24106:tid 140706937001728] [client 104.23.239.16:9548] [client 104.23.239.16] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcRPDs8oMu6f6EYbxSi_QAAAUs"]
[Mon Jul 27 10:05:16.077795 2026] [:error] [pid 24106:tid 140706937001728] [client 104.23.239.16:9548] [client 104.23.239.16] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcRPDs8oMu6f6EYbxSi_QAAAUs"]
[Mon Jul 27 10:05:16.080392 2026] [:error] [pid 12380:tid 140706827896576] [client 104.23.239.123:10566] [client 104.23.239.123] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amcRPKaChfbWW0CZ_hrzVgAAANg"]
[Mon Jul 27 10:05:16.081365 2026] [:error] [pid 12380:tid 140706827896576] [client 104.23.239.123:10566] [client 104.23.239.123] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amcRPKaChfbWW0CZ_hrzVgAAANg"]
[Mon Jul 27 10:05:16.081943 2026] [:error] [pid 12380:tid 140706827896576] [client 104.23.239.123:10566] [client 104.23.239.123] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amcRPKaChfbWW0CZ_hrzVgAAANg"]
[Mon Jul 27 10:05:16.082244 2026] [:error] [pid 12380:tid 140706827896576] [client 104.23.239.123:10566] [client 104.23.239.123] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amcRPKaChfbWW0CZ_hrzVgAAANg"]
[Mon Jul 27 10:05:16.092441 2026] [:error] [pid 12380:tid 140706995750656] [client 172.70.240.73:10694] [client 172.70.240.73] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amcRPKaChfbWW0CZ_hrzVwAAAMQ"]
[Mon Jul 27 10:05:16.093146 2026] [:error] [pid 12380:tid 140706995750656] [client 172.70.240.73:10694] [client 172.70.240.73] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amcRPKaChfbWW0CZ_hrzVwAAAMQ"]
[Mon Jul 27 10:05:16.093584 2026] [:error] [pid 12380:tid 140706995750656] [client 172.70.240.73:10694] [client 172.70.240.73] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amcRPKaChfbWW0CZ_hrzVwAAAMQ"]
[Mon Jul 27 10:05:16.095255 2026] [:error] [pid 24106:tid 140706844681984] [client 172.71.164.5:10829] [client 172.71.164.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/env"] [unique_id "amcRPDs8oMu6f6EYbxSi_gAAAVY"]
[Mon Jul 27 10:05:16.096130 2026] [:error] [pid 24106:tid 140706844681984] [client 172.71.164.5:10829] [client 172.71.164.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/env"] [unique_id "amcRPDs8oMu6f6EYbxSi_gAAAVY"]
[Mon Jul 27 10:05:16.096679 2026] [:error] [pid 24106:tid 140706844681984] [client 172.71.164.5:10829] [client 172.71.164.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/env"] [unique_id "amcRPDs8oMu6f6EYbxSi_gAAAVY"]
[Mon Jul 27 10:05:16.112227 2026] [:error] [pid 12275:tid 140706937001728] [client 172.71.148.37:12357] [client 172.71.148.37] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/settings.js"] [unique_id "amcRPHFwI8r7BFXGkAuPhQAAAAs"]
[Mon Jul 27 10:05:16.112406 2026] [:error] [pid 12277:tid 140706895038208] [client 172.70.250.163:10662] [client 172.70.250.163] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/js/env.js"] [unique_id "amcRPBwjcb8HQE21kA6j_AAAAJA"]
[Mon Jul 27 10:05:16.113252 2026] [:error] [pid 12275:tid 140706937001728] [client 172.71.148.37:12357] [client 172.71.148.37] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/settings.js"] [unique_id "amcRPHFwI8r7BFXGkAuPhQAAAAs"]
[Mon Jul 27 10:05:16.113318 2026] [:error] [pid 12277:tid 140706895038208] [client 172.70.250.163:10662] [client 172.70.250.163] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/js/env.js"] [unique_id "amcRPBwjcb8HQE21kA6j_AAAAJA"]
[Mon Jul 27 10:05:16.113870 2026] [:error] [pid 12277:tid 140706895038208] [client 172.70.250.163:10662] [client 172.70.250.163] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/js/env.js"] [unique_id "amcRPBwjcb8HQE21kA6j_AAAAJA"]
[Mon Jul 27 10:05:16.113901 2026] [:error] [pid 12275:tid 140706937001728] [client 172.71.148.37:12357] [client 172.71.148.37] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/settings.js"] [unique_id "amcRPHFwI8r7BFXGkAuPhQAAAAs"]
[Mon Jul 27 10:24:51.809989 2026] [:error] [pid 12275:tid 140707012536064] [client 104.23.223.54:11053] [client 104.23.223.54] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amcV03FwI8r7BFXGkAuZSAAAAAI"]
[Mon Jul 27 10:24:51.810925 2026] [:error] [pid 12275:tid 140707012536064] [client 104.23.223.54:11053] [client 104.23.223.54] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amcV03FwI8r7BFXGkAuZSAAAAAI"]
[Mon Jul 27 10:24:51.811459 2026] [:error] [pid 12275:tid 140707012536064] [client 104.23.223.54:11053] [client 104.23.223.54] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amcV03FwI8r7BFXGkAuZSAAAAAI"]
[Mon Jul 27 10:26:03.688437 2026] [:error] [pid 12380:tid 140706827896576] [client 172.70.35.207:13188] [client 172.70.35.207] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcWG6aChfbWW0CZ_hoFWgAAANg"]
[Mon Jul 27 10:26:03.689318 2026] [:error] [pid 12380:tid 140706827896576] [client 172.70.35.207:13188] [client 172.70.35.207] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcWG6aChfbWW0CZ_hoFWgAAANg"]
[Mon Jul 27 10:26:03.689852 2026] [:error] [pid 12380:tid 140706827896576] [client 172.70.35.207:13188] [client 172.70.35.207] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcWG6aChfbWW0CZ_hoFWgAAANg"]
[Mon Jul 27 10:26:22.098728 2026] [:error] [pid 12275:tid 140706911823616] [client 104.22.24.170:12574] [client 104.22.24.170] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcWLnFwI8r7BFXGkAuZpAAAAA4"]
[Mon Jul 27 10:26:22.099649 2026] [:error] [pid 12275:tid 140706911823616] [client 104.22.24.170:12574] [client 104.22.24.170] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcWLnFwI8r7BFXGkAuZpAAAAA4"]
[Mon Jul 27 10:26:22.100127 2026] [:error] [pid 12275:tid 140706911823616] [client 104.22.24.170:12574] [client 104.22.24.170] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:from outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:from=oai-searchbot(at)openai.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcWLnFwI8r7BFXGkAuZpAAAAA4"]
[Mon Jul 27 10:26:22.100182 2026] [:error] [pid 12275:tid 140706911823616] [client 104.22.24.170:12574] [client 104.22.24.170] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcWLnFwI8r7BFXGkAuZpAAAAA4"]
[Mon Jul 27 10:28:59.993646 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.155.59:13914] [client 162.158.155.59] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcWy6aChfbWW0CZ_hoHzgAAAMg"]
[Mon Jul 27 10:28:59.994219 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.155.59:13914] [client 162.158.155.59] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcWy6aChfbWW0CZ_hoHzgAAAMg"]
[Mon Jul 27 10:28:59.994603 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.155.59:13914] [client 162.158.155.59] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcWy6aChfbWW0CZ_hoHzgAAAMg"]
[Mon Jul 27 10:33:10.957612 2026] [:error] [pid 21545:tid 140706895038208] [client 104.23.172.124:10502] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcXxphXfYDIcpslIWOtzwAAAZA"]
[Mon Jul 27 10:33:10.962254 2026] [:error] [pid 21545:tid 140706895038208] [client 104.23.172.124:10502] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcXxphXfYDIcpslIWOtzwAAAZA"]
[Mon Jul 27 10:33:10.962728 2026] [:error] [pid 21545:tid 140706895038208] [client 104.23.172.124:10502] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcXxphXfYDIcpslIWOtzwAAAZA"]
[Mon Jul 27 10:37:57.505148 2026] [:error] [pid 12380:tid 140706861467392] [client 172.71.232.35:12579] [client 172.71.232.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcY5aaChfbWW0CZ_hoTIgAAANQ"]
[Mon Jul 27 10:37:57.505954 2026] [:error] [pid 12380:tid 140706861467392] [client 172.71.232.35:12579] [client 172.71.232.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcY5aaChfbWW0CZ_hoTIgAAANQ"]
[Mon Jul 27 10:37:57.506509 2026] [:error] [pid 12380:tid 140706861467392] [client 172.71.232.35:12579] [client 172.71.232.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcY5aaChfbWW0CZ_hoTIgAAANQ"]
[Mon Jul 27 10:38:32.403478 2026] [:error] [pid 24106:tid 140706878252800] [client 172.71.164.5:12074] [client 172.71.164.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcZCDs8oMu6f6EYbxS-jAAAAVI"]
[Mon Jul 27 10:38:32.404426 2026] [:error] [pid 24106:tid 140706878252800] [client 172.71.164.5:12074] [client 172.71.164.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcZCDs8oMu6f6EYbxS-jAAAAVI"]
[Mon Jul 27 10:38:32.404890 2026] [:error] [pid 24106:tid 140706878252800] [client 172.71.164.5:12074] [client 172.71.164.5] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcZCDs8oMu6f6EYbxS-jAAAAVI"]
[Mon Jul 27 10:38:32.404998 2026] [:error] [pid 24106:tid 140706878252800] [client 172.71.164.5:12074] [client 172.71.164.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcZCDs8oMu6f6EYbxS-jAAAAVI"]
[Mon Jul 27 10:38:32.405210 2026] [:error] [pid 24106:tid 140706878252800] [client 172.71.164.5:12074] [client 172.71.164.5] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcZCDs8oMu6f6EYbxS-jAAAAVI"]
[Mon Jul 27 10:53:09.527647 2026] [:error] [pid 21545:tid 140706970572544] [client 172.68.3.101:10288] [client 172.68.3.101] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdZhXfYDIcpslIWOwoAAAAYc"]
[Mon Jul 27 10:53:09.528193 2026] [:error] [pid 21545:tid 140706970572544] [client 172.68.3.101:10288] [client 172.68.3.101] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdZhXfYDIcpslIWOwoAAAAYc"]
[Mon Jul 27 10:53:09.528598 2026] [:error] [pid 21545:tid 140706970572544] [client 172.68.3.101:10288] [client 172.68.3.101] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdZhXfYDIcpslIWOwoAAAAYc"]
[Mon Jul 27 10:53:09.807066 2026] [:error] [pid 12275:tid 140706995750656] [client 104.23.243.181:13662] [client 104.23.243.181] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdXFwI8r7BFXGkAui2AAAAAQ"]
[Mon Jul 27 10:53:09.807936 2026] [:error] [pid 12275:tid 140706995750656] [client 104.23.243.181:13662] [client 104.23.243.181] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdXFwI8r7BFXGkAui2AAAAAQ"]
[Mon Jul 27 10:53:09.808443 2026] [:error] [pid 12275:tid 140706995750656] [client 104.23.243.181:13662] [client 104.23.243.181] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdXFwI8r7BFXGkAui2AAAAAQ"]
[Mon Jul 27 10:53:09.814469 2026] [:error] [pid 12277:tid 140706853074688] [client 104.23.223.26:10519] [client 104.23.223.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdRwjcb8HQE21kA6lEwAAAJU"]
[Mon Jul 27 10:53:09.815229 2026] [:error] [pid 12277:tid 140706853074688] [client 104.23.223.26:10519] [client 104.23.223.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdRwjcb8HQE21kA6lEwAAAJU"]
[Mon Jul 27 10:53:09.815827 2026] [:error] [pid 12277:tid 140706853074688] [client 104.23.223.26:10519] [client 104.23.223.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdRwjcb8HQE21kA6lEwAAAJU"]
[Mon Jul 27 10:53:09.955090 2026] [:error] [pid 12380:tid 140706928609024] [client 172.68.174.216:13499] [client 172.68.174.216] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdaaChfbWW0CZ_hofbgAAAMw"]
[Mon Jul 27 10:53:09.955881 2026] [:error] [pid 12380:tid 140706928609024] [client 172.68.174.216:13499] [client 172.68.174.216] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdaaChfbWW0CZ_hofbgAAAMw"]
[Mon Jul 27 10:53:09.956435 2026] [:error] [pid 12380:tid 140706928609024] [client 172.68.174.216:13499] [client 172.68.174.216] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdaaChfbWW0CZ_hofbgAAAMw"]
[Mon Jul 27 10:53:09.994650 2026] [:error] [pid 24106:tid 140706970572544] [client 162.158.170.222:9599] [client 162.158.170.222] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdTs8oMu6f6EYbxTJhwAAAUc"]
[Mon Jul 27 10:53:09.995152 2026] [:error] [pid 24106:tid 140706970572544] [client 162.158.170.222:9599] [client 162.158.170.222] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdTs8oMu6f6EYbxTJhwAAAUc"]
[Mon Jul 27 10:53:09.995530 2026] [:error] [pid 24106:tid 140706970572544] [client 162.158.170.222:9599] [client 162.158.170.222] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/SXZN_3sEcs_Idl8QtcCgKgS-CUqwDVHS29SGtsB6iJo"] [unique_id "amccdTs8oMu6f6EYbxTJhwAAAUc"]
[Mon Jul 27 10:53:16.151913 2026] [:error] [pid 12380:tid 140706869860096] [client 172.68.34.106:11945] [client 172.68.34.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfKaChfbWW0CZ_hofjAAAANM"]
[Mon Jul 27 10:53:16.152570 2026] [:error] [pid 12380:tid 140706869860096] [client 172.68.34.106:11945] [client 172.68.34.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfKaChfbWW0CZ_hofjAAAANM"]
[Mon Jul 27 10:53:16.152974 2026] [:error] [pid 12380:tid 140706869860096] [client 172.68.34.106:11945] [client 172.68.34.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfKaChfbWW0CZ_hofjAAAANM"]
[Mon Jul 27 10:53:16.396799 2026] [:error] [pid 12380:tid 140706953787136] [client 104.23.243.164:12250] [client 104.23.243.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfKaChfbWW0CZ_hofjQAAAMk"]
[Mon Jul 27 10:53:16.397495 2026] [:error] [pid 12380:tid 140706953787136] [client 104.23.243.164:12250] [client 104.23.243.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfKaChfbWW0CZ_hofjQAAAMk"]
[Mon Jul 27 10:53:16.397936 2026] [:error] [pid 12380:tid 140706953787136] [client 104.23.243.164:12250] [client 104.23.243.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfKaChfbWW0CZ_hofjQAAAMk"]
[Mon Jul 27 10:53:16.432934 2026] [:error] [pid 24106:tid 140706937001728] [client 162.158.183.12:10646] [client 162.158.183.12] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfDs8oMu6f6EYbxTJnwAAAUs"]
[Mon Jul 27 10:53:16.435906 2026] [:error] [pid 24106:tid 140706937001728] [client 162.158.183.12:10646] [client 162.158.183.12] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfDs8oMu6f6EYbxTJnwAAAUs"]
[Mon Jul 27 10:53:16.436533 2026] [:error] [pid 24106:tid 140706937001728] [client 162.158.183.12:10646] [client 162.158.183.12] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfDs8oMu6f6EYbxTJnwAAAUs"]
[Mon Jul 27 10:53:16.586919 2026] [:error] [pid 12380:tid 140706878252800] [client 172.68.174.236:12818] [client 172.68.174.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfKaChfbWW0CZ_hofjgAAANI"]
[Mon Jul 27 10:53:16.587783 2026] [:error] [pid 12380:tid 140706878252800] [client 172.68.174.236:12818] [client 172.68.174.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfKaChfbWW0CZ_hofjgAAANI"]
[Mon Jul 27 10:53:16.588293 2026] [:error] [pid 12380:tid 140706878252800] [client 172.68.174.236:12818] [client 172.68.174.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfKaChfbWW0CZ_hofjgAAANI"]
[Mon Jul 27 10:53:16.658447 2026] [:error] [pid 12275:tid 140707020928768] [client 172.70.143.201:13034] [client 172.70.143.201] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfHFwI8r7BFXGkAui_gAAAAE"]
[Mon Jul 27 10:53:16.659221 2026] [:error] [pid 12275:tid 140707020928768] [client 172.70.143.201:13034] [client 172.70.143.201] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfHFwI8r7BFXGkAui_gAAAAE"]
[Mon Jul 27 10:53:16.659746 2026] [:error] [pid 12275:tid 140707020928768] [client 172.70.143.201:13034] [client 172.70.143.201] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/vtFvT1EDfJyi_Q-187sNVAUBDSGtzlwrc2kOnIKQ8mI"] [unique_id "amccfHFwI8r7BFXGkAui_gAAAAE"]
[Mon Jul 27 10:53:23.721887 2026] [:error] [pid 24106:tid 140707020928768] [client 104.23.162.16:13219] [client 104.23.162.16] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccgzs8oMu6f6EYbxTJsQAAAUE"]
[Mon Jul 27 10:53:23.723012 2026] [:error] [pid 24106:tid 140707020928768] [client 104.23.162.16:13219] [client 104.23.162.16] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccgzs8oMu6f6EYbxTJsQAAAUE"]
[Mon Jul 27 10:53:23.723808 2026] [:error] [pid 24106:tid 140707020928768] [client 104.23.162.16:13219] [client 104.23.162.16] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccgzs8oMu6f6EYbxTJsQAAAUE"]
[Mon Jul 27 10:53:23.723873 2026] [:error] [pid 24106:tid 140707020928768] [client 104.23.162.16:13219] [client 104.23.162.16] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccgzs8oMu6f6EYbxTJsQAAAUE"]
[Mon Jul 27 10:53:23.823673 2026] [:error] [pid 24106:tid 140706878252800] [client 141.101.105.104:12677] [client 141.101.105.104] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amccgzs8oMu6f6EYbxTJsgAAAVI"]
[Mon Jul 27 10:53:23.824680 2026] [:error] [pid 24106:tid 140706878252800] [client 141.101.105.104:12677] [client 141.101.105.104] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amccgzs8oMu6f6EYbxTJsgAAAVI"]
[Mon Jul 27 10:53:23.825510 2026] [:error] [pid 24106:tid 140706878252800] [client 141.101.105.104:12677] [client 141.101.105.104] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amccgzs8oMu6f6EYbxTJsgAAAVI"]
[Mon Jul 27 10:53:23.825593 2026] [:error] [pid 24106:tid 140706878252800] [client 141.101.105.104:12677] [client 141.101.105.104] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amccgzs8oMu6f6EYbxTJsgAAAVI"]
[Mon Jul 27 10:53:23.932085 2026] [:error] [pid 24106:tid 140706861467392] [client 141.101.105.104:12677] [client 141.101.105.104] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amccgzs8oMu6f6EYbxTJswAAAVQ"]
[Mon Jul 27 10:53:23.933214 2026] [:error] [pid 24106:tid 140706861467392] [client 141.101.105.104:12677] [client 141.101.105.104] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amccgzs8oMu6f6EYbxTJswAAAVQ"]
[Mon Jul 27 10:53:23.933790 2026] [:error] [pid 24106:tid 140706861467392] [client 141.101.105.104:12677] [client 141.101.105.104] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amccgzs8oMu6f6EYbxTJswAAAVQ"]
[Mon Jul 27 10:53:23.933911 2026] [:error] [pid 24106:tid 140706861467392] [client 141.101.105.104:12677] [client 141.101.105.104] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amccgzs8oMu6f6EYbxTJswAAAVQ"]
[Mon Jul 27 10:53:23.934181 2026] [:error] [pid 24106:tid 140706861467392] [client 141.101.105.104:12677] [client 141.101.105.104] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amccgzs8oMu6f6EYbxTJswAAAVQ"]
[Mon Jul 27 10:53:23.974215 2026] [:error] [pid 24106:tid 140706978965248] [client 104.23.162.16:13219] [client 104.23.162.16] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amccgzs8oMu6f6EYbxTJtAAAAUY"]
[Mon Jul 27 10:53:23.974871 2026] [:error] [pid 24106:tid 140706978965248] [client 104.23.162.16:13219] [client 104.23.162.16] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amccgzs8oMu6f6EYbxTJtAAAAUY"]
[Mon Jul 27 10:53:23.975176 2026] [:error] [pid 24106:tid 140706978965248] [client 104.23.162.16:13219] [client 104.23.162.16] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amccgzs8oMu6f6EYbxTJtAAAAUY"]
[Mon Jul 27 10:53:23.975241 2026] [:error] [pid 24106:tid 140706978965248] [client 104.23.162.16:13219] [client 104.23.162.16] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amccgzs8oMu6f6EYbxTJtAAAAUY"]
[Mon Jul 27 10:53:23.975383 2026] [:error] [pid 24106:tid 140706978965248] [client 104.23.162.16:13219] [client 104.23.162.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amccgzs8oMu6f6EYbxTJtAAAAUY"]
[Mon Jul 27 10:53:51.152041 2026] [:error] [pid 12276:tid 140706970572544] [client 172.64.198.97:13850] [client 172.64.198.97] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amccn-csEMuHmMYmk66gZAAAAEc"]
[Mon Jul 27 10:53:51.152759 2026] [:error] [pid 12276:tid 140706970572544] [client 172.64.198.97:13850] [client 172.64.198.97] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amccn-csEMuHmMYmk66gZAAAAEc"]
[Mon Jul 27 10:53:51.153245 2026] [:error] [pid 12276:tid 140706970572544] [client 172.64.198.97:13850] [client 172.64.198.97] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amccn-csEMuHmMYmk66gZAAAAEc"]
[Mon Jul 27 10:53:51.157533 2026] [:error] [pid 12276:tid 140706970572544] [client 172.64.198.97:13850] [client 172.64.198.97] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:fly_ab_uid. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: -7d64-45a7- found within REQUEST_COOKIES:fly_ab_uid: 3f25fb31-7d64-45a7-8658-cbca12052af1"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amccn-csEMuHmMYmk66gZAAAAEc"]
[Mon Jul 27 10:53:51.157697 2026] [:error] [pid 12276:tid 140706970572544] [client 172.64.198.97:13850] [client 172.64.198.97] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:user_agent. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: -telegram-clone- found within REQUEST_COOKIES:user_agent: monitor-telegram-clone-realtime/1.0"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amccn-csEMuHmMYmk66gZAAAAEc"]
[Mon Jul 27 10:54:29.964834 2026] [:error] [pid 12380:tid 140706886645504] [client 172.71.126.166:9243] [client 172.71.126.166] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amccxaaChfbWW0CZ_hohFgAAANE"]
[Mon Jul 27 10:54:29.965536 2026] [:error] [pid 12380:tid 140706886645504] [client 172.71.126.166:9243] [client 172.71.126.166] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amccxaaChfbWW0CZ_hohFgAAANE"]
[Mon Jul 27 10:54:29.965970 2026] [:error] [pid 12380:tid 140706886645504] [client 172.71.126.166:9243] [client 172.71.126.166] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amccxaaChfbWW0CZ_hohFgAAANE"]
[Mon Jul 27 10:54:29.966232 2026] [:error] [pid 12380:tid 140706886645504] [client 172.71.126.166:9243] [client 172.71.126.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amccxaaChfbWW0CZ_hohFgAAANE"]
[Mon Jul 27 10:54:30.363537 2026] [:error] [pid 24106:tid 140707004143360] [client 141.101.69.88:13906] [client 141.101.69.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amccxjs8oMu6f6EYbxTKjwAAAUM"]
[Mon Jul 27 10:54:30.364484 2026] [:error] [pid 24106:tid 140707004143360] [client 141.101.69.88:13906] [client 141.101.69.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amccxjs8oMu6f6EYbxTKjwAAAUM"]
[Mon Jul 27 10:54:30.364956 2026] [:error] [pid 24106:tid 140707004143360] [client 141.101.69.88:13906] [client 141.101.69.88] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amccxjs8oMu6f6EYbxTKjwAAAUM"]
[Mon Jul 27 10:54:30.365066 2026] [:error] [pid 24106:tid 140707004143360] [client 141.101.69.88:13906] [client 141.101.69.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amccxjs8oMu6f6EYbxTKjwAAAUM"]
[Mon Jul 27 10:54:30.365306 2026] [:error] [pid 24106:tid 140707004143360] [client 141.101.69.88:13906] [client 141.101.69.88] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amccxjs8oMu6f6EYbxTKjwAAAUM"]
[Mon Jul 27 10:54:32.842598 2026] [:error] [pid 12380:tid 140706953787136] [client 172.71.120.177:11457] [client 172.71.120.177] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccyKaChfbWW0CZ_hohIwAAAMk"]
[Mon Jul 27 10:54:32.843499 2026] [:error] [pid 12380:tid 140706953787136] [client 172.71.120.177:11457] [client 172.71.120.177] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccyKaChfbWW0CZ_hohIwAAAMk"]
[Mon Jul 27 10:54:32.843934 2026] [:error] [pid 12380:tid 140706953787136] [client 172.71.120.177:11457] [client 172.71.120.177] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccyKaChfbWW0CZ_hohIwAAAMk"]
[Mon Jul 27 10:54:32.844037 2026] [:error] [pid 12380:tid 140706953787136] [client 172.71.120.177:11457] [client 172.71.120.177] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccyKaChfbWW0CZ_hohIwAAAMk"]
[Mon Jul 27 10:54:33.881972 2026] [:error] [pid 24106:tid 140706970572544] [client 172.69.221.200:11205] [client 172.69.221.200] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccyTs8oMu6f6EYbxTKmgAAAUc"]
[Mon Jul 27 10:54:33.882654 2026] [:error] [pid 24106:tid 140706970572544] [client 172.69.221.200:11205] [client 172.69.221.200] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccyTs8oMu6f6EYbxTKmgAAAUc"]
[Mon Jul 27 10:54:33.883037 2026] [:error] [pid 24106:tid 140706970572544] [client 172.69.221.200:11205] [client 172.69.221.200] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccyTs8oMu6f6EYbxTKmgAAAUc"]
[Mon Jul 27 10:54:35.472649 2026] [:error] [pid 12275:tid 140706844681984] [client 108.162.241.85:11096] [client 108.162.241.85] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccy3FwI8r7BFXGkAuklwAAABY"]
[Mon Jul 27 10:54:35.473518 2026] [:error] [pid 12275:tid 140706844681984] [client 108.162.241.85:11096] [client 108.162.241.85] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccy3FwI8r7BFXGkAuklwAAABY"]
[Mon Jul 27 10:54:35.473956 2026] [:error] [pid 12275:tid 140706844681984] [client 108.162.241.85:11096] [client 108.162.241.85] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccy3FwI8r7BFXGkAuklwAAABY"]
[Mon Jul 27 10:54:35.474065 2026] [:error] [pid 12275:tid 140706844681984] [client 108.162.241.85:11096] [client 108.162.241.85] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amccy3FwI8r7BFXGkAuklwAAABY"]
[Mon Jul 27 10:54:36.687870 2026] [:error] [pid 12380:tid 140706903430912] [client 104.22.20.116:13322] [client 104.22.20.116] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcczKaChfbWW0CZ_hohNAAAAM8"]
[Mon Jul 27 10:54:36.687975 2026] [:error] [pid 12380:tid 140707004143360] [client 172.71.232.155:14206] [client 172.71.232.155] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcczKaChfbWW0CZ_hohNQAAAMM"]
[Mon Jul 27 10:54:36.688691 2026] [:error] [pid 12380:tid 140707004143360] [client 172.71.232.155:14206] [client 172.71.232.155] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcczKaChfbWW0CZ_hohNQAAAMM"]
[Mon Jul 27 10:54:36.688694 2026] [:error] [pid 12380:tid 140706903430912] [client 104.22.20.116:13322] [client 104.22.20.116] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcczKaChfbWW0CZ_hohNAAAAM8"]
[Mon Jul 27 10:54:36.689088 2026] [:error] [pid 12380:tid 140707004143360] [client 172.71.232.155:14206] [client 172.71.232.155] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcczKaChfbWW0CZ_hohNQAAAMM"]
[Mon Jul 27 10:54:36.689093 2026] [:error] [pid 12380:tid 140706903430912] [client 104.22.20.116:13322] [client 104.22.20.116] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcczKaChfbWW0CZ_hohNAAAAM8"]
[Mon Jul 27 10:54:36.689215 2026] [:error] [pid 12380:tid 140706903430912] [client 104.22.20.116:13322] [client 104.22.20.116] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcczKaChfbWW0CZ_hohNAAAAM8"]
[Mon Jul 27 10:54:36.689222 2026] [:error] [pid 12380:tid 140707004143360] [client 172.71.232.155:14206] [client 172.71.232.155] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcczKaChfbWW0CZ_hohNQAAAMM"]
[Mon Jul 27 10:54:36.689426 2026] [:error] [pid 12380:tid 140707004143360] [client 172.71.232.155:14206] [client 172.71.232.155] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcczKaChfbWW0CZ_hohNQAAAMM"]
[Mon Jul 27 10:54:37.307187 2026] [:error] [pid 12380:tid 140706878252800] [client 172.69.22.192:14253] [client 172.69.22.192] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcczaaChfbWW0CZ_hohQQAAANI"]
[Mon Jul 27 10:54:37.308021 2026] [:error] [pid 12380:tid 140706878252800] [client 172.69.22.192:14253] [client 172.69.22.192] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcczaaChfbWW0CZ_hohQQAAANI"]
[Mon Jul 27 10:54:37.308531 2026] [:error] [pid 12380:tid 140706878252800] [client 172.69.22.192:14253] [client 172.69.22.192] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua=Google Chrome\\x22;v=\\x22111\\x22, \\x22Not(A:Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22111"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcczaaChfbWW0CZ_hohQQAAANI"]
[Mon Jul 27 10:54:37.308623 2026] [:error] [pid 12380:tid 140706878252800] [client 172.69.22.192:14253] [client 172.69.22.192] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcczaaChfbWW0CZ_hohQQAAANI"]
[Mon Jul 27 10:54:37.701384 2026] [:error] [pid 24106:tid 140706827896576] [client 172.70.231.55:11707] [client 172.70.231.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcczTs8oMu6f6EYbxTKpgAAAVg"]
[Mon Jul 27 10:54:37.702198 2026] [:error] [pid 24106:tid 140706827896576] [client 172.70.231.55:11707] [client 172.70.231.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcczTs8oMu6f6EYbxTKpgAAAVg"]
[Mon Jul 27 10:54:37.702539 2026] [:error] [pid 24106:tid 140706827896576] [client 172.70.231.55:11707] [client 172.70.231.55] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcczTs8oMu6f6EYbxTKpgAAAVg"]
[Mon Jul 27 10:54:37.702655 2026] [:error] [pid 24106:tid 140706827896576] [client 172.70.231.55:11707] [client 172.70.231.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcczTs8oMu6f6EYbxTKpgAAAVg"]
[Mon Jul 27 10:54:38.062187 2026] [:error] [pid 24106:tid 140706945394432] [client 172.71.127.115:14154] [client 172.71.127.115] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcczjs8oMu6f6EYbxTKqAAAAUo"]
[Mon Jul 27 10:54:38.063186 2026] [:error] [pid 24106:tid 140706945394432] [client 172.71.127.115:14154] [client 172.71.127.115] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcczjs8oMu6f6EYbxTKqAAAAUo"]
[Mon Jul 27 10:54:38.063717 2026] [:error] [pid 24106:tid 140706945394432] [client 172.71.127.115:14154] [client 172.71.127.115] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcczjs8oMu6f6EYbxTKqAAAAUo"]
[Mon Jul 27 10:54:38.063951 2026] [:error] [pid 24106:tid 140706945394432] [client 172.71.127.115:14154] [client 172.71.127.115] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcczjs8oMu6f6EYbxTKqAAAAUo"]
[Mon Jul 27 10:54:38.736646 2026] [:error] [pid 12380:tid 140706970572544] [client 162.158.62.6:9664] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcczqaChfbWW0CZ_hohawAAAMc"]
[Mon Jul 27 10:54:38.737301 2026] [:error] [pid 12380:tid 140706970572544] [client 162.158.62.6:9664] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcczqaChfbWW0CZ_hohawAAAMc"]
[Mon Jul 27 10:54:38.737709 2026] [:error] [pid 12380:tid 140706970572544] [client 162.158.62.6:9664] [client 162.158.62.6] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcczqaChfbWW0CZ_hohawAAAMc"]
[Mon Jul 27 10:54:38.737784 2026] [:error] [pid 12380:tid 140706970572544] [client 162.158.62.6:9664] [client 162.158.62.6] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcczqaChfbWW0CZ_hohawAAAMc"]
[Mon Jul 27 10:54:39.039479 2026] [:error] [pid 24106:tid 140706920216320] [client 162.158.62.6:11675] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/console/"] [unique_id "amcczzs8oMu6f6EYbxTKrwAAAU0"]
[Mon Jul 27 10:54:39.040263 2026] [:error] [pid 24106:tid 140706920216320] [client 162.158.62.6:11675] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/console/"] [unique_id "amcczzs8oMu6f6EYbxTKrwAAAU0"]
[Mon Jul 27 10:54:39.040644 2026] [:error] [pid 24106:tid 140706920216320] [client 162.158.62.6:11675] [client 162.158.62.6] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/console/"] [unique_id "amcczzs8oMu6f6EYbxTKrwAAAU0"]
[Mon Jul 27 10:54:39.040728 2026] [:error] [pid 24106:tid 140706920216320] [client 162.158.62.6:11675] [client 162.158.62.6] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/console/"] [unique_id "amcczzs8oMu6f6EYbxTKrwAAAU0"]
[Mon Jul 27 10:54:39.904817 2026] [:error] [pid 12380:tid 140706911823616] [client 104.23.251.17:9281] [client 104.23.251.17] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amccz6aChfbWW0CZ_hohmgAAAM4"]
[Mon Jul 27 10:54:39.905516 2026] [:error] [pid 12380:tid 140706911823616] [client 104.23.251.17:9281] [client 104.23.251.17] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amccz6aChfbWW0CZ_hohmgAAAM4"]
[Mon Jul 27 10:54:39.905974 2026] [:error] [pid 12380:tid 140706911823616] [client 104.23.251.17:9281] [client 104.23.251.17] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua=Google Chrome\\x22;v=\\x22111\\x22, \\x22Not(A:Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22111"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amccz6aChfbWW0CZ_hohmgAAAM4"]
[Mon Jul 27 10:54:39.906040 2026] [:error] [pid 12380:tid 140706911823616] [client 104.23.251.17:9281] [client 104.23.251.17] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amccz6aChfbWW0CZ_hohmgAAAM4"]
[Mon Jul 27 10:54:40.042272 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.203.34:11244] [client 172.71.203.34] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/server"] [unique_id "amcc0JhXfYDIcpslIWOwzQAAAYs"]
[Mon Jul 27 10:54:40.043390 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.203.34:11244] [client 172.71.203.34] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/server"] [unique_id "amcc0JhXfYDIcpslIWOwzQAAAYs"]
[Mon Jul 27 10:54:40.043887 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.203.34:11244] [client 172.71.203.34] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/server"] [unique_id "amcc0JhXfYDIcpslIWOwzQAAAYs"]
[Mon Jul 27 10:54:40.044047 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.203.34:11244] [client 172.71.203.34] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/server"] [unique_id "amcc0JhXfYDIcpslIWOwzQAAAYs"]
[Mon Jul 27 10:54:41.316085 2026] [:error] [pid 12380:tid 140707004143360] [client 104.23.187.198:9925] [client 104.23.187.198] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/server-status"] [unique_id "amcc0aaChfbWW0CZ_hohqwAAAMM"]
[Mon Jul 27 10:54:41.320332 2026] [authz_host:error] [pid 12380:tid 140707004143360] [client 104.23.187.198:9925] AH01753: access check of 'localhost' to /server-status failed, reason: unable to get the remote host name
[Mon Jul 27 10:54:41.320414 2026] [authz_core:error] [pid 12380:tid 140707004143360] [client 104.23.187.198:9925] AH01630: client denied by server configuration: /home/sbfconsu/sbf-consultancy.com/server-status
[Mon Jul 27 10:54:41.928426 2026] [:error] [pid 24106:tid 140706978965248] [client 104.23.239.32:10186] [client 104.23.239.32] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc0Ts8oMu6f6EYbxTK0gAAAUY"]
[Mon Jul 27 10:54:41.929167 2026] [:error] [pid 24106:tid 140706978965248] [client 104.23.239.32:10186] [client 104.23.239.32] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc0Ts8oMu6f6EYbxTK0gAAAUY"]
[Mon Jul 27 10:54:41.929544 2026] [:error] [pid 24106:tid 140706978965248] [client 104.23.239.32:10186] [client 104.23.239.32] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc0Ts8oMu6f6EYbxTK0gAAAUY"]
[Mon Jul 27 10:54:41.929670 2026] [:error] [pid 24106:tid 140706978965248] [client 104.23.239.32:10186] [client 104.23.239.32] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc0Ts8oMu6f6EYbxTK0gAAAUY"]
[Mon Jul 27 10:54:43.103814 2026] [:error] [pid 24106:tid 140706962179840] [client 172.71.172.131:10107] [client 172.71.172.131] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/console/"] [unique_id "amcc0zs8oMu6f6EYbxTK3AAAAUg"]
[Mon Jul 27 10:54:43.104742 2026] [:error] [pid 24106:tid 140706962179840] [client 172.71.172.131:10107] [client 172.71.172.131] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/console/"] [unique_id "amcc0zs8oMu6f6EYbxTK3AAAAUg"]
[Mon Jul 27 10:54:43.105171 2026] [:error] [pid 24106:tid 140706962179840] [client 172.71.172.131:10107] [client 172.71.172.131] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/console/"] [unique_id "amcc0zs8oMu6f6EYbxTK3AAAAUg"]
[Mon Jul 27 10:54:43.105278 2026] [:error] [pid 24106:tid 140706962179840] [client 172.71.172.131:10107] [client 172.71.172.131] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/console/"] [unique_id "amcc0zs8oMu6f6EYbxTK3AAAAUg"]
[Mon Jul 27 10:54:43.741353 2026] [:error] [pid 12380:tid 140706836289280] [client 172.70.111.98:12644] [client 172.70.111.98] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/about"] [unique_id "amcc06aChfbWW0CZ_hohswAAANc"]
[Mon Jul 27 10:54:43.742228 2026] [:error] [pid 12380:tid 140706836289280] [client 172.70.111.98:12644] [client 172.70.111.98] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/about"] [unique_id "amcc06aChfbWW0CZ_hohswAAANc"]
[Mon Jul 27 10:54:43.742629 2026] [:error] [pid 12380:tid 140706836289280] [client 172.70.111.98:12644] [client 172.70.111.98] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/about"] [unique_id "amcc06aChfbWW0CZ_hohswAAANc"]
[Mon Jul 27 10:54:43.742710 2026] [:error] [pid 12380:tid 140706836289280] [client 172.70.111.98:12644] [client 172.70.111.98] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/about"] [unique_id "amcc06aChfbWW0CZ_hohswAAANc"]
[Mon Jul 27 10:54:43.914819 2026] [:error] [pid 24106:tid 140706836289280] [client 162.158.95.178:12071] [client 162.158.95.178] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/server"] [unique_id "amcc0zs8oMu6f6EYbxTK3wAAAVc"]
[Mon Jul 27 10:54:43.915650 2026] [:error] [pid 24106:tid 140706836289280] [client 162.158.95.178:12071] [client 162.158.95.178] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/server"] [unique_id "amcc0zs8oMu6f6EYbxTK3wAAAVc"]
[Mon Jul 27 10:54:43.916588 2026] [:error] [pid 24106:tid 140706836289280] [client 162.158.95.178:12071] [client 162.158.95.178] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/server"] [unique_id "amcc0zs8oMu6f6EYbxTK3wAAAVc"]
[Mon Jul 27 10:54:43.916741 2026] [:error] [pid 24106:tid 140706836289280] [client 162.158.95.178:12071] [client 162.158.95.178] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/server"] [unique_id "amcc0zs8oMu6f6EYbxTK3wAAAVc"]
[Mon Jul 27 10:54:44.506820 2026] [:error] [pid 12380:tid 140706827896576] [client 162.158.158.214:14325] [client 162.158.158.214] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcc1KaChfbWW0CZ_hohtwAAANg"]
[Mon Jul 27 10:54:44.507790 2026] [:error] [pid 12380:tid 140706827896576] [client 162.158.158.214:14325] [client 162.158.158.214] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcc1KaChfbWW0CZ_hohtwAAANg"]
[Mon Jul 27 10:54:44.508215 2026] [:error] [pid 12380:tid 140706827896576] [client 162.158.158.214:14325] [client 162.158.158.214] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcc1KaChfbWW0CZ_hohtwAAANg"]
[Mon Jul 27 10:54:44.508322 2026] [:error] [pid 12380:tid 140706827896576] [client 162.158.158.214:14325] [client 162.158.158.214] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcc1KaChfbWW0CZ_hohtwAAANg"]
[Mon Jul 27 10:54:44.967758 2026] [:error] [pid 24106:tid 140706827896576] [client 172.71.148.14:10990] [client 172.71.148.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/server-status"] [unique_id "amcc1Ds8oMu6f6EYbxTK6QAAAVg"]
[Mon Jul 27 10:54:44.973804 2026] [authz_host:error] [pid 24106:tid 140706827896576] [client 172.71.148.14:10990] AH01753: access check of 'localhost' to /server-status failed, reason: unable to get the remote host name
[Mon Jul 27 10:54:44.973852 2026] [authz_core:error] [pid 24106:tid 140706827896576] [client 172.71.148.14:10990] AH01630: client denied by server configuration: /home/sbfconsu/sbf-consultancy.com/server-status
[Mon Jul 27 10:54:46.169190 2026] [:error] [pid 12276:tid 140706861467392] [client 172.71.164.93:12970] [client 172.71.164.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/about"] [unique_id "amcc1ucsEMuHmMYmk66gawAAAFQ"]
[Mon Jul 27 10:54:46.170091 2026] [:error] [pid 12276:tid 140706861467392] [client 172.71.164.93:12970] [client 172.71.164.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/about"] [unique_id "amcc1ucsEMuHmMYmk66gawAAAFQ"]
[Mon Jul 27 10:54:46.170544 2026] [:error] [pid 12276:tid 140706861467392] [client 172.71.164.93:12970] [client 172.71.164.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/about"] [unique_id "amcc1ucsEMuHmMYmk66gawAAAFQ"]
[Mon Jul 27 10:54:46.170705 2026] [:error] [pid 12276:tid 140706861467392] [client 172.71.164.93:12970] [client 172.71.164.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/about"] [unique_id "amcc1ucsEMuHmMYmk66gawAAAFQ"]
[Mon Jul 27 10:54:46.202101 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.62.6:11556] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc1qaChfbWW0CZ_hohuwAAAMA"]
[Mon Jul 27 10:54:46.202941 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.62.6:11556] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc1qaChfbWW0CZ_hohuwAAAMA"]
[Mon Jul 27 10:54:46.203324 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.62.6:11556] [client 162.158.62.6] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc1qaChfbWW0CZ_hohuwAAAMA"]
[Mon Jul 27 10:54:46.203423 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.62.6:11556] [client 162.158.62.6] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc1qaChfbWW0CZ_hohuwAAAMA"]
[Mon Jul 27 10:54:46.796212 2026] [:error] [pid 12276:tid 140706953787136] [client 172.71.164.93:12970] [client 172.71.164.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcc1ucsEMuHmMYmk66gbAAAAEk"]
[Mon Jul 27 10:54:46.796967 2026] [:error] [pid 12276:tid 140706953787136] [client 172.71.164.93:12970] [client 172.71.164.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcc1ucsEMuHmMYmk66gbAAAAEk"]
[Mon Jul 27 10:54:46.797324 2026] [:error] [pid 12276:tid 140706953787136] [client 172.71.164.93:12970] [client 172.71.164.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcc1ucsEMuHmMYmk66gbAAAAEk"]
[Mon Jul 27 10:54:46.797403 2026] [:error] [pid 12276:tid 140706953787136] [client 172.71.164.93:12970] [client 172.71.164.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/login.action"] [unique_id "amcc1ucsEMuHmMYmk66gbAAAAEk"]
[Mon Jul 27 10:54:46.893403 2026] [:error] [pid 17228:tid 140706861467392] [client 172.71.203.35:12670] [client 172.71.203.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcc1pjBQLO4t9VCDfpDrgAAARQ"]
[Mon Jul 27 10:54:46.894393 2026] [:error] [pid 17228:tid 140706861467392] [client 172.71.203.35:12670] [client 172.71.203.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcc1pjBQLO4t9VCDfpDrgAAARQ"]
[Mon Jul 27 10:54:46.894933 2026] [:error] [pid 17228:tid 140706861467392] [client 172.71.203.35:12670] [client 172.71.203.35] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcc1pjBQLO4t9VCDfpDrgAAARQ"]
[Mon Jul 27 10:54:46.895064 2026] [:error] [pid 17228:tid 140706861467392] [client 172.71.203.35:12670] [client 172.71.203.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcc1pjBQLO4t9VCDfpDrgAAARQ"]
[Mon Jul 27 10:54:47.495858 2026] [:error] [pid 12380:tid 140706827896576] [client 162.158.155.193:14029] [client 162.158.155.193] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcc16aChfbWW0CZ_hohxAAAANg"]
[Mon Jul 27 10:54:47.496687 2026] [:error] [pid 12380:tid 140706827896576] [client 162.158.155.193:14029] [client 162.158.155.193] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcc16aChfbWW0CZ_hohxAAAANg"]
[Mon Jul 27 10:54:47.497063 2026] [:error] [pid 12380:tid 140706827896576] [client 162.158.155.193:14029] [client 162.158.155.193] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcc16aChfbWW0CZ_hohxAAAANg"]
[Mon Jul 27 10:54:47.497173 2026] [:error] [pid 12380:tid 140706827896576] [client 162.158.155.193:14029] [client 162.158.155.193] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcc16aChfbWW0CZ_hohxAAAANg"]
[Mon Jul 27 10:54:47.891202 2026] [:error] [pid 24106:tid 140706911823616] [client 172.69.150.42:11193] [client 172.69.150.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc1zs8oMu6f6EYbxTLEAAAAU4"]
[Mon Jul 27 10:54:47.892169 2026] [:error] [pid 24106:tid 140706911823616] [client 172.69.150.42:11193] [client 172.69.150.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc1zs8oMu6f6EYbxTLEAAAAU4"]
[Mon Jul 27 10:54:47.892648 2026] [:error] [pid 24106:tid 140706911823616] [client 172.69.150.42:11193] [client 172.69.150.42] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc1zs8oMu6f6EYbxTLEAAAAU4"]
[Mon Jul 27 10:54:47.892752 2026] [:error] [pid 24106:tid 140706911823616] [client 172.69.150.42:11193] [client 172.69.150.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc1zs8oMu6f6EYbxTLEAAAAU4"]
[Mon Jul 27 10:54:47.988842 2026] [:error] [pid 12380:tid 140706962179840] [client 172.71.144.142:12969] [client 172.71.144.142] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcc16aChfbWW0CZ_hohyAAAAMg"]
[Mon Jul 27 10:54:47.989513 2026] [:error] [pid 12380:tid 140706962179840] [client 172.71.144.142:12969] [client 172.71.144.142] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcc16aChfbWW0CZ_hohyAAAAMg"]
[Mon Jul 27 10:54:47.989852 2026] [:error] [pid 12380:tid 140706962179840] [client 172.71.144.142:12969] [client 172.71.144.142] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcc16aChfbWW0CZ_hohyAAAAMg"]
[Mon Jul 27 10:54:47.989926 2026] [:error] [pid 12380:tid 140706962179840] [client 172.71.144.142:12969] [client 172.71.144.142] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_whm/login"] [unique_id "amcc16aChfbWW0CZ_hohyAAAAMg"]
[Mon Jul 27 10:54:48.090334 2026] [:error] [pid 12380:tid 140706937001728] [client 172.71.144.142:12969] [client 172.71.144.142] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcc2KaChfbWW0CZ_hohywAAAMs"]
[Mon Jul 27 10:54:48.091102 2026] [:error] [pid 12380:tid 140706937001728] [client 172.71.144.142:12969] [client 172.71.144.142] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcc2KaChfbWW0CZ_hohywAAAMs"]
[Mon Jul 27 10:54:48.091383 2026] [:error] [pid 12380:tid 140706937001728] [client 172.71.144.142:12969] [client 172.71.144.142] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcc2KaChfbWW0CZ_hohywAAAMs"]
[Mon Jul 27 10:54:48.091464 2026] [:error] [pid 12380:tid 140706937001728] [client 172.71.144.142:12969] [client 172.71.144.142] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/___proxy_subdomain_cpanel"] [unique_id "amcc2KaChfbWW0CZ_hohywAAAMs"]
[Mon Jul 27 10:54:48.401053 2026] [:error] [pid 12380:tid 140706970572544] [client 172.70.111.98:12644] [client 172.70.111.98] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/v2/_catalog"] [unique_id "amcc2KaChfbWW0CZ_hohzgAAAMc"]
[Mon Jul 27 10:54:48.402172 2026] [:error] [pid 12380:tid 140706970572544] [client 172.70.111.98:12644] [client 172.70.111.98] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/v2/_catalog"] [unique_id "amcc2KaChfbWW0CZ_hohzgAAAMc"]
[Mon Jul 27 10:54:48.402766 2026] [:error] [pid 12380:tid 140706970572544] [client 172.70.111.98:12644] [client 172.70.111.98] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/v2/_catalog"] [unique_id "amcc2KaChfbWW0CZ_hohzgAAAMc"]
[Mon Jul 27 10:54:48.822993 2026] [:error] [pid 12380:tid 140706895038208] [client 172.70.243.154:13058] [client 172.70.243.154] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/v2/_catalog"] [unique_id "amcc2KaChfbWW0CZ_hohzwAAANA"]
[Mon Jul 27 10:54:48.823820 2026] [:error] [pid 12380:tid 140706895038208] [client 172.70.243.154:13058] [client 172.70.243.154] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/v2/_catalog"] [unique_id "amcc2KaChfbWW0CZ_hohzwAAANA"]
[Mon Jul 27 10:54:48.824348 2026] [:error] [pid 12380:tid 140706895038208] [client 172.70.243.154:13058] [client 172.70.243.154] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/v2/_catalog"] [unique_id "amcc2KaChfbWW0CZ_hohzwAAANA"]
[Mon Jul 27 10:54:49.353086 2026] [:error] [pid 12380:tid 140706928609024] [client 172.70.231.55:11470] [client 172.70.231.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcc2aaChfbWW0CZ_hoh0QAAAMw"]
[Mon Jul 27 10:54:49.353760 2026] [:error] [pid 12380:tid 140706928609024] [client 172.70.231.55:11470] [client 172.70.231.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcc2aaChfbWW0CZ_hoh0QAAAMw"]
[Mon Jul 27 10:54:49.354238 2026] [:error] [pid 12380:tid 140706928609024] [client 172.70.231.55:11470] [client 172.70.231.55] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcc2aaChfbWW0CZ_hoh0QAAAMw"]
[Mon Jul 27 10:54:49.354338 2026] [:error] [pid 12380:tid 140706928609024] [client 172.70.231.55:11470] [client 172.70.231.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcc2aaChfbWW0CZ_hoh0QAAAMw"]
[Mon Jul 27 10:54:49.354583 2026] [:error] [pid 12380:tid 140706928609024] [client 172.70.231.55:11470] [client 172.70.231.55] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcc2aaChfbWW0CZ_hoh0QAAAMw"]
[Mon Jul 27 10:54:49.927573 2026] [:error] [pid 12276:tid 140707004143360] [client 172.71.164.93:12970] [client 172.71.164.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcc2ecsEMuHmMYmk66gbQAAAEM"]
[Mon Jul 27 10:54:49.928452 2026] [:error] [pid 12276:tid 140707004143360] [client 172.71.164.93:12970] [client 172.71.164.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcc2ecsEMuHmMYmk66gbQAAAEM"]
[Mon Jul 27 10:54:49.928899 2026] [:error] [pid 12276:tid 140707004143360] [client 172.71.164.93:12970] [client 172.71.164.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcc2ecsEMuHmMYmk66gbQAAAEM"]
[Mon Jul 27 10:54:49.929013 2026] [:error] [pid 12276:tid 140707004143360] [client 172.71.164.93:12970] [client 172.71.164.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcc2ecsEMuHmMYmk66gbQAAAEM"]
[Mon Jul 27 10:54:49.929274 2026] [:error] [pid 12276:tid 140707004143360] [client 172.71.164.93:12970] [client 172.71.164.93] ModSecurity: Warning. Matched phrase "/.DS_Store" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.DS_Store found within REQUEST_FILENAME: /.ds_store"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.DS_Store"] [unique_id "amcc2ecsEMuHmMYmk66gbQAAAEM"]
[Mon Jul 27 10:54:50.617793 2026] [:error] [pid 17228:tid 140706937001728] [client 104.23.190.196:11792] [client 104.23.190.196] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcc2pjBQLO4t9VCDfpDrwAAAQs"]
[Mon Jul 27 10:54:50.618881 2026] [:error] [pid 17228:tid 140706937001728] [client 104.23.190.196:11792] [client 104.23.190.196] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcc2pjBQLO4t9VCDfpDrwAAAQs"]
[Mon Jul 27 10:54:50.619478 2026] [:error] [pid 17228:tid 140706937001728] [client 104.23.190.196:11792] [client 104.23.190.196] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcc2pjBQLO4t9VCDfpDrwAAAQs"]
[Mon Jul 27 10:54:50.619686 2026] [:error] [pid 17228:tid 140706937001728] [client 104.23.190.196:11792] [client 104.23.190.196] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcc2pjBQLO4t9VCDfpDrwAAAQs"]
[Mon Jul 27 10:54:50.620013 2026] [:error] [pid 17228:tid 140706937001728] [client 104.23.190.196:11792] [client 104.23.190.196] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcc2pjBQLO4t9VCDfpDrwAAAQs"]
[Mon Jul 27 10:54:50.951671 2026] [:error] [pid 12380:tid 140706911823616] [client 162.158.88.144:11722] [client 162.158.88.144] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcc2qaChfbWW0CZ_hoh3QAAAM4"]
[Mon Jul 27 10:54:50.952357 2026] [:error] [pid 12380:tid 140706911823616] [client 162.158.88.144:11722] [client 162.158.88.144] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcc2qaChfbWW0CZ_hoh3QAAAM4"]
[Mon Jul 27 10:54:50.952929 2026] [:error] [pid 12380:tid 140706911823616] [client 162.158.88.144:11722] [client 162.158.88.144] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcc2qaChfbWW0CZ_hoh3QAAAM4"]
[Mon Jul 27 10:54:50.953179 2026] [:error] [pid 12380:tid 140706911823616] [client 162.158.88.144:11722] [client 162.158.88.144] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcc2qaChfbWW0CZ_hoh3QAAAM4"]
[Mon Jul 27 10:54:51.196073 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.148.14:12629] [client 172.71.148.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcc25hXfYDIcpslIWOw1wAAAYs"]
[Mon Jul 27 10:54:51.196730 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.148.14:12629] [client 172.71.148.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcc25hXfYDIcpslIWOw1wAAAYs"]
[Mon Jul 27 10:54:51.197038 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.148.14:12629] [client 172.71.148.14] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcc25hXfYDIcpslIWOw1wAAAYs"]
[Mon Jul 27 10:54:51.197132 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.148.14:12629] [client 172.71.148.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcc25hXfYDIcpslIWOw1wAAAYs"]
[Mon Jul 27 10:54:51.197318 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.148.14:12629] [client 172.71.148.14] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amcc25hXfYDIcpslIWOw1wAAAYs"]
[Mon Jul 27 10:54:52.876365 2026] [:error] [pid 12275:tid 140706836289280] [client 104.23.187.198:14220] [client 104.23.187.198] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcc3HFwI8r7BFXGkAuksAAAABc"]
[Mon Jul 27 10:54:52.877118 2026] [:error] [pid 12275:tid 140706836289280] [client 104.23.187.198:14220] [client 104.23.187.198] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcc3HFwI8r7BFXGkAuksAAAABc"]
[Mon Jul 27 10:54:52.877508 2026] [:error] [pid 12275:tid 140706836289280] [client 104.23.187.198:14220] [client 104.23.187.198] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcc3HFwI8r7BFXGkAuksAAAABc"]
[Mon Jul 27 10:54:52.877645 2026] [:error] [pid 12275:tid 140706836289280] [client 104.23.187.198:14220] [client 104.23.187.198] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcc3HFwI8r7BFXGkAuksAAAABc"]
[Mon Jul 27 10:54:53.182134 2026] [:error] [pid 24106:tid 140706937001728] [client 172.70.247.99:11772] [client 172.70.247.99] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcc3Ts8oMu6f6EYbxTLHQAAAUs"]
[Mon Jul 27 10:54:53.182905 2026] [:error] [pid 24106:tid 140706937001728] [client 172.70.247.99:11772] [client 172.70.247.99] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcc3Ts8oMu6f6EYbxTLHQAAAUs"]
[Mon Jul 27 10:54:53.183369 2026] [:error] [pid 24106:tid 140706937001728] [client 172.70.247.99:11772] [client 172.70.247.99] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcc3Ts8oMu6f6EYbxTLHQAAAUs"]
[Mon Jul 27 10:54:53.183527 2026] [:error] [pid 24106:tid 140706937001728] [client 172.70.247.99:11772] [client 172.70.247.99] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"] [unique_id "amcc3Ts8oMu6f6EYbxTLHQAAAUs"]
[Mon Jul 27 10:54:54.609209 2026] [:error] [pid 12275:tid 140706978965248] [client 104.23.187.198:14220] [client 104.23.187.198] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcc3nFwI8r7BFXGkAuktAAAAAY"]
[Mon Jul 27 10:54:54.609937 2026] [:error] [pid 12275:tid 140706978965248] [client 104.23.187.198:14220] [client 104.23.187.198] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcc3nFwI8r7BFXGkAuktAAAAAY"]
[Mon Jul 27 10:54:54.610233 2026] [:error] [pid 12275:tid 140706978965248] [client 104.23.187.198:14220] [client 104.23.187.198] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcc3nFwI8r7BFXGkAuktAAAAAY"]
[Mon Jul 27 10:54:54.610298 2026] [:error] [pid 12275:tid 140706978965248] [client 104.23.187.198:14220] [client 104.23.187.198] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcc3nFwI8r7BFXGkAuktAAAAAY"]
[Mon Jul 27 10:54:54.610473 2026] [:error] [pid 12275:tid 140706978965248] [client 104.23.187.198:14220] [client 104.23.187.198] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcc3nFwI8r7BFXGkAuktAAAAAY"]
[Mon Jul 27 10:54:55.064485 2026] [:error] [pid 12380:tid 140706937001728] [client 172.69.150.42:9657] [client 172.69.150.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcc36aChfbWW0CZ_hoiRgAAAMs"]
[Mon Jul 27 10:54:55.065370 2026] [:error] [pid 12380:tid 140706937001728] [client 172.69.150.42:9657] [client 172.69.150.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcc36aChfbWW0CZ_hoiRgAAAMs"]
[Mon Jul 27 10:54:55.065827 2026] [:error] [pid 12380:tid 140706937001728] [client 172.69.150.42:9657] [client 172.69.150.42] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcc36aChfbWW0CZ_hoiRgAAAMs"]
[Mon Jul 27 10:54:55.065937 2026] [:error] [pid 12380:tid 140706937001728] [client 172.69.150.42:9657] [client 172.69.150.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcc36aChfbWW0CZ_hoiRgAAAMs"]
[Mon Jul 27 10:54:55.066182 2026] [:error] [pid 12380:tid 140706937001728] [client 172.69.150.42:9657] [client 172.69.150.42] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcc36aChfbWW0CZ_hoiRgAAAMs"]
[Mon Jul 27 10:54:55.487460 2026] [:error] [pid 12275:tid 140706911823616] [client 104.23.187.198:14220] [client 104.23.187.198] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcc33FwI8r7BFXGkAuktQAAAA4"]
[Mon Jul 27 10:54:55.488144 2026] [:error] [pid 12275:tid 140706911823616] [client 104.23.187.198:14220] [client 104.23.187.198] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcc33FwI8r7BFXGkAuktQAAAA4"]
[Mon Jul 27 10:54:55.488376 2026] [:error] [pid 12275:tid 140706911823616] [client 104.23.187.198:14220] [client 104.23.187.198] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcc33FwI8r7BFXGkAuktQAAAA4"]
[Mon Jul 27 10:54:55.488651 2026] [:error] [pid 12275:tid 140706911823616] [client 104.23.187.198:14220] [client 104.23.187.198] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcc33FwI8r7BFXGkAuktQAAAA4"]
[Mon Jul 27 10:54:56.075387 2026] [:error] [pid 24106:tid 140706836289280] [client 162.158.155.194:12773] [client 162.158.155.194] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api"] [unique_id "amcc4Ds8oMu6f6EYbxTLJwAAAVc"]
[Mon Jul 27 10:54:56.076019 2026] [:error] [pid 24106:tid 140706836289280] [client 162.158.155.194:12773] [client 162.158.155.194] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api"] [unique_id "amcc4Ds8oMu6f6EYbxTLJwAAAVc"]
[Mon Jul 27 10:54:56.076251 2026] [:error] [pid 24106:tid 140706836289280] [client 162.158.155.194:12773] [client 162.158.155.194] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api"] [unique_id "amcc4Ds8oMu6f6EYbxTLJwAAAVc"]
[Mon Jul 27 10:54:56.076444 2026] [:error] [pid 24106:tid 140706836289280] [client 162.158.155.194:12773] [client 162.158.155.194] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api"] [unique_id "amcc4Ds8oMu6f6EYbxTLJwAAAVc"]
[Mon Jul 27 10:54:56.172854 2026] [:error] [pid 12380:tid 140706895038208] [client 172.71.144.143:10565] [client 172.71.144.143] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcc4KaChfbWW0CZ_hoiSgAAANA"]
[Mon Jul 27 10:54:56.173463 2026] [:error] [pid 12380:tid 140706895038208] [client 172.71.144.143:10565] [client 172.71.144.143] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcc4KaChfbWW0CZ_hoiSgAAANA"]
[Mon Jul 27 10:54:56.173737 2026] [:error] [pid 12380:tid 140706895038208] [client 172.71.144.143:10565] [client 172.71.144.143] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcc4KaChfbWW0CZ_hoiSgAAANA"]
[Mon Jul 27 10:54:56.173982 2026] [:error] [pid 12380:tid 140706895038208] [client 172.71.144.143:10565] [client 172.71.144.143] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/graphql"] [unique_id "amcc4KaChfbWW0CZ_hoiSgAAANA"]
[Mon Jul 27 10:54:56.480472 2026] [:error] [pid 12380:tid 140706928609024] [client 172.71.164.92:11770] [client 172.71.164.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api"] [unique_id "amcc4KaChfbWW0CZ_hoiTAAAAMw"]
[Mon Jul 27 10:54:56.481280 2026] [:error] [pid 12380:tid 140706928609024] [client 172.71.164.92:11770] [client 172.71.164.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api"] [unique_id "amcc4KaChfbWW0CZ_hoiTAAAAMw"]
[Mon Jul 27 10:54:56.481566 2026] [:error] [pid 12380:tid 140706928609024] [client 172.71.164.92:11770] [client 172.71.164.92] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api"] [unique_id "amcc4KaChfbWW0CZ_hoiTAAAAMw"]
[Mon Jul 27 10:54:56.482001 2026] [:error] [pid 12380:tid 140706928609024] [client 172.71.164.92:11770] [client 172.71.164.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api"] [unique_id "amcc4KaChfbWW0CZ_hoiTAAAAMw"]
[Mon Jul 27 10:54:56.567497 2026] [:error] [pid 24106:tid 140706987357952] [client 172.70.111.98:13934] [client 172.70.111.98] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcc4Ds8oMu6f6EYbxTLLQAAAUU"]
[Mon Jul 27 10:54:56.568304 2026] [:error] [pid 24106:tid 140706987357952] [client 172.70.111.98:13934] [client 172.70.111.98] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcc4Ds8oMu6f6EYbxTLLQAAAUU"]
[Mon Jul 27 10:54:56.568623 2026] [:error] [pid 24106:tid 140706987357952] [client 172.70.111.98:13934] [client 172.70.111.98] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcc4Ds8oMu6f6EYbxTLLQAAAUU"]
[Mon Jul 27 10:54:56.568929 2026] [:error] [pid 24106:tid 140706987357952] [client 172.70.111.98:13934] [client 172.70.111.98] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcc4Ds8oMu6f6EYbxTLLQAAAUU"]
[Mon Jul 27 10:54:56.728108 2026] [:error] [pid 21545:tid 140706978965248] [client 172.64.217.182:12722] [client 172.64.217.182] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcc4JhXfYDIcpslIWOw2gAAAYY"]
[Mon Jul 27 10:54:56.728774 2026] [:error] [pid 21545:tid 140706978965248] [client 172.64.217.182:12722] [client 172.64.217.182] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcc4JhXfYDIcpslIWOw2gAAAYY"]
[Mon Jul 27 10:54:56.729263 2026] [:error] [pid 21545:tid 140706978965248] [client 172.64.217.182:12722] [client 172.64.217.182] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua=Google Chrome\\x22;v=\\x22111\\x22, \\x22Not(A:Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22111"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcc4JhXfYDIcpslIWOw2gAAAYY"]
[Mon Jul 27 10:54:56.729354 2026] [:error] [pid 21545:tid 140706978965248] [client 172.64.217.182:12722] [client 172.64.217.182] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcc4JhXfYDIcpslIWOw2gAAAYY"]
[Mon Jul 27 10:54:56.856939 2026] [:error] [pid 12380:tid 140706844681984] [client 172.69.150.42:9657] [client 172.69.150.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcc4KaChfbWW0CZ_hoiTQAAANY"]
[Mon Jul 27 10:54:56.857681 2026] [:error] [pid 12380:tid 140706844681984] [client 172.69.150.42:9657] [client 172.69.150.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcc4KaChfbWW0CZ_hoiTQAAANY"]
[Mon Jul 27 10:54:56.857979 2026] [:error] [pid 12380:tid 140706844681984] [client 172.69.150.42:9657] [client 172.69.150.42] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcc4KaChfbWW0CZ_hoiTQAAANY"]
[Mon Jul 27 10:54:56.858212 2026] [:error] [pid 12380:tid 140706844681984] [client 172.69.150.42:9657] [client 172.69.150.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amcc4KaChfbWW0CZ_hoiTQAAANY"]
[Mon Jul 27 10:54:57.184869 2026] [:error] [pid 24106:tid 140706869860096] [client 104.22.123.71:10862] [client 104.22.123.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcc4Ts8oMu6f6EYbxTLMQAAAVM"]
[Mon Jul 27 10:54:57.185511 2026] [:error] [pid 24106:tid 140706869860096] [client 104.22.123.71:10862] [client 104.22.123.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcc4Ts8oMu6f6EYbxTLMQAAAVM"]
[Mon Jul 27 10:54:57.185766 2026] [:error] [pid 24106:tid 140706869860096] [client 104.22.123.71:10862] [client 104.22.123.71] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcc4Ts8oMu6f6EYbxTLMQAAAVM"]
[Mon Jul 27 10:54:57.186040 2026] [:error] [pid 24106:tid 140706869860096] [client 104.22.123.71:10862] [client 104.22.123.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcc4Ts8oMu6f6EYbxTLMQAAAVM"]
[Mon Jul 27 10:54:57.339364 2026] [:error] [pid 24106:tid 140707004143360] [client 104.22.123.71:10862] [client 104.22.123.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcc4Ts8oMu6f6EYbxTLMgAAAUM"]
[Mon Jul 27 10:54:57.340253 2026] [:error] [pid 24106:tid 140707004143360] [client 104.22.123.71:10862] [client 104.22.123.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcc4Ts8oMu6f6EYbxTLMgAAAUM"]
[Mon Jul 27 10:54:57.340564 2026] [:error] [pid 24106:tid 140707004143360] [client 104.22.123.71:10862] [client 104.22.123.71] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcc4Ts8oMu6f6EYbxTLMgAAAUM"]
[Mon Jul 27 10:54:57.340877 2026] [:error] [pid 24106:tid 140707004143360] [client 104.22.123.71:10862] [client 104.22.123.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcc4Ts8oMu6f6EYbxTLMgAAAUM"]
[Mon Jul 27 10:54:57.815141 2026] [:error] [pid 24106:tid 140706970572544] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcc4Ts8oMu6f6EYbxTLNgAAAUc"]
[Mon Jul 27 10:54:57.815914 2026] [:error] [pid 24106:tid 140706970572544] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcc4Ts8oMu6f6EYbxTLNgAAAUc"]
[Mon Jul 27 10:54:57.816156 2026] [:error] [pid 24106:tid 140706970572544] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcc4Ts8oMu6f6EYbxTLNgAAAUc"]
[Mon Jul 27 10:54:57.816411 2026] [:error] [pid 24106:tid 140706970572544] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/api"] [unique_id "amcc4Ts8oMu6f6EYbxTLNgAAAUc"]
[Mon Jul 27 10:54:58.083757 2026] [:error] [pid 12275:tid 140706878252800] [client 172.70.248.24:13897] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcc4nFwI8r7BFXGkAukuQAAABI"]
[Mon Jul 27 10:54:58.084347 2026] [:error] [pid 12275:tid 140706878252800] [client 172.70.248.24:13897] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcc4nFwI8r7BFXGkAukuQAAABI"]
[Mon Jul 27 10:54:58.084671 2026] [:error] [pid 12275:tid 140706878252800] [client 172.70.248.24:13897] [client 172.70.248.24] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcc4nFwI8r7BFXGkAukuQAAABI"]
[Mon Jul 27 10:54:58.084741 2026] [:error] [pid 12275:tid 140706878252800] [client 172.70.248.24:13897] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcc4nFwI8r7BFXGkAukuQAAABI"]
[Mon Jul 27 10:54:58.367850 2026] [:error] [pid 24106:tid 140706945394432] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcc4js8oMu6f6EYbxTLOAAAAUo"]
[Mon Jul 27 10:54:58.368710 2026] [:error] [pid 24106:tid 140706945394432] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcc4js8oMu6f6EYbxTLOAAAAUo"]
[Mon Jul 27 10:54:58.369008 2026] [:error] [pid 24106:tid 140706945394432] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcc4js8oMu6f6EYbxTLOAAAAUo"]
[Mon Jul 27 10:54:58.369311 2026] [:error] [pid 24106:tid 140706945394432] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/gql"] [unique_id "amcc4js8oMu6f6EYbxTLOAAAAUo"]
[Mon Jul 27 10:54:58.749153 2026] [:error] [pid 24106:tid 140707012536064] [client 172.70.111.98:13934] [client 172.70.111.98] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcc4js8oMu6f6EYbxTLOwAAAUI"]
[Mon Jul 27 10:54:58.750001 2026] [:error] [pid 24106:tid 140707012536064] [client 172.70.111.98:13934] [client 172.70.111.98] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcc4js8oMu6f6EYbxTLOwAAAUI"]
[Mon Jul 27 10:54:58.750448 2026] [:error] [pid 24106:tid 140707012536064] [client 172.70.111.98:13934] [client 172.70.111.98] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcc4js8oMu6f6EYbxTLOwAAAUI"]
[Mon Jul 27 10:54:58.750580 2026] [:error] [pid 24106:tid 140707012536064] [client 172.70.111.98:13934] [client 172.70.111.98] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/s/33e27393e2431313e2838313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties"] [unique_id "amcc4js8oMu6f6EYbxTLOwAAAUI"]
[Mon Jul 27 10:54:58.911529 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.95.178:11887] [client 162.158.95.178] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcc4ucsEMuHmMYmk66gcAAAAEc"]
[Mon Jul 27 10:54:58.912421 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.95.178:11887] [client 162.158.95.178] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcc4ucsEMuHmMYmk66gcAAAAEc"]
[Mon Jul 27 10:54:58.912899 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.95.178:11887] [client 162.158.95.178] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcc4ucsEMuHmMYmk66gcAAAAEc"]
[Mon Jul 27 10:54:58.913014 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.95.178:11887] [client 162.158.95.178] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcc4ucsEMuHmMYmk66gcAAAAEc"]
[Mon Jul 27 10:54:59.913512 2026] [:error] [pid 12380:tid 140706928609024] [client 104.23.190.196:13415] [client 104.23.190.196] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcc46aChfbWW0CZ_hoiWgAAAMw"]
[Mon Jul 27 10:54:59.914436 2026] [:error] [pid 12380:tid 140706928609024] [client 104.23.190.196:13415] [client 104.23.190.196] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcc46aChfbWW0CZ_hoiWgAAAMw"]
[Mon Jul 27 10:54:59.914916 2026] [:error] [pid 12380:tid 140706928609024] [client 104.23.190.196:13415] [client 104.23.190.196] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcc46aChfbWW0CZ_hoiWgAAAMw"]
[Mon Jul 27 10:54:59.915029 2026] [:error] [pid 12380:tid 140706928609024] [client 104.23.190.196:13415] [client 104.23.190.196] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcc46aChfbWW0CZ_hoiWgAAAMw"]
[Mon Jul 27 10:54:59.940196 2026] [:error] [pid 12380:tid 140706978965248] [client 172.70.243.154:14322] [client 172.70.243.154] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcc46aChfbWW0CZ_hoiWwAAAMY"]
[Mon Jul 27 10:54:59.941049 2026] [:error] [pid 12380:tid 140706978965248] [client 172.70.243.154:14322] [client 172.70.243.154] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcc46aChfbWW0CZ_hoiWwAAAMY"]
[Mon Jul 27 10:54:59.941488 2026] [:error] [pid 12380:tid 140706978965248] [client 172.70.243.154:14322] [client 172.70.243.154] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcc46aChfbWW0CZ_hoiWwAAAMY"]
[Mon Jul 27 10:54:59.941616 2026] [:error] [pid 12380:tid 140706978965248] [client 172.70.243.154:14322] [client 172.70.243.154] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcc46aChfbWW0CZ_hoiWwAAAMY"]
[Mon Jul 27 10:55:01.431276 2026] [:error] [pid 17228:tid 140706827896576] [client 172.71.172.130:11295] [client 172.71.172.130] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcc5ZjBQLO4t9VCDfpDsQAAARg"]
[Mon Jul 27 10:55:01.432348 2026] [:error] [pid 17228:tid 140706827896576] [client 172.71.172.130:11295] [client 172.71.172.130] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcc5ZjBQLO4t9VCDfpDsQAAARg"]
[Mon Jul 27 10:55:01.432892 2026] [:error] [pid 17228:tid 140706827896576] [client 172.71.172.130:11295] [client 172.71.172.130] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcc5ZjBQLO4t9VCDfpDsQAAARg"]
[Mon Jul 27 10:55:01.433004 2026] [:error] [pid 17228:tid 140706827896576] [client 172.71.172.130:11295] [client 172.71.172.130] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcc5ZjBQLO4t9VCDfpDsQAAARg"]
[Mon Jul 27 10:55:02.137855 2026] [:error] [pid 12380:tid 140706903430912] [client 104.23.187.198:10602] [client 104.23.187.198] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcc5qaChfbWW0CZ_hoiZAAAAM8"]
[Mon Jul 27 10:55:02.138905 2026] [:error] [pid 12380:tid 140706903430912] [client 104.23.187.198:10602] [client 104.23.187.198] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcc5qaChfbWW0CZ_hoiZAAAAM8"]
[Mon Jul 27 10:55:02.139486 2026] [:error] [pid 12380:tid 140706903430912] [client 104.23.187.198:10602] [client 104.23.187.198] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcc5qaChfbWW0CZ_hoiZAAAAM8"]
[Mon Jul 27 10:55:02.139646 2026] [:error] [pid 12380:tid 140706903430912] [client 104.23.187.198:10602] [client 104.23.187.198] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/telescope/requests"] [unique_id "amcc5qaChfbWW0CZ_hoiZAAAAM8"]
[Mon Jul 27 10:55:02.635991 2026] [:error] [pid 24106:tid 140706836289280] [client 172.71.148.15:14117] [client 172.71.148.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcc5js8oMu6f6EYbxTLSAAAAVc"]
[Mon Jul 27 10:55:02.636785 2026] [:error] [pid 24106:tid 140706836289280] [client 172.71.148.15:14117] [client 172.71.148.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcc5js8oMu6f6EYbxTLSAAAAVc"]
[Mon Jul 27 10:55:02.637113 2026] [:error] [pid 24106:tid 140706836289280] [client 172.71.148.15:14117] [client 172.71.148.15] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcc5js8oMu6f6EYbxTLSAAAAVc"]
[Mon Jul 27 10:55:02.637182 2026] [:error] [pid 24106:tid 140706836289280] [client 172.71.148.15:14117] [client 172.71.148.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcc5js8oMu6f6EYbxTLSAAAAVc"]
[Mon Jul 27 10:55:03.001896 2026] [:error] [pid 24106:tid 140707020928768] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcc5zs8oMu6f6EYbxTLSwAAAUE"]
[Mon Jul 27 10:55:03.002630 2026] [:error] [pid 24106:tid 140707020928768] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcc5zs8oMu6f6EYbxTLSwAAAUE"]
[Mon Jul 27 10:55:03.003089 2026] [:error] [pid 24106:tid 140707020928768] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcc5zs8oMu6f6EYbxTLSwAAAUE"]
[Mon Jul 27 10:55:03.003192 2026] [:error] [pid 24106:tid 140707020928768] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/info.php"] [unique_id "amcc5zs8oMu6f6EYbxTLSwAAAUE"]
[Mon Jul 27 10:55:03.945471 2026] [:error] [pid 12380:tid 140707103270656] [client 172.70.247.99:9391] [client 172.70.247.99] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcc56aChfbWW0CZ_hoibwAAAMA"]
[Mon Jul 27 10:55:03.946291 2026] [:error] [pid 12380:tid 140707103270656] [client 172.70.247.99:9391] [client 172.70.247.99] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcc56aChfbWW0CZ_hoibwAAAMA"]
[Mon Jul 27 10:55:03.946799 2026] [:error] [pid 12380:tid 140707103270656] [client 172.70.247.99:9391] [client 172.70.247.99] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcc56aChfbWW0CZ_hoibwAAAMA"]
[Mon Jul 27 10:55:03.946916 2026] [:error] [pid 12380:tid 140707103270656] [client 172.70.247.99:9391] [client 172.70.247.99] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcc56aChfbWW0CZ_hoibwAAAMA"]
[Mon Jul 27 10:55:04.156665 2026] [:error] [pid 12380:tid 140707004143360] [client 104.23.190.196:13415] [client 104.23.190.196] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcc6KaChfbWW0CZ_hoicAAAAMM"]
[Mon Jul 27 10:55:04.157626 2026] [:error] [pid 12380:tid 140707004143360] [client 104.23.190.196:13415] [client 104.23.190.196] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcc6KaChfbWW0CZ_hoicAAAAMM"]
[Mon Jul 27 10:55:04.158071 2026] [:error] [pid 12380:tid 140707004143360] [client 104.23.190.196:13415] [client 104.23.190.196] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcc6KaChfbWW0CZ_hoicAAAAMM"]
[Mon Jul 27 10:55:04.158186 2026] [:error] [pid 12380:tid 140707004143360] [client 104.23.190.196:13415] [client 104.23.190.196] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/security.txt"] [unique_id "amcc6KaChfbWW0CZ_hoicAAAAMM"]
[Mon Jul 27 10:55:04.637316 2026] [:error] [pid 24106:tid 140706911823616] [client 172.71.148.15:14117] [client 172.71.148.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcc6Ds8oMu6f6EYbxTLTwAAAU4"]
[Mon Jul 27 10:55:04.638236 2026] [:error] [pid 24106:tid 140706911823616] [client 172.71.148.15:14117] [client 172.71.148.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcc6Ds8oMu6f6EYbxTLTwAAAU4"]
[Mon Jul 27 10:55:04.638617 2026] [:error] [pid 24106:tid 140706911823616] [client 172.71.148.15:14117] [client 172.71.148.15] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcc6Ds8oMu6f6EYbxTLTwAAAU4"]
[Mon Jul 27 10:55:04.638719 2026] [:error] [pid 24106:tid 140706911823616] [client 172.71.148.15:14117] [client 172.71.148.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcc6Ds8oMu6f6EYbxTLTwAAAU4"]
[Mon Jul 27 10:55:04.775204 2026] [:error] [pid 24106:tid 140706928609024] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcc6Ds8oMu6f6EYbxTLUAAAAUw"]
[Mon Jul 27 10:55:04.776043 2026] [:error] [pid 24106:tid 140706928609024] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcc6Ds8oMu6f6EYbxTLUAAAAUw"]
[Mon Jul 27 10:55:04.776477 2026] [:error] [pid 24106:tid 140706928609024] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcc6Ds8oMu6f6EYbxTLUAAAAUw"]
[Mon Jul 27 10:55:04.776620 2026] [:error] [pid 24106:tid 140706928609024] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/actuator/env"] [unique_id "amcc6Ds8oMu6f6EYbxTLUAAAAUw"]
[Mon Jul 27 10:55:05.204480 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.164.93:9806] [client 172.71.164.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcc6ecsEMuHmMYmk66gcQAAAEg"]
[Mon Jul 27 10:55:05.205493 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.164.93:9806] [client 172.71.164.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcc6ecsEMuHmMYmk66gcQAAAEg"]
[Mon Jul 27 10:55:05.205973 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.164.93:9806] [client 172.71.164.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcc6ecsEMuHmMYmk66gcQAAAEg"]
[Mon Jul 27 10:55:05.206082 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.164.93:9806] [client 172.71.164.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcc6ecsEMuHmMYmk66gcQAAAEg"]
[Mon Jul 27 10:55:06.285432 2026] [:error] [pid 12276:tid 140706903430912] [client 172.71.164.93:9806] [client 172.71.164.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcc6ucsEMuHmMYmk66gcgAAAE8"]
[Mon Jul 27 10:55:06.286515 2026] [:error] [pid 12276:tid 140706903430912] [client 172.71.164.93:9806] [client 172.71.164.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcc6ucsEMuHmMYmk66gcgAAAE8"]
[Mon Jul 27 10:55:06.287042 2026] [:error] [pid 12276:tid 140706903430912] [client 172.71.164.93:9806] [client 172.71.164.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcc6ucsEMuHmMYmk66gcgAAAE8"]
[Mon Jul 27 10:55:06.287168 2026] [:error] [pid 12276:tid 140706903430912] [client 172.71.164.93:9806] [client 172.71.164.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcc6ucsEMuHmMYmk66gcgAAAE8"]
[Mon Jul 27 10:55:06.346418 2026] [:error] [pid 12276:tid 140707103270656] [client 104.23.253.15:10938] [client 104.23.253.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcc6ucsEMuHmMYmk66gcwAAAEA"]
[Mon Jul 27 10:55:06.347645 2026] [:error] [pid 12276:tid 140707103270656] [client 104.23.253.15:10938] [client 104.23.253.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcc6ucsEMuHmMYmk66gcwAAAEA"]
[Mon Jul 27 10:55:06.348022 2026] [:error] [pid 12276:tid 140707103270656] [client 104.23.253.15:10938] [client 104.23.253.15] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcc6ucsEMuHmMYmk66gcwAAAEA"]
[Mon Jul 27 10:55:06.348137 2026] [:error] [pid 12276:tid 140707103270656] [client 104.23.253.15:10938] [client 104.23.253.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/trace.axd"] [unique_id "amcc6ucsEMuHmMYmk66gcwAAAEA"]
[Mon Jul 27 10:55:06.763271 2026] [:error] [pid 24106:tid 140706853074688] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcc6js8oMu6f6EYbxTLVwAAAVU"]
[Mon Jul 27 10:55:06.764135 2026] [:error] [pid 24106:tid 140706853074688] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcc6js8oMu6f6EYbxTLVwAAAVU"]
[Mon Jul 27 10:55:06.764528 2026] [:error] [pid 24106:tid 140706853074688] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcc6js8oMu6f6EYbxTLVwAAAVU"]
[Mon Jul 27 10:55:06.764676 2026] [:error] [pid 24106:tid 140706853074688] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/@vite/env"] [unique_id "amcc6js8oMu6f6EYbxTLVwAAAVU"]
[Mon Jul 27 10:55:07.045854 2026] [:error] [pid 24106:tid 140706937001728] [client 104.23.168.92:10643] [client 104.23.168.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcc6zs8oMu6f6EYbxTLWgAAAUs"]
[Mon Jul 27 10:55:07.046700 2026] [:error] [pid 24106:tid 140706937001728] [client 104.23.168.92:10643] [client 104.23.168.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcc6zs8oMu6f6EYbxTLWgAAAUs"]
[Mon Jul 27 10:55:07.047263 2026] [:error] [pid 24106:tid 140706937001728] [client 104.23.168.92:10643] [client 104.23.168.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcc6zs8oMu6f6EYbxTLWgAAAUs"]
[Mon Jul 27 10:55:07.047472 2026] [:error] [pid 24106:tid 140706937001728] [client 104.23.168.92:10643] [client 104.23.168.92] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcc6zs8oMu6f6EYbxTLWgAAAUs"]
[Mon Jul 27 10:55:07.170435 2026] [:error] [pid 12380:tid 140706920216320] [client 172.70.243.154:14323] [client 172.70.243.154] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc66aChfbWW0CZ_hoifAAAAM0"]
[Mon Jul 27 10:55:07.171182 2026] [:error] [pid 12380:tid 140706920216320] [client 172.70.243.154:14323] [client 172.70.243.154] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "OPTIONS"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc66aChfbWW0CZ_hoifAAAAM0"]
[Mon Jul 27 10:55:07.171621 2026] [:error] [pid 12380:tid 140706920216320] [client 172.70.243.154:14323] [client 172.70.243.154] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc66aChfbWW0CZ_hoifAAAAM0"]
[Mon Jul 27 10:55:07.944515 2026] [:error] [pid 21545:tid 140706911823616] [client 172.70.111.97:13606] [client 172.70.111.97] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcc65hXfYDIcpslIWOw3gAAAY4"]
[Mon Jul 27 10:55:07.945436 2026] [:error] [pid 21545:tid 140706911823616] [client 172.70.111.97:13606] [client 172.70.111.97] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcc65hXfYDIcpslIWOw3gAAAY4"]
[Mon Jul 27 10:55:07.945959 2026] [:error] [pid 21545:tid 140706911823616] [client 172.70.111.97:13606] [client 172.70.111.97] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcc65hXfYDIcpslIWOw3gAAAY4"]
[Mon Jul 27 10:55:07.946078 2026] [:error] [pid 21545:tid 140706911823616] [client 172.70.111.97:13606] [client 172.70.111.97] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/sftp.json"] [unique_id "amcc65hXfYDIcpslIWOw3gAAAY4"]
[Mon Jul 27 10:55:08.190069 2026] [:error] [pid 12275:tid 140706836289280] [client 172.70.248.24:11408] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc7HFwI8r7BFXGkAukxAAAABc"]
[Mon Jul 27 10:55:08.190668 2026] [:error] [pid 12275:tid 140706836289280] [client 172.70.248.24:11408] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc7HFwI8r7BFXGkAukxAAAABc"]
[Mon Jul 27 10:55:08.190954 2026] [:error] [pid 12275:tid 140706836289280] [client 172.70.248.24:11408] [client 172.70.248.24] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc7HFwI8r7BFXGkAukxAAAABc"]
[Mon Jul 27 10:55:08.191010 2026] [:error] [pid 12275:tid 140706836289280] [client 172.70.248.24:11408] [client 172.70.248.24] ModSecurity: Warning. Found 4 byte(s) in ARGS:rest_route outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:rest_route=/wp/v2/users/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc7HFwI8r7BFXGkAukxAAAABc"]
[Mon Jul 27 10:55:08.191061 2026] [:error] [pid 12275:tid 140706836289280] [client 172.70.248.24:11408] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc7HFwI8r7BFXGkAukxAAAABc"]
[Mon Jul 27 10:55:08.718773 2026] [:error] [pid 24106:tid 140706836289280] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc7Ds8oMu6f6EYbxTLYAAAAVc"]
[Mon Jul 27 10:55:08.719579 2026] [:error] [pid 24106:tid 140706836289280] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "OPTIONS"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc7Ds8oMu6f6EYbxTLYAAAAVc"]
[Mon Jul 27 10:55:08.720030 2026] [:error] [pid 24106:tid 140706836289280] [client 162.158.62.6:13092] [client 162.158.62.6] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc7Ds8oMu6f6EYbxTLYAAAAVc"]
[Mon Jul 27 10:55:09.020274 2026] [:error] [pid 24106:tid 140706861467392] [client 162.158.95.177:10668] [client 162.158.95.177] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcc7Ts8oMu6f6EYbxTLYgAAAVQ"]
[Mon Jul 27 10:55:09.021025 2026] [:error] [pid 24106:tid 140706861467392] [client 162.158.95.177:10668] [client 162.158.95.177] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcc7Ts8oMu6f6EYbxTLYgAAAVQ"]
[Mon Jul 27 10:55:09.021342 2026] [:error] [pid 24106:tid 140706861467392] [client 162.158.95.177:10668] [client 162.158.95.177] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcc7Ts8oMu6f6EYbxTLYgAAAVQ"]
[Mon Jul 27 10:55:09.021460 2026] [:error] [pid 24106:tid 140706861467392] [client 162.158.95.177:10668] [client 162.158.95.177] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcc7Ts8oMu6f6EYbxTLYgAAAVQ"]
[Mon Jul 27 10:55:09.693518 2026] [:error] [pid 21545:tid 140706928609024] [client 172.70.111.97:13606] [client 172.70.111.97] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc7ZhXfYDIcpslIWOw4QAAAYw"]
[Mon Jul 27 10:55:09.694377 2026] [:error] [pid 21545:tid 140706928609024] [client 172.70.111.97:13606] [client 172.70.111.97] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc7ZhXfYDIcpslIWOw4QAAAYw"]
[Mon Jul 27 10:55:09.694898 2026] [:error] [pid 21545:tid 140706928609024] [client 172.70.111.97:13606] [client 172.70.111.97] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc7ZhXfYDIcpslIWOw4QAAAYw"]
[Mon Jul 27 10:55:09.694994 2026] [:error] [pid 21545:tid 140706928609024] [client 172.70.111.97:13606] [client 172.70.111.97] ModSecurity: Warning. Found 4 byte(s) in ARGS:rest_route outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:rest_route=/wp/v2/users/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc7ZhXfYDIcpslIWOw4QAAAYw"]
[Mon Jul 27 10:55:09.695239 2026] [:error] [pid 21545:tid 140706928609024] [client 172.70.111.97:13606] [client 172.70.111.97] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcc7ZhXfYDIcpslIWOw4QAAAYw"]
[Mon Jul 27 10:55:10.775264 2026] [:error] [pid 24106:tid 140706978965248] [client 104.23.187.198:13627] [client 104.23.187.198] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcc7js8oMu6f6EYbxTLZwAAAUY"]
[Mon Jul 27 10:55:10.776039 2026] [:error] [pid 24106:tid 140706978965248] [client 104.23.187.198:13627] [client 104.23.187.198] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcc7js8oMu6f6EYbxTLZwAAAUY"]
[Mon Jul 27 10:55:10.776410 2026] [:error] [pid 24106:tid 140706978965248] [client 104.23.187.198:13627] [client 104.23.187.198] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcc7js8oMu6f6EYbxTLZwAAAUY"]
[Mon Jul 27 10:55:10.776511 2026] [:error] [pid 24106:tid 140706978965248] [client 104.23.187.198:13627] [client 104.23.187.198] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/debug/default/view"] [unique_id "amcc7js8oMu6f6EYbxTLZwAAAUY"]
[Mon Jul 27 10:55:13.874104 2026] [:error] [pid 12380:tid 140706920216320] [client 104.23.254.16:13432] [client 104.23.254.16] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amcc8aaChfbWW0CZ_hoikAAAAM0"]
[Mon Jul 27 10:55:13.874935 2026] [:error] [pid 12380:tid 140706920216320] [client 104.23.254.16:13432] [client 104.23.254.16] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amcc8aaChfbWW0CZ_hoikAAAAM0"]
[Mon Jul 27 10:55:13.875401 2026] [:error] [pid 12380:tid 140706920216320] [client 104.23.254.16:13432] [client 104.23.254.16] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amcc8aaChfbWW0CZ_hoikAAAAM0"]
[Mon Jul 27 10:55:13.875640 2026] [:error] [pid 12380:tid 140706920216320] [client 104.23.254.16:13432] [client 104.23.254.16] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amcc8aaChfbWW0CZ_hoikAAAAM0"]
[Mon Jul 27 10:55:37.360696 2026] [:error] [pid 12277:tid 140706895038208] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcdCRwjcb8HQE21kA6lIQAAAJA"]
[Mon Jul 27 10:55:37.361633 2026] [:error] [pid 12277:tid 140706895038208] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcdCRwjcb8HQE21kA6lIQAAAJA"]
[Mon Jul 27 10:55:37.362103 2026] [:error] [pid 12277:tid 140706895038208] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcdCRwjcb8HQE21kA6lIQAAAJA"]
[Mon Jul 27 10:55:37.362306 2026] [:error] [pid 12277:tid 140706895038208] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcdCRwjcb8HQE21kA6lIQAAAJA"]
[Mon Jul 27 10:55:37.831614 2026] [:error] [pid 12277:tid 140706995750656] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amcdCRwjcb8HQE21kA6lIgAAAIQ"]
[Mon Jul 27 10:55:37.832466 2026] [:error] [pid 12277:tid 140706995750656] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amcdCRwjcb8HQE21kA6lIgAAAIQ"]
[Mon Jul 27 10:55:37.832928 2026] [:error] [pid 12277:tid 140706995750656] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amcdCRwjcb8HQE21kA6lIgAAAIQ"]
[Mon Jul 27 10:55:37.833122 2026] [:error] [pid 12277:tid 140706995750656] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amcdCRwjcb8HQE21kA6lIgAAAIQ"]
[Mon Jul 27 10:55:38.790039 2026] [:error] [pid 12275:tid 140707103270656] [client 172.70.208.124:12115] [client 172.70.208.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcdCnFwI8r7BFXGkAuk9AAAAAA"]
[Mon Jul 27 10:55:38.790906 2026] [:error] [pid 12275:tid 140707103270656] [client 172.70.208.124:12115] [client 172.70.208.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcdCnFwI8r7BFXGkAuk9AAAAAA"]
[Mon Jul 27 10:55:38.791395 2026] [:error] [pid 12275:tid 140707103270656] [client 172.70.208.124:12115] [client 172.70.208.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcdCnFwI8r7BFXGkAuk9AAAAAA"]
[Mon Jul 27 10:55:38.791710 2026] [:error] [pid 12275:tid 140707103270656] [client 172.70.208.124:12115] [client 172.70.208.124] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcdCnFwI8r7BFXGkAuk9AAAAAA"]
[Mon Jul 27 10:55:39.257987 2026] [:error] [pid 12277:tid 140706928609024] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcdCxwjcb8HQE21kA6lIwAAAIw"]
[Mon Jul 27 10:55:39.259167 2026] [:error] [pid 12277:tid 140706928609024] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcdCxwjcb8HQE21kA6lIwAAAIw"]
[Mon Jul 27 10:55:39.259893 2026] [:error] [pid 12277:tid 140706928609024] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcdCxwjcb8HQE21kA6lIwAAAIw"]
[Mon Jul 27 10:55:39.260175 2026] [:error] [pid 12277:tid 140706928609024] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcdCxwjcb8HQE21kA6lIwAAAIw"]
[Mon Jul 27 10:55:39.724431 2026] [:error] [pid 12277:tid 140707012536064] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcdCxwjcb8HQE21kA6lJQAAAII"]
[Mon Jul 27 10:55:39.725104 2026] [:error] [pid 12277:tid 140707012536064] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcdCxwjcb8HQE21kA6lJQAAAII"]
[Mon Jul 27 10:55:39.725618 2026] [:error] [pid 12277:tid 140707012536064] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcdCxwjcb8HQE21kA6lJQAAAII"]
[Mon Jul 27 10:55:39.725800 2026] [:error] [pid 12277:tid 140707012536064] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcdCxwjcb8HQE21kA6lJQAAAII"]
[Mon Jul 27 10:55:40.196689 2026] [:error] [pid 12275:tid 140706937001728] [client 172.70.208.124:12115] [client 172.70.208.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcdDHFwI8r7BFXGkAuk9gAAAAs"]
[Mon Jul 27 10:55:40.197675 2026] [:error] [pid 12275:tid 140706937001728] [client 172.70.208.124:12115] [client 172.70.208.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcdDHFwI8r7BFXGkAuk9gAAAAs"]
[Mon Jul 27 10:55:40.198207 2026] [:error] [pid 12275:tid 140706937001728] [client 172.70.208.124:12115] [client 172.70.208.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcdDHFwI8r7BFXGkAuk9gAAAAs"]
[Mon Jul 27 10:55:40.198489 2026] [:error] [pid 12275:tid 140706937001728] [client 172.70.208.124:12115] [client 172.70.208.124] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcdDHFwI8r7BFXGkAuk9gAAAAs"]
[Mon Jul 27 10:55:40.660009 2026] [:error] [pid 12277:tid 140707020928768] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amcdDBwjcb8HQE21kA6lJgAAAIE"]
[Mon Jul 27 10:55:40.661151 2026] [:error] [pid 12277:tid 140707020928768] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amcdDBwjcb8HQE21kA6lJgAAAIE"]
[Mon Jul 27 10:55:40.661850 2026] [:error] [pid 12277:tid 140707020928768] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amcdDBwjcb8HQE21kA6lJgAAAIE"]
[Mon Jul 27 10:55:40.662134 2026] [:error] [pid 12277:tid 140707020928768] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.tmp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amcdDBwjcb8HQE21kA6lJgAAAIE"]
[Mon Jul 27 10:55:41.653487 2026] [:error] [pid 12380:tid 140706953787136] [client 172.70.92.193:10373] [client 172.70.92.193] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amcdDaaChfbWW0CZ_hojKwAAAMk"]
[Mon Jul 27 10:55:41.654350 2026] [:error] [pid 12380:tid 140706953787136] [client 172.70.92.193:10373] [client 172.70.92.193] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amcdDaaChfbWW0CZ_hojKwAAAMk"]
[Mon Jul 27 10:55:41.654761 2026] [:error] [pid 12380:tid 140706953787136] [client 172.70.92.193:10373] [client 172.70.92.193] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amcdDaaChfbWW0CZ_hojKwAAAMk"]
[Mon Jul 27 10:55:41.654943 2026] [:error] [pid 12380:tid 140706953787136] [client 172.70.92.193:10373] [client 172.70.92.193] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amcdDaaChfbWW0CZ_hojKwAAAMk"]
[Mon Jul 27 10:55:42.124669 2026] [:error] [pid 12277:tid 140706861467392] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amcdDhwjcb8HQE21kA6lKAAAAJQ"]
[Mon Jul 27 10:55:42.125433 2026] [:error] [pid 12277:tid 140706861467392] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amcdDhwjcb8HQE21kA6lKAAAAJQ"]
[Mon Jul 27 10:55:42.125707 2026] [:error] [pid 12277:tid 140706861467392] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Pattern match "\\\\.[^.~]+~(?:/.*|)$" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1060"] [id "920500"] [msg "Attempt to access a backup or working file"] [data ".env~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amcdDhwjcb8HQE21kA6lKAAAAJQ"]
[Mon Jul 27 10:55:42.125926 2026] [:error] [pid 12277:tid 140706861467392] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amcdDhwjcb8HQE21kA6lKAAAAJQ"]
[Mon Jul 27 10:55:42.126144 2026] [:error] [pid 12277:tid 140706861467392] [client 172.70.208.167:10713] [client 172.70.208.167] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amcdDhwjcb8HQE21kA6lKAAAAJQ"]
[Mon Jul 27 10:55:43.141352 2026] [:error] [pid 24106:tid 140706928609024] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amcdDzs8oMu6f6EYbxTMHwAAAUw"]
[Mon Jul 27 10:55:43.142465 2026] [:error] [pid 24106:tid 140706928609024] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amcdDzs8oMu6f6EYbxTMHwAAAUw"]
[Mon Jul 27 10:55:43.143156 2026] [:error] [pid 24106:tid 140706928609024] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amcdDzs8oMu6f6EYbxTMHwAAAUw"]
[Mon Jul 27 10:55:43.143375 2026] [:error] [pid 24106:tid 140706928609024] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amcdDzs8oMu6f6EYbxTMHwAAAUw"]
[Mon Jul 27 10:55:44.133047 2026] [:error] [pid 12275:tid 140707020928768] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcdEHFwI8r7BFXGkAuk_wAAAAE"]
[Mon Jul 27 10:55:44.133993 2026] [:error] [pid 12275:tid 140707020928768] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcdEHFwI8r7BFXGkAuk_wAAAAE"]
[Mon Jul 27 10:55:44.141808 2026] [:error] [pid 12275:tid 140707020928768] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcdEHFwI8r7BFXGkAuk_wAAAAE"]
[Mon Jul 27 10:55:44.142109 2026] [:error] [pid 12275:tid 140707020928768] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcdEHFwI8r7BFXGkAuk_wAAAAE"]
[Mon Jul 27 10:55:44.615880 2026] [:error] [pid 24106:tid 140706962179840] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcdEDs8oMu6f6EYbxTMJAAAAUg"]
[Mon Jul 27 10:55:44.616595 2026] [:error] [pid 24106:tid 140706962179840] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcdEDs8oMu6f6EYbxTMJAAAAUg"]
[Mon Jul 27 10:55:44.616950 2026] [:error] [pid 24106:tid 140706962179840] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcdEDs8oMu6f6EYbxTMJAAAAUg"]
[Mon Jul 27 10:55:44.617123 2026] [:error] [pid 24106:tid 140706962179840] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcdEDs8oMu6f6EYbxTMJAAAAUg"]
[Mon Jul 27 10:55:45.089749 2026] [:error] [pid 12275:tid 140707004143360] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.template"] [unique_id "amcdEXFwI8r7BFXGkAulAgAAAAM"]
[Mon Jul 27 10:55:45.090643 2026] [:error] [pid 12275:tid 140707004143360] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.template"] [unique_id "amcdEXFwI8r7BFXGkAulAgAAAAM"]
[Mon Jul 27 10:55:45.091166 2026] [:error] [pid 12275:tid 140707004143360] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.template"] [unique_id "amcdEXFwI8r7BFXGkAulAgAAAAM"]
[Mon Jul 27 10:55:45.091446 2026] [:error] [pid 12275:tid 140707004143360] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.template"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.template"] [unique_id "amcdEXFwI8r7BFXGkAulAgAAAAM"]
[Mon Jul 27 10:55:45.599983 2026] [:error] [pid 24106:tid 140706895038208] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcdETs8oMu6f6EYbxTMKwAAAVA"]
[Mon Jul 27 10:55:45.600771 2026] [:error] [pid 24106:tid 140706895038208] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcdETs8oMu6f6EYbxTMKwAAAVA"]
[Mon Jul 27 10:55:45.601314 2026] [:error] [pid 24106:tid 140706895038208] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcdETs8oMu6f6EYbxTMKwAAAVA"]
[Mon Jul 27 10:55:45.601509 2026] [:error] [pid 24106:tid 140706895038208] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcdETs8oMu6f6EYbxTMKwAAAVA"]
[Mon Jul 27 10:55:46.078355 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcdEnFwI8r7BFXGkAulBQAAAAQ"]
[Mon Jul 27 10:55:46.078996 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcdEnFwI8r7BFXGkAulBQAAAAQ"]
[Mon Jul 27 10:55:46.079396 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcdEnFwI8r7BFXGkAulBQAAAAQ"]
[Mon Jul 27 10:55:46.079664 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcdEnFwI8r7BFXGkAulBQAAAAQ"]
[Mon Jul 27 10:55:46.553469 2026] [:error] [pid 24106:tid 140706978965248] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test.local"] [unique_id "amcdEjs8oMu6f6EYbxTMLgAAAUY"]
[Mon Jul 27 10:55:46.554373 2026] [:error] [pid 24106:tid 140706978965248] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test.local"] [unique_id "amcdEjs8oMu6f6EYbxTMLgAAAUY"]
[Mon Jul 27 10:55:46.554910 2026] [:error] [pid 24106:tid 140706978965248] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test.local"] [unique_id "amcdEjs8oMu6f6EYbxTMLgAAAUY"]
[Mon Jul 27 10:55:46.555193 2026] [:error] [pid 24106:tid 140706978965248] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test.local"] [unique_id "amcdEjs8oMu6f6EYbxTMLgAAAUY"]
[Mon Jul 27 10:55:47.034061 2026] [:error] [pid 12275:tid 140706953787136] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amcdE3FwI8r7BFXGkAulCgAAAAk"]
[Mon Jul 27 10:55:47.035163 2026] [:error] [pid 12275:tid 140706953787136] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amcdE3FwI8r7BFXGkAulCgAAAAk"]
[Mon Jul 27 10:55:47.035703 2026] [:error] [pid 12275:tid 140706953787136] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amcdE3FwI8r7BFXGkAulCgAAAAk"]
[Mon Jul 27 10:55:47.035946 2026] [:error] [pid 12275:tid 140706953787136] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envrc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amcdE3FwI8r7BFXGkAulCgAAAAk"]
[Mon Jul 27 10:55:47.510472 2026] [:error] [pid 24106:tid 140706911823616] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.flaskenv"] [unique_id "amcdEzs8oMu6f6EYbxTMMgAAAU4"]
[Mon Jul 27 10:55:47.511149 2026] [:error] [pid 24106:tid 140706911823616] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.flaskenv"] [unique_id "amcdEzs8oMu6f6EYbxTMMgAAAU4"]
[Mon Jul 27 10:55:47.511524 2026] [:error] [pid 24106:tid 140706911823616] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.flaskenv"] [unique_id "amcdEzs8oMu6f6EYbxTMMgAAAU4"]
[Mon Jul 27 10:55:47.989278 2026] [:error] [pid 12275:tid 140706836289280] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/env"] [unique_id "amcdE3FwI8r7BFXGkAulDQAAABc"]
[Mon Jul 27 10:55:47.990296 2026] [:error] [pid 12275:tid 140706836289280] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/env"] [unique_id "amcdE3FwI8r7BFXGkAulDQAAABc"]
[Mon Jul 27 10:55:47.990832 2026] [:error] [pid 12275:tid 140706836289280] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/env"] [unique_id "amcdE3FwI8r7BFXGkAulDQAAABc"]
[Mon Jul 27 10:55:48.978043 2026] [:error] [pid 17228:tid 140706945394432] [client 172.70.208.53:11238] [client 172.70.208.53] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/env.js"] [unique_id "amcdFJjBQLO4t9VCDfpDuAAAAQo"]
[Mon Jul 27 10:55:48.979108 2026] [:error] [pid 17228:tid 140706945394432] [client 172.70.208.53:11238] [client 172.70.208.53] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/env.js"] [unique_id "amcdFJjBQLO4t9VCDfpDuAAAAQo"]
[Mon Jul 27 10:55:48.979774 2026] [:error] [pid 17228:tid 140706945394432] [client 172.70.208.53:11238] [client 172.70.208.53] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/env.js"] [unique_id "amcdFJjBQLO4t9VCDfpDuAAAAQo"]
[Mon Jul 27 10:55:49.462131 2026] [:error] [pid 12275:tid 140706978965248] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/env.json"] [unique_id "amcdFXFwI8r7BFXGkAulEgAAAAY"]
[Mon Jul 27 10:55:49.463078 2026] [:error] [pid 12275:tid 140706978965248] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/env.json"] [unique_id "amcdFXFwI8r7BFXGkAulEgAAAAY"]
[Mon Jul 27 10:55:49.463610 2026] [:error] [pid 12275:tid 140706978965248] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/env.json"] [unique_id "amcdFXFwI8r7BFXGkAulEgAAAAY"]
[Mon Jul 27 10:55:49.940815 2026] [:error] [pid 24106:tid 140707004143360] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amcdFTs8oMu6f6EYbxTMQgAAAUM"]
[Mon Jul 27 10:55:49.941734 2026] [:error] [pid 24106:tid 140707004143360] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amcdFTs8oMu6f6EYbxTMQgAAAUM"]
[Mon Jul 27 10:55:49.942258 2026] [:error] [pid 24106:tid 140707004143360] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amcdFTs8oMu6f6EYbxTMQgAAAUM"]
[Mon Jul 27 10:55:49.942533 2026] [:error] [pid 24106:tid 140707004143360] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amcdFTs8oMu6f6EYbxTMQgAAAUM"]
[Mon Jul 27 10:55:50.421791 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amcdFnFwI8r7BFXGkAulFQAAAAQ"]
[Mon Jul 27 10:55:50.422586 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amcdFnFwI8r7BFXGkAulFQAAAAQ"]
[Mon Jul 27 10:55:50.423078 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amcdFnFwI8r7BFXGkAulFQAAAAQ"]
[Mon Jul 27 10:55:50.423358 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amcdFnFwI8r7BFXGkAulFQAAAAQ"]
[Mon Jul 27 10:55:50.894628 2026] [:error] [pid 24106:tid 140706953787136] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amcdFjs8oMu6f6EYbxTMRwAAAUk"]
[Mon Jul 27 10:55:50.895390 2026] [:error] [pid 24106:tid 140706953787136] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amcdFjs8oMu6f6EYbxTMRwAAAUk"]
[Mon Jul 27 10:55:50.895881 2026] [:error] [pid 24106:tid 140706953787136] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amcdFjs8oMu6f6EYbxTMRwAAAUk"]
[Mon Jul 27 10:55:50.896146 2026] [:error] [pid 24106:tid 140706953787136] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amcdFjs8oMu6f6EYbxTMRwAAAUk"]
[Mon Jul 27 10:55:51.375646 2026] [:error] [pid 12275:tid 140706911823616] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amcdF3FwI8r7BFXGkAulFwAAAA4"]
[Mon Jul 27 10:55:51.376485 2026] [:error] [pid 12275:tid 140706911823616] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amcdF3FwI8r7BFXGkAulFwAAAA4"]
[Mon Jul 27 10:55:51.377011 2026] [:error] [pid 12275:tid 140706911823616] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amcdF3FwI8r7BFXGkAulFwAAAA4"]
[Mon Jul 27 10:55:51.377300 2026] [:error] [pid 12275:tid 140706911823616] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amcdF3FwI8r7BFXGkAulFwAAAA4"]
[Mon Jul 27 10:55:51.855380 2026] [:error] [pid 24106:tid 140706987357952] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amcdFzs8oMu6f6EYbxTMTQAAAUU"]
[Mon Jul 27 10:55:51.856337 2026] [:error] [pid 24106:tid 140706987357952] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amcdFzs8oMu6f6EYbxTMTQAAAUU"]
[Mon Jul 27 10:55:51.856973 2026] [:error] [pid 24106:tid 140706987357952] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amcdFzs8oMu6f6EYbxTMTQAAAUU"]
[Mon Jul 27 10:55:51.857253 2026] [:error] [pid 24106:tid 140706987357952] [client 172.70.93.67:12444] [client 172.70.93.67] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /frontend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amcdFzs8oMu6f6EYbxTMTQAAAUU"]
[Mon Jul 27 10:55:52.336742 2026] [:error] [pid 12275:tid 140706878252800] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amcdGHFwI8r7BFXGkAulGgAAABI"]
[Mon Jul 27 10:55:52.337636 2026] [:error] [pid 12275:tid 140706878252800] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amcdGHFwI8r7BFXGkAulGgAAABI"]
[Mon Jul 27 10:55:52.338121 2026] [:error] [pid 12275:tid 140706878252800] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amcdGHFwI8r7BFXGkAulGgAAABI"]
[Mon Jul 27 10:55:52.338394 2026] [:error] [pid 12275:tid 140706878252800] [client 162.158.108.167:12156] [client 162.158.108.167] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amcdGHFwI8r7BFXGkAulGgAAABI"]
[Mon Jul 27 10:55:53.342704 2026] [:error] [pid 12380:tid 140707020928768] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amcdGaaChfbWW0CZ_hojnwAAAME"]
[Mon Jul 27 10:55:53.343424 2026] [:error] [pid 12380:tid 140707020928768] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amcdGaaChfbWW0CZ_hojnwAAAME"]
[Mon Jul 27 10:55:53.343846 2026] [:error] [pid 12380:tid 140707020928768] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amcdGaaChfbWW0CZ_hojnwAAAME"]
[Mon Jul 27 10:55:53.344105 2026] [:error] [pid 12380:tid 140707020928768] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amcdGaaChfbWW0CZ_hojnwAAAME"]
[Mon Jul 27 10:55:53.821797 2026] [:error] [pid 12380:tid 140706911823616] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amcdGaaChfbWW0CZ_hojpgAAAM4"]
[Mon Jul 27 10:55:53.822424 2026] [:error] [pid 12380:tid 140706911823616] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amcdGaaChfbWW0CZ_hojpgAAAM4"]
[Mon Jul 27 10:55:53.822830 2026] [:error] [pid 12380:tid 140706911823616] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amcdGaaChfbWW0CZ_hojpgAAAM4"]
[Mon Jul 27 10:55:53.823015 2026] [:error] [pid 12380:tid 140706911823616] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /client/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amcdGaaChfbWW0CZ_hojpgAAAM4"]
[Mon Jul 27 10:55:54.291663 2026] [:error] [pid 12380:tid 140706937001728] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amcdGqaChfbWW0CZ_hojrAAAAMs"]
[Mon Jul 27 10:55:54.292068 2026] [:error] [pid 12380:tid 140706937001728] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amcdGqaChfbWW0CZ_hojrAAAAMs"]
[Mon Jul 27 10:55:54.292353 2026] [:error] [pid 12380:tid 140706937001728] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amcdGqaChfbWW0CZ_hojrAAAAMs"]
[Mon Jul 27 10:55:54.292501 2026] [:error] [pid 12380:tid 140706937001728] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amcdGqaChfbWW0CZ_hojrAAAAMs"]
[Mon Jul 27 10:55:54.781301 2026] [:error] [pid 12380:tid 140707103270656] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amcdGqaChfbWW0CZ_hojsAAAAMA"]
[Mon Jul 27 10:55:54.782348 2026] [:error] [pid 12380:tid 140707103270656] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amcdGqaChfbWW0CZ_hojsAAAAMA"]
[Mon Jul 27 10:55:54.782939 2026] [:error] [pid 12380:tid 140707103270656] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amcdGqaChfbWW0CZ_hojsAAAAMA"]
[Mon Jul 27 10:55:54.783227 2026] [:error] [pid 12380:tid 140707103270656] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amcdGqaChfbWW0CZ_hojsAAAAMA"]
[Mon Jul 27 10:55:55.262784 2026] [:error] [pid 12380:tid 140706895038208] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amcdG6aChfbWW0CZ_hojtAAAANA"]
[Mon Jul 27 10:55:55.263731 2026] [:error] [pid 12380:tid 140706895038208] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amcdG6aChfbWW0CZ_hojtAAAANA"]
[Mon Jul 27 10:55:55.264233 2026] [:error] [pid 12380:tid 140706895038208] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amcdG6aChfbWW0CZ_hojtAAAANA"]
[Mon Jul 27 10:55:55.264510 2026] [:error] [pid 12380:tid 140706895038208] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /private/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amcdG6aChfbWW0CZ_hojtAAAANA"]
[Mon Jul 27 10:55:55.758894 2026] [:error] [pid 12380:tid 140706937001728] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/var/.env"] [unique_id "amcdG6aChfbWW0CZ_hojugAAAMs"]
[Mon Jul 27 10:55:55.760061 2026] [:error] [pid 12380:tid 140706937001728] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/var/.env"] [unique_id "amcdG6aChfbWW0CZ_hojugAAAMs"]
[Mon Jul 27 10:55:55.760706 2026] [:error] [pid 12380:tid 140706937001728] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/var/.env"] [unique_id "amcdG6aChfbWW0CZ_hojugAAAMs"]
[Mon Jul 27 10:55:55.760976 2026] [:error] [pid 12380:tid 140706937001728] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /var/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/var/.env"] [unique_id "amcdG6aChfbWW0CZ_hojugAAAMs"]
[Mon Jul 27 10:55:56.230219 2026] [:error] [pid 12380:tid 140706978965248] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.yml"] [unique_id "amcdHKaChfbWW0CZ_hojvQAAAMY"]
[Mon Jul 27 10:55:56.231365 2026] [:error] [pid 12380:tid 140706978965248] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.yml"] [unique_id "amcdHKaChfbWW0CZ_hojvQAAAMY"]
[Mon Jul 27 10:55:56.231935 2026] [:error] [pid 12380:tid 140706978965248] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.yml"] [unique_id "amcdHKaChfbWW0CZ_hojvQAAAMY"]
[Mon Jul 27 10:55:56.705150 2026] [:error] [pid 12380:tid 140706844681984] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.yaml"] [unique_id "amcdHKaChfbWW0CZ_hojwQAAANY"]
[Mon Jul 27 10:55:56.706303 2026] [:error] [pid 12380:tid 140706844681984] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.yaml"] [unique_id "amcdHKaChfbWW0CZ_hojwQAAANY"]
[Mon Jul 27 10:55:56.706907 2026] [:error] [pid 12380:tid 140706844681984] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.yaml"] [unique_id "amcdHKaChfbWW0CZ_hojwQAAANY"]
[Mon Jul 27 10:55:57.669686 2026] [:error] [pid 21545:tid 140706987357952] [client 172.69.165.62:9978] [client 172.69.165.62] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.override.yml"] [unique_id "amcdHZhXfYDIcpslIWOxAQAAAYU"]
[Mon Jul 27 10:55:57.670687 2026] [:error] [pid 21545:tid 140706987357952] [client 172.69.165.62:9978] [client 172.69.165.62] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.override.yml"] [unique_id "amcdHZhXfYDIcpslIWOxAQAAAYU"]
[Mon Jul 27 10:55:57.671164 2026] [:error] [pid 21545:tid 140706987357952] [client 172.69.165.62:9978] [client 172.69.165.62] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.override.yml"] [unique_id "amcdHZhXfYDIcpslIWOxAQAAAYU"]
[Mon Jul 27 10:55:58.132779 2026] [:error] [pid 12380:tid 140706978965248] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.dev.yml"] [unique_id "amcdHqaChfbWW0CZ_hojyAAAAMY"]
[Mon Jul 27 10:55:58.133810 2026] [:error] [pid 12380:tid 140706978965248] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.dev.yml"] [unique_id "amcdHqaChfbWW0CZ_hojyAAAAMY"]
[Mon Jul 27 10:55:58.134308 2026] [:error] [pid 12380:tid 140706978965248] [client 172.70.208.166:11145] [client 172.70.208.166] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.dev.yml"] [unique_id "amcdHqaChfbWW0CZ_hojyAAAAMY"]
[Mon Jul 27 10:55:59.086198 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.163.157:12232] [client 162.158.163.157] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.prod.yml"] [unique_id "amcdH-csEMuHmMYmk66giAAAAFY"]
[Mon Jul 27 10:55:59.086796 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.163.157:12232] [client 162.158.163.157] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.prod.yml"] [unique_id "amcdH-csEMuHmMYmk66giAAAAFY"]
[Mon Jul 27 10:55:59.087150 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.163.157:12232] [client 162.158.163.157] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/docker-compose.prod.yml"] [unique_id "amcdH-csEMuHmMYmk66giAAAAFY"]
[Mon Jul 27 10:56:00.037402 2026] [:error] [pid 12276:tid 140706827896576] [client 172.71.152.83:9981] [client 172.71.152.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.js"] [unique_id "amcdIOcsEMuHmMYmk66gigAAAFg"]
[Mon Jul 27 10:56:00.038482 2026] [:error] [pid 12276:tid 140706827896576] [client 172.71.152.83:9981] [client 172.71.152.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.js"] [unique_id "amcdIOcsEMuHmMYmk66gigAAAFg"]
[Mon Jul 27 10:56:00.039145 2026] [:error] [pid 12276:tid 140706827896576] [client 172.71.152.83:9981] [client 172.71.152.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.js"] [unique_id "amcdIOcsEMuHmMYmk66gigAAAFg"]
[Mon Jul 27 10:56:00.982033 2026] [:error] [pid 12380:tid 140706953787136] [client 104.23.175.149:10779] [client 104.23.175.149] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcdIKaChfbWW0CZ_hoj2wAAAMk"]
[Mon Jul 27 10:56:00.982436 2026] [:error] [pid 12380:tid 140706953787136] [client 104.23.175.149:10779] [client 104.23.175.149] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcdIKaChfbWW0CZ_hoj2wAAAMk"]
[Mon Jul 27 10:56:00.982797 2026] [:error] [pid 12380:tid 140706953787136] [client 104.23.175.149:10779] [client 104.23.175.149] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcdIKaChfbWW0CZ_hoj2wAAAMk"]
[Mon Jul 27 10:56:01.927600 2026] [:error] [pid 12276:tid 140706995750656] [client 172.70.208.77:9318] [client 172.70.208.77] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/settings.js"] [unique_id "amcdIecsEMuHmMYmk66gkAAAAEQ"]
[Mon Jul 27 10:56:01.928431 2026] [:error] [pid 12276:tid 140706995750656] [client 172.70.208.77:9318] [client 172.70.208.77] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/settings.js"] [unique_id "amcdIecsEMuHmMYmk66gkAAAAEQ"]
[Mon Jul 27 10:56:01.928959 2026] [:error] [pid 12276:tid 140706995750656] [client 172.70.208.77:9318] [client 172.70.208.77] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/settings.js"] [unique_id "amcdIecsEMuHmMYmk66gkAAAAEQ"]
[Mon Jul 27 10:56:02.878776 2026] [:error] [pid 12275:tid 140706869860096] [client 104.23.175.22:12949] [client 104.23.175.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/settings.json"] [unique_id "amcdInFwI8r7BFXGkAulKgAAABM"]
[Mon Jul 27 10:56:02.879388 2026] [:error] [pid 12275:tid 140706869860096] [client 104.23.175.22:12949] [client 104.23.175.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/settings.json"] [unique_id "amcdInFwI8r7BFXGkAulKgAAABM"]
[Mon Jul 27 10:56:02.879785 2026] [:error] [pid 12275:tid 140706869860096] [client 104.23.175.22:12949] [client 104.23.175.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/settings.json"] [unique_id "amcdInFwI8r7BFXGkAulKgAAABM"]
[Mon Jul 27 10:56:03.821623 2026] [:error] [pid 12275:tid 140706895038208] [client 172.70.92.192:13058] [client 172.70.92.192] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcdI3FwI8r7BFXGkAulKwAAABA"]
[Mon Jul 27 10:56:03.822741 2026] [:error] [pid 12275:tid 140706895038208] [client 172.70.92.192:13058] [client 172.70.92.192] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcdI3FwI8r7BFXGkAulKwAAABA"]
[Mon Jul 27 10:56:03.823290 2026] [:error] [pid 12275:tid 140706895038208] [client 172.70.92.192:13058] [client 172.70.92.192] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcdI3FwI8r7BFXGkAulKwAAABA"]
[Mon Jul 27 10:56:04.291502 2026] [:error] [pid 12275:tid 140707020928768] [client 104.23.175.22:12949] [client 104.23.175.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/credentials.json"] [unique_id "amcdJHFwI8r7BFXGkAulLAAAAAE"]
[Mon Jul 27 10:56:04.292254 2026] [:error] [pid 12275:tid 140707020928768] [client 104.23.175.22:12949] [client 104.23.175.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/credentials.json"] [unique_id "amcdJHFwI8r7BFXGkAulLAAAAAE"]
[Mon Jul 27 10:56:04.292652 2026] [:error] [pid 12275:tid 140707020928768] [client 104.23.175.22:12949] [client 104.23.175.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/credentials.json"] [unique_id "amcdJHFwI8r7BFXGkAulLAAAAAE"]
[Mon Jul 27 10:56:04.757415 2026] [:error] [pid 12275:tid 140706853074688] [client 172.70.92.192:13058] [client 172.70.92.192] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cdp_api_key.json"] [unique_id "amcdJHFwI8r7BFXGkAulLQAAABU"]
[Mon Jul 27 10:56:04.758076 2026] [:error] [pid 12275:tid 140706853074688] [client 172.70.92.192:13058] [client 172.70.92.192] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cdp_api_key.json"] [unique_id "amcdJHFwI8r7BFXGkAulLQAAABU"]
[Mon Jul 27 10:56:04.758457 2026] [:error] [pid 12275:tid 140706853074688] [client 172.70.92.192:13058] [client 172.70.92.192] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cdp_api_key.json"] [unique_id "amcdJHFwI8r7BFXGkAulLQAAABU"]
[Mon Jul 27 10:56:05.714629 2026] [:error] [pid 12275:tid 140706827896576] [client 172.70.189.28:12559] [client 172.70.189.28] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/app.js"] [unique_id "amcdJXFwI8r7BFXGkAulLgAAABg"]
[Mon Jul 27 10:56:05.715383 2026] [:error] [pid 12275:tid 140706827896576] [client 172.70.189.28:12559] [client 172.70.189.28] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/app.js"] [unique_id "amcdJXFwI8r7BFXGkAulLgAAABg"]
[Mon Jul 27 10:56:05.715938 2026] [:error] [pid 12275:tid 140706827896576] [client 172.70.189.28:12559] [client 172.70.189.28] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/app.js"] [unique_id "amcdJXFwI8r7BFXGkAulLgAAABg"]
[Mon Jul 27 10:56:06.694424 2026] [:error] [pid 24106:tid 140706844681984] [client 172.69.176.143:13229] [client 172.69.176.143] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/main.js"] [unique_id "amcdJjs8oMu6f6EYbxTMkAAAAVY"]
[Mon Jul 27 10:56:06.695136 2026] [:error] [pid 24106:tid 140706844681984] [client 172.69.176.143:13229] [client 172.69.176.143] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/main.js"] [unique_id "amcdJjs8oMu6f6EYbxTMkAAAAVY"]
[Mon Jul 27 10:56:06.695517 2026] [:error] [pid 24106:tid 140706844681984] [client 172.69.176.143:13229] [client 172.69.176.143] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/main.js"] [unique_id "amcdJjs8oMu6f6EYbxTMkAAAAVY"]
[Mon Jul 27 10:56:07.653635 2026] [:error] [pid 12380:tid 140706844681984] [client 172.70.208.118:11225] [client 172.70.208.118] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/index.js"] [unique_id "amcdJ6aChfbWW0CZ_hokBQAAANY"]
[Mon Jul 27 10:56:07.654246 2026] [:error] [pid 12380:tid 140706844681984] [client 172.70.208.118:11225] [client 172.70.208.118] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/index.js"] [unique_id "amcdJ6aChfbWW0CZ_hokBQAAANY"]
[Mon Jul 27 10:56:07.654624 2026] [:error] [pid 12380:tid 140706844681984] [client 172.70.208.118:11225] [client 172.70.208.118] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/index.js"] [unique_id "amcdJ6aChfbWW0CZ_hokBQAAANY"]
[Mon Jul 27 10:56:08.594184 2026] [:error] [pid 21545:tid 140706895038208] [client 108.162.226.146:10247] [client 108.162.226.146] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/server.js"] [unique_id "amcdKJhXfYDIcpslIWOxHQAAAZA"]
[Mon Jul 27 10:56:08.595113 2026] [:error] [pid 21545:tid 140706895038208] [client 108.162.226.146:10247] [client 108.162.226.146] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/server.js"] [unique_id "amcdKJhXfYDIcpslIWOxHQAAAZA"]
[Mon Jul 27 10:56:08.595637 2026] [:error] [pid 21545:tid 140706895038208] [client 108.162.226.146:10247] [client 108.162.226.146] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/server.js"] [unique_id "amcdKJhXfYDIcpslIWOxHQAAAZA"]
[Mon Jul 27 10:56:09.567384 2026] [:error] [pid 12380:tid 140706953787136] [client 162.158.189.183:11688] [client 162.158.189.183] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/bundle.js"] [unique_id "amcdKaaChfbWW0CZ_hokFQAAAMk"]
[Mon Jul 27 10:56:09.568499 2026] [:error] [pid 12380:tid 140706953787136] [client 162.158.189.183:11688] [client 162.158.189.183] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/bundle.js"] [unique_id "amcdKaaChfbWW0CZ_hokFQAAAMk"]
[Mon Jul 27 10:56:09.569097 2026] [:error] [pid 12380:tid 140706953787136] [client 162.158.189.183:11688] [client 162.158.189.183] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/bundle.js"] [unique_id "amcdKaaChfbWW0CZ_hokFQAAAMk"]
[Mon Jul 27 10:56:10.540667 2026] [:error] [pid 12380:tid 140706869860096] [client 104.22.66.106:9516] [client 104.22.66.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/app.bundle.js"] [unique_id "amcdKqaChfbWW0CZ_hokHAAAANM"]
[Mon Jul 27 10:56:10.541418 2026] [:error] [pid 12380:tid 140706869860096] [client 104.22.66.106:9516] [client 104.22.66.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/app.bundle.js"] [unique_id "amcdKqaChfbWW0CZ_hokHAAAANM"]
[Mon Jul 27 10:56:10.541807 2026] [:error] [pid 12380:tid 140706869860096] [client 104.22.66.106:9516] [client 104.22.66.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/app.bundle.js"] [unique_id "amcdKqaChfbWW0CZ_hokHAAAANM"]
[Mon Jul 27 10:56:11.512951 2026] [:error] [pid 24106:tid 140706878252800] [client 162.158.88.15:11253] [client 162.158.88.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/main.bundle.js"] [unique_id "amcdKzs8oMu6f6EYbxTMqQAAAVI"]
[Mon Jul 27 10:56:11.513739 2026] [:error] [pid 24106:tid 140706878252800] [client 162.158.88.15:11253] [client 162.158.88.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/main.bundle.js"] [unique_id "amcdKzs8oMu6f6EYbxTMqQAAAVI"]
[Mon Jul 27 10:56:11.514104 2026] [:error] [pid 24106:tid 140706878252800] [client 162.158.88.15:11253] [client 162.158.88.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/main.bundle.js"] [unique_id "amcdKzs8oMu6f6EYbxTMqQAAAVI"]
[Mon Jul 27 10:56:12.453993 2026] [:error] [pid 24106:tid 140706911823616] [client 104.23.175.100:9822] [client 104.23.175.100] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/vendor.js"] [unique_id "amcdLDs8oMu6f6EYbxTMrgAAAU4"]
[Mon Jul 27 10:56:12.454824 2026] [:error] [pid 24106:tid 140706911823616] [client 104.23.175.100:9822] [client 104.23.175.100] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/vendor.js"] [unique_id "amcdLDs8oMu6f6EYbxTMrgAAAU4"]
[Mon Jul 27 10:56:12.455214 2026] [:error] [pid 24106:tid 140706911823616] [client 104.23.175.100:9822] [client 104.23.175.100] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/vendor.js"] [unique_id "amcdLDs8oMu6f6EYbxTMrgAAAU4"]
[Mon Jul 27 10:56:13.418515 2026] [:error] [pid 12380:tid 140706945394432] [client 162.158.162.132:11069] [client 162.158.162.132] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/chunk.js"] [unique_id "amcdLaaChfbWW0CZ_hokMwAAAMo"]
[Mon Jul 27 10:56:13.419951 2026] [:error] [pid 12380:tid 140706945394432] [client 162.158.162.132:11069] [client 162.158.162.132] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/chunk.js"] [unique_id "amcdLaaChfbWW0CZ_hokMwAAAMo"]
[Mon Jul 27 10:56:13.420681 2026] [:error] [pid 12380:tid 140706945394432] [client 162.158.162.132:11069] [client 162.158.162.132] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/chunk.js"] [unique_id "amcdLaaChfbWW0CZ_hokMwAAAMo"]
[Mon Jul 27 10:56:14.381793 2026] [:error] [pid 12380:tid 140706895038208] [client 108.162.226.14:10698] [client 108.162.226.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/static/js/main.js"] [unique_id "amcdLqaChfbWW0CZ_hokPwAAANA"]
[Mon Jul 27 10:56:14.382769 2026] [:error] [pid 12380:tid 140706895038208] [client 108.162.226.14:10698] [client 108.162.226.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/static/js/main.js"] [unique_id "amcdLqaChfbWW0CZ_hokPwAAANA"]
[Mon Jul 27 10:56:14.383309 2026] [:error] [pid 12380:tid 140706895038208] [client 108.162.226.14:10698] [client 108.162.226.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/static/js/main.js"] [unique_id "amcdLqaChfbWW0CZ_hokPwAAANA"]
[Mon Jul 27 10:56:15.347801 2026] [:error] [pid 12275:tid 140706861467392] [client 172.69.166.121:11876] [client 172.69.166.121] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/static/js/app.js"] [unique_id "amcdL3FwI8r7BFXGkAulOAAAABQ"]
[Mon Jul 27 10:56:15.348647 2026] [:error] [pid 12275:tid 140706861467392] [client 172.69.166.121:11876] [client 172.69.166.121] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/static/js/app.js"] [unique_id "amcdL3FwI8r7BFXGkAulOAAAABQ"]
[Mon Jul 27 10:56:15.349069 2026] [:error] [pid 12275:tid 140706861467392] [client 172.69.166.121:11876] [client 172.69.166.121] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/static/js/app.js"] [unique_id "amcdL3FwI8r7BFXGkAulOAAAABQ"]
[Mon Jul 27 10:56:16.300237 2026] [:error] [pid 24106:tid 140706937001728] [client 162.158.163.209:14331] [client 162.158.163.209] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/static/js/bundle.js"] [unique_id "amcdMDs8oMu6f6EYbxTMxgAAAUs"]
[Mon Jul 27 10:56:16.301071 2026] [:error] [pid 24106:tid 140706937001728] [client 162.158.163.209:14331] [client 162.158.163.209] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/static/js/bundle.js"] [unique_id "amcdMDs8oMu6f6EYbxTMxgAAAUs"]
[Mon Jul 27 10:56:16.301602 2026] [:error] [pid 24106:tid 140706937001728] [client 162.158.163.209:14331] [client 162.158.163.209] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/static/js/bundle.js"] [unique_id "amcdMDs8oMu6f6EYbxTMxgAAAUs"]
[Mon Jul 27 10:56:17.289599 2026] [:error] [pid 12276:tid 140706869860096] [client 172.69.176.6:13013] [client 172.69.176.6] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/dist/main.js"] [unique_id "amcdMecsEMuHmMYmk66gqwAAAFM"]
[Mon Jul 27 10:56:17.290464 2026] [:error] [pid 12276:tid 140706869860096] [client 172.69.176.6:13013] [client 172.69.176.6] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/dist/main.js"] [unique_id "amcdMecsEMuHmMYmk66gqwAAAFM"]
[Mon Jul 27 10:56:17.290989 2026] [:error] [pid 12276:tid 140706869860096] [client 172.69.176.6:13013] [client 172.69.176.6] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/dist/main.js"] [unique_id "amcdMecsEMuHmMYmk66gqwAAAFM"]
[Mon Jul 27 10:56:18.234791 2026] [:error] [pid 12380:tid 140706836289280] [client 172.70.142.185:9235] [client 172.70.142.185] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/dist/app.js"] [unique_id "amcdMqaChfbWW0CZ_hokVwAAANc"]
[Mon Jul 27 10:56:18.235650 2026] [:error] [pid 12380:tid 140706836289280] [client 172.70.142.185:9235] [client 172.70.142.185] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/dist/app.js"] [unique_id "amcdMqaChfbWW0CZ_hokVwAAANc"]
[Mon Jul 27 10:56:18.236142 2026] [:error] [pid 12380:tid 140706836289280] [client 172.70.142.185:9235] [client 172.70.142.185] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/dist/app.js"] [unique_id "amcdMqaChfbWW0CZ_hokVwAAANc"]
[Mon Jul 27 10:56:19.204346 2026] [:error] [pid 12276:tid 140706995750656] [client 172.70.93.11:11239] [client 172.70.93.11] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/dist/bundle.js"] [unique_id "amcdM-csEMuHmMYmk66grAAAAEQ"]
[Mon Jul 27 10:56:19.205168 2026] [:error] [pid 12276:tid 140706995750656] [client 172.70.93.11:11239] [client 172.70.93.11] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/dist/bundle.js"] [unique_id "amcdM-csEMuHmMYmk66grAAAAEQ"]
[Mon Jul 27 10:56:19.205670 2026] [:error] [pid 12276:tid 140706995750656] [client 172.70.93.11:11239] [client 172.70.93.11] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/dist/bundle.js"] [unique_id "amcdM-csEMuHmMYmk66grAAAAEQ"]
[Mon Jul 27 10:56:20.209827 2026] [:error] [pid 24106:tid 140707103270656] [client 172.69.176.78:11033] [client 172.69.176.78] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/build/static/js/main.js"] [unique_id "amcdNDs8oMu6f6EYbxTM4gAAAUA"]
[Mon Jul 27 10:56:20.210641 2026] [:error] [pid 24106:tid 140707103270656] [client 172.69.176.78:11033] [client 172.69.176.78] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/build/static/js/main.js"] [unique_id "amcdNDs8oMu6f6EYbxTM4gAAAUA"]
[Mon Jul 27 10:56:20.211118 2026] [:error] [pid 24106:tid 140707103270656] [client 172.69.176.78:11033] [client 172.69.176.78] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/build/static/js/main.js"] [unique_id "amcdNDs8oMu6f6EYbxTM4gAAAUA"]
[Mon Jul 27 10:56:21.202479 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.162.87:11404] [client 162.158.162.87] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/assets/index.js"] [unique_id "amcdNRwjcb8HQE21kA6lOQAAAIM"]
[Mon Jul 27 10:56:21.203476 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.162.87:11404] [client 162.158.162.87] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/assets/index.js"] [unique_id "amcdNRwjcb8HQE21kA6lOQAAAIM"]
[Mon Jul 27 10:56:21.204072 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.162.87:11404] [client 162.158.162.87] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/assets/index.js"] [unique_id "amcdNRwjcb8HQE21kA6lOQAAAIM"]
[Mon Jul 27 10:56:22.157271 2026] [:error] [pid 24106:tid 140706945394432] [client 172.68.242.48:10398] [client 172.68.242.48] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/assets/app.js"] [unique_id "amcdNjs8oMu6f6EYbxTM8AAAAUo"]
[Mon Jul 27 10:56:22.157919 2026] [:error] [pid 24106:tid 140706945394432] [client 172.68.242.48:10398] [client 172.68.242.48] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/assets/app.js"] [unique_id "amcdNjs8oMu6f6EYbxTM8AAAAUo"]
[Mon Jul 27 10:56:22.158268 2026] [:error] [pid 24106:tid 140706945394432] [client 172.68.242.48:10398] [client 172.68.242.48] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/assets/app.js"] [unique_id "amcdNjs8oMu6f6EYbxTM8AAAAUo"]
[Mon Jul 27 10:56:23.104258 2026] [:error] [pid 12380:tid 140706978965248] [client 104.23.175.197:13372] [client 104.23.175.197] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/js/app.js"] [unique_id "amcdN6aChfbWW0CZ_hokfgAAAMY"]
[Mon Jul 27 10:56:23.104946 2026] [:error] [pid 12380:tid 140706978965248] [client 104.23.175.197:13372] [client 104.23.175.197] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/js/app.js"] [unique_id "amcdN6aChfbWW0CZ_hokfgAAAMY"]
[Mon Jul 27 10:56:23.105321 2026] [:error] [pid 12380:tid 140706978965248] [client 104.23.175.197:13372] [client 104.23.175.197] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/js/app.js"] [unique_id "amcdN6aChfbWW0CZ_hokfgAAAMY"]
[Mon Jul 27 10:56:24.077883 2026] [:error] [pid 21545:tid 140706920216320] [client 104.22.66.21:10795] [client 104.22.66.21] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/js/main.js"] [unique_id "amcdOJhXfYDIcpslIWOxJwAAAY0"]
[Mon Jul 27 10:56:24.078796 2026] [:error] [pid 21545:tid 140706920216320] [client 104.22.66.21:10795] [client 104.22.66.21] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/js/main.js"] [unique_id "amcdOJhXfYDIcpslIWOxJwAAAY0"]
[Mon Jul 27 10:56:24.079263 2026] [:error] [pid 21545:tid 140706920216320] [client 104.22.66.21:10795] [client 104.22.66.21] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/js/main.js"] [unique_id "amcdOJhXfYDIcpslIWOxJwAAAY0"]
[Mon Jul 27 10:56:25.067174 2026] [:error] [pid 12380:tid 140706945394432] [client 172.69.165.62:13334] [client 172.69.165.62] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/settings.py"] [unique_id "amcdOaaChfbWW0CZ_hokigAAAMo"]
[Mon Jul 27 10:56:25.067909 2026] [:error] [pid 12380:tid 140706945394432] [client 172.69.165.62:13334] [client 172.69.165.62] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/settings.py"] [unique_id "amcdOaaChfbWW0CZ_hokigAAAMo"]
[Mon Jul 27 10:56:25.068287 2026] [:error] [pid 12380:tid 140706945394432] [client 172.69.165.62:13334] [client 172.69.165.62] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/settings.py"] [unique_id "amcdOaaChfbWW0CZ_hokigAAAMo"]
[Mon Jul 27 10:56:26.009565 2026] [:error] [pid 21545:tid 140706962179840] [client 172.70.92.192:13005] [client 172.70.92.192] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.py"] [unique_id "amcdOphXfYDIcpslIWOxKQAAAYg"]
[Mon Jul 27 10:56:26.010439 2026] [:error] [pid 21545:tid 140706962179840] [client 172.70.92.192:13005] [client 172.70.92.192] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.py"] [unique_id "amcdOphXfYDIcpslIWOxKQAAAYg"]
[Mon Jul 27 10:56:26.010955 2026] [:error] [pid 21545:tid 140706962179840] [client 172.70.92.192:13005] [client 172.70.92.192] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.py"] [unique_id "amcdOphXfYDIcpslIWOxKQAAAYg"]
[Mon Jul 27 10:56:26.506865 2026] [:error] [pid 12380:tid 140706869860096] [client 172.69.165.62:13334] [client 172.69.165.62] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/secrets.py"] [unique_id "amcdOqaChfbWW0CZ_hokkQAAANM"]
[Mon Jul 27 10:56:26.508167 2026] [:error] [pid 12380:tid 140706869860096] [client 172.69.165.62:13334] [client 172.69.165.62] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/secrets.py"] [unique_id "amcdOqaChfbWW0CZ_hokkQAAANM"]
[Mon Jul 27 10:56:26.508784 2026] [:error] [pid 12380:tid 140706869860096] [client 172.69.165.62:13334] [client 172.69.165.62] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/secrets.py"] [unique_id "amcdOqaChfbWW0CZ_hokkQAAANM"]
[Mon Jul 27 10:56:26.970413 2026] [:error] [pid 21545:tid 140707004143360] [client 172.70.92.192:13005] [client 172.70.92.192] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config/secrets.yml"] [unique_id "amcdOphXfYDIcpslIWOxKgAAAYM"]
[Mon Jul 27 10:56:26.971341 2026] [:error] [pid 21545:tid 140707004143360] [client 172.70.92.192:13005] [client 172.70.92.192] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config/secrets.yml"] [unique_id "amcdOphXfYDIcpslIWOxKgAAAYM"]
[Mon Jul 27 10:56:26.971943 2026] [:error] [pid 21545:tid 140707004143360] [client 172.70.92.192:13005] [client 172.70.92.192] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config/secrets.yml"] [unique_id "amcdOphXfYDIcpslIWOxKgAAAYM"]
[Mon Jul 27 10:56:27.442817 2026] [:error] [pid 12380:tid 140706886645504] [client 172.69.165.62:13334] [client 172.69.165.62] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config/master.key"] [unique_id "amcdO6aChfbWW0CZ_hoklgAAANE"]
[Mon Jul 27 10:56:27.443838 2026] [:error] [pid 12380:tid 140706886645504] [client 172.69.165.62:13334] [client 172.69.165.62] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config/master.key"] [unique_id "amcdO6aChfbWW0CZ_hoklgAAANE"]
[Mon Jul 27 10:56:27.444385 2026] [:error] [pid 12380:tid 140706886645504] [client 172.69.165.62:13334] [client 172.69.165.62] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config/master.key"] [unique_id "amcdO6aChfbWW0CZ_hoklgAAANE"]
[Mon Jul 27 10:58:09.031944 2026] [:error] [pid 21545:tid 140706886645504] [client 104.23.162.72:12199] [client 104.23.162.72] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcdoZhXfYDIcpslIWOxwgAAAZE"]
[Mon Jul 27 10:58:09.032549 2026] [:error] [pid 21545:tid 140706886645504] [client 104.23.162.72:12199] [client 104.23.162.72] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcdoZhXfYDIcpslIWOxwgAAAZE"]
[Mon Jul 27 10:58:09.032918 2026] [:error] [pid 21545:tid 140706886645504] [client 104.23.162.72:12199] [client 104.23.162.72] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcdoZhXfYDIcpslIWOxwgAAAZE"]
[Mon Jul 27 10:58:47.380318 2026] [:error] [pid 12277:tid 140706962179840] [client 172.68.51.12:12181] [client 172.68.51.12] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcdxxwjcb8HQE21kA6lhAAAAIg"]
[Mon Jul 27 10:58:47.380955 2026] [:error] [pid 12277:tid 140706962179840] [client 172.68.51.12:12181] [client 172.68.51.12] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcdxxwjcb8HQE21kA6lhAAAAIg"]
[Mon Jul 27 10:58:47.381360 2026] [:error] [pid 12277:tid 140706962179840] [client 172.68.51.12:12181] [client 172.68.51.12] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcdxxwjcb8HQE21kA6lhAAAAIg"]
[Mon Jul 27 10:58:56.429779 2026] [:error] [pid 12380:tid 140706878252800] [client 172.68.51.11:10136] [client 172.68.51.11] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcd0KaChfbWW0CZ_hopmQAAANI"]
[Mon Jul 27 10:58:56.430362 2026] [:error] [pid 12380:tid 140706878252800] [client 172.68.51.11:10136] [client 172.68.51.11] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcd0KaChfbWW0CZ_hopmQAAANI"]
[Mon Jul 27 10:58:56.430794 2026] [:error] [pid 12380:tid 140706878252800] [client 172.68.51.11:10136] [client 172.68.51.11] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcd0KaChfbWW0CZ_hopmQAAANI"]
[Mon Jul 27 11:02:10.898673 2026] [:error] [pid 24106:tid 140706844681984] [client 162.158.167.20:10558] [client 162.158.167.20] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcekjs8oMu6f6EYbxTTRQAAAVY"]
[Mon Jul 27 11:02:10.899897 2026] [:error] [pid 24106:tid 140706844681984] [client 162.158.167.20:10558] [client 162.158.167.20] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcekjs8oMu6f6EYbxTTRQAAAVY"]
[Mon Jul 27 11:02:10.900733 2026] [:error] [pid 24106:tid 140706844681984] [client 162.158.167.20:10558] [client 162.158.167.20] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcekjs8oMu6f6EYbxTTRQAAAVY"]
[Mon Jul 27 11:02:10.900817 2026] [:error] [pid 24106:tid 140706844681984] [client 162.158.167.20:10558] [client 162.158.167.20] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcekjs8oMu6f6EYbxTTRQAAAVY"]
[Mon Jul 27 11:02:11.221745 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.167.132:11906] [client 162.158.167.132] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcek6aChfbWW0CZ_hovQwAAAM0"], referer: http://www.sbf-consultancy.com/
[Mon Jul 27 11:02:11.222787 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.167.132:11906] [client 162.158.167.132] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcek6aChfbWW0CZ_hovQwAAAM0"], referer: http://www.sbf-consultancy.com/
[Mon Jul 27 11:02:11.223706 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.167.132:11906] [client 162.158.167.132] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcek6aChfbWW0CZ_hovQwAAAM0"], referer: http://www.sbf-consultancy.com/
[Mon Jul 27 11:02:11.223769 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.167.132:11906] [client 162.158.167.132] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcek6aChfbWW0CZ_hovQwAAAM0"], referer: http://www.sbf-consultancy.com/
[Mon Jul 27 11:02:11.928934 2026] [:error] [pid 24106:tid 140707004143360] [client 162.158.167.19:13394] [client 162.158.167.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcekzs8oMu6f6EYbxTTRgAAAUM"]
[Mon Jul 27 11:02:11.929855 2026] [:error] [pid 24106:tid 140707004143360] [client 162.158.167.19:13394] [client 162.158.167.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcekzs8oMu6f6EYbxTTRgAAAUM"]
[Mon Jul 27 11:02:11.930944 2026] [:error] [pid 24106:tid 140707004143360] [client 162.158.167.19:13394] [client 162.158.167.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcekzs8oMu6f6EYbxTTRgAAAUM"]
[Mon Jul 27 11:02:11.931072 2026] [:error] [pid 24106:tid 140707004143360] [client 162.158.167.19:13394] [client 162.158.167.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcekzs8oMu6f6EYbxTTRgAAAUM"]
[Mon Jul 27 11:02:12.699876 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.167.131:11722] [client 162.158.167.131] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcelHFwI8r7BFXGkAupNwAAABM"], referer: https://www.sbf-consultancy.com/
[Mon Jul 27 11:02:12.700751 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.167.131:11722] [client 162.158.167.131] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcelHFwI8r7BFXGkAupNwAAABM"], referer: https://www.sbf-consultancy.com/
[Mon Jul 27 11:02:12.701409 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.167.131:11722] [client 162.158.167.131] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcelHFwI8r7BFXGkAupNwAAABM"], referer: https://www.sbf-consultancy.com/
[Mon Jul 27 11:02:12.701460 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.167.131:11722] [client 162.158.167.131] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amcelHFwI8r7BFXGkAupNwAAABM"], referer: https://www.sbf-consultancy.com/
[Mon Jul 27 11:02:16.346924 2026] [:error] [pid 24106:tid 140706844681984] [client 172.71.158.125:14168] [client 172.71.158.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcemDs8oMu6f6EYbxTTTgAAAVY"]
[Mon Jul 27 11:02:16.347829 2026] [:error] [pid 24106:tid 140706844681984] [client 172.71.158.125:14168] [client 172.71.158.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcemDs8oMu6f6EYbxTTTgAAAVY"]
[Mon Jul 27 11:02:16.348420 2026] [:error] [pid 24106:tid 140706844681984] [client 172.71.158.125:14168] [client 172.71.158.125] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcemDs8oMu6f6EYbxTTTgAAAVY"]
[Mon Jul 27 11:02:17.044827 2026] [:error] [pid 24106:tid 140707103270656] [client 104.22.20.116:14073] [client 104.22.20.116] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcemTs8oMu6f6EYbxTTTwAAAUA"]
[Mon Jul 27 11:02:17.045870 2026] [:error] [pid 24106:tid 140707103270656] [client 104.22.20.116:14073] [client 104.22.20.116] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcemTs8oMu6f6EYbxTTTwAAAUA"]
[Mon Jul 27 11:02:17.046656 2026] [:error] [pid 24106:tid 140707103270656] [client 104.22.20.116:14073] [client 104.22.20.116] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcemTs8oMu6f6EYbxTTTwAAAUA"]
[Mon Jul 27 11:02:17.046722 2026] [:error] [pid 24106:tid 140707103270656] [client 104.22.20.116:14073] [client 104.22.20.116] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcemTs8oMu6f6EYbxTTTwAAAUA"]
[Mon Jul 27 11:02:42.369467 2026] [:error] [pid 17228:tid 140706953787136] [client 162.158.63.138:13591] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcespjBQLO4t9VCDfpF3AAAAQk"]
[Mon Jul 27 11:02:42.370179 2026] [:error] [pid 17228:tid 140706953787136] [client 162.158.63.138:13591] [client 162.158.63.138] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcespjBQLO4t9VCDfpF3AAAAQk"]
[Mon Jul 27 11:02:42.370545 2026] [:error] [pid 17228:tid 140706953787136] [client 162.158.63.138:13591] [client 162.158.63.138] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcespjBQLO4t9VCDfpF3AAAAQk"]
[Mon Jul 27 11:02:42.370649 2026] [:error] [pid 17228:tid 140706953787136] [client 162.158.63.138:13591] [client 162.158.63.138] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcespjBQLO4t9VCDfpF3AAAAQk"]
[Mon Jul 27 11:02:47.250286 2026] [:error] [pid 12380:tid 140707004143360] [client 172.70.222.242:13086] [client 172.70.222.242] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcet6aChfbWW0CZ_hovxAAAAMM"], referer: https://sbf-consultancy.com/
[Mon Jul 27 11:02:47.250965 2026] [:error] [pid 12380:tid 140707004143360] [client 172.70.222.242:13086] [client 172.70.222.242] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcet6aChfbWW0CZ_hovxAAAAMM"], referer: https://sbf-consultancy.com/
[Mon Jul 27 11:02:47.251468 2026] [:error] [pid 12380:tid 140707004143360] [client 172.70.222.242:13086] [client 172.70.222.242] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcet6aChfbWW0CZ_hovxAAAAMM"], referer: https://sbf-consultancy.com/
[Mon Jul 27 11:04:58.724743 2026] [:error] [pid 12276:tid 140706920216320] [client 172.71.103.42:13866] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcfOucsEMuHmMYmk66jvwAAAE0"]
[Mon Jul 27 11:04:58.725740 2026] [:error] [pid 12276:tid 140706920216320] [client 172.71.103.42:13866] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcfOucsEMuHmMYmk66jvwAAAE0"]
[Mon Jul 27 11:04:58.726299 2026] [:error] [pid 12276:tid 140706920216320] [client 172.71.103.42:13866] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcfOucsEMuHmMYmk66jvwAAAE0"]
[Mon Jul 27 11:05:02.046505 2026] [:error] [pid 12380:tid 140706962179840] [client 172.71.190.19:11456] [client 172.71.190.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcfPqaChfbWW0CZ_hozEQAAAMg"]
[Mon Jul 27 11:05:02.047329 2026] [:error] [pid 12380:tid 140706962179840] [client 172.71.190.19:11456] [client 172.71.190.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcfPqaChfbWW0CZ_hozEQAAAMg"]
[Mon Jul 27 11:05:02.047853 2026] [:error] [pid 12380:tid 140706962179840] [client 172.71.190.19:11456] [client 172.71.190.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcfPqaChfbWW0CZ_hozEQAAAMg"]
[Mon Jul 27 11:10:42.779433 2026] [:error] [pid 24106:tid 140706903430912] [client 172.69.39.56:13634] [client 172.69.39.56] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcgkjs8oMu6f6EYbxTbVgAAAU8"]
[Mon Jul 27 11:10:42.780269 2026] [:error] [pid 24106:tid 140706903430912] [client 172.69.39.56:13634] [client 172.69.39.56] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcgkjs8oMu6f6EYbxTbVgAAAU8"]
[Mon Jul 27 11:10:42.780738 2026] [:error] [pid 24106:tid 140706903430912] [client 172.69.39.56:13634] [client 172.69.39.56] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcgkjs8oMu6f6EYbxTbVgAAAU8"]
[Mon Jul 27 11:10:42.780772 2026] [:error] [pid 24106:tid 140706903430912] [client 172.69.39.56:13634] [client 172.69.39.56] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcgkjs8oMu6f6EYbxTbVgAAAU8"]
[Mon Jul 27 11:10:44.434061 2026] [:error] [pid 12380:tid 140706861467392] [client 172.69.11.133:11813] [client 172.69.11.133] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcglKaChfbWW0CZ_ho7uQAAANQ"]
[Mon Jul 27 11:10:44.435171 2026] [:error] [pid 12380:tid 140706861467392] [client 172.69.11.133:11813] [client 172.69.11.133] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcglKaChfbWW0CZ_ho7uQAAANQ"]
[Mon Jul 27 11:10:44.435693 2026] [:error] [pid 12380:tid 140706861467392] [client 172.69.11.133:11813] [client 172.69.11.133] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcglKaChfbWW0CZ_ho7uQAAANQ"]
[Mon Jul 27 11:11:01.970165 2026] [:error] [pid 12380:tid 140706928609024] [client 162.158.49.4:14318] [client 162.158.49.4] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcgpaaChfbWW0CZ_ho8SgAAAMw"]
[Mon Jul 27 11:11:01.970633 2026] [:error] [pid 12380:tid 140706928609024] [client 162.158.49.4:14318] [client 162.158.49.4] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcgpaaChfbWW0CZ_ho8SgAAAMw"]
[Mon Jul 27 11:11:01.970892 2026] [:error] [pid 12380:tid 140706928609024] [client 162.158.49.4:14318] [client 162.158.49.4] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcgpaaChfbWW0CZ_ho8SgAAAMw"]
[Mon Jul 27 11:11:02.054680 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.49.100:11415] [client 162.158.49.100] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcgpucsEMuHmMYmk66l7AAAAFc"]
[Mon Jul 27 11:11:02.055571 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.49.100:11415] [client 162.158.49.100] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcgpucsEMuHmMYmk66l7AAAAFc"]
[Mon Jul 27 11:11:02.056083 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.49.100:11415] [client 162.158.49.100] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcgpucsEMuHmMYmk66l7AAAAFc"]
[Mon Jul 27 11:20:10.215269 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.238.60:11659] [client 172.71.238.60] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amciyphXfYDIcpslIWO6WQAAAYE"]
[Mon Jul 27 11:20:10.216188 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.238.60:11659] [client 172.71.238.60] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amciyphXfYDIcpslIWO6WQAAAYE"]
[Mon Jul 27 11:20:10.216884 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.238.60:11659] [client 172.71.238.60] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amciyphXfYDIcpslIWO6WQAAAYE"]
[Mon Jul 27 11:20:10.216938 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.238.60:11659] [client 172.71.238.60] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amciyphXfYDIcpslIWO6WQAAAYE"]
[Mon Jul 27 11:20:11.605128 2026] [:error] [pid 12275:tid 140706920216320] [client 172.69.11.132:13146] [client 172.69.11.132] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amciy3FwI8r7BFXGkAuzFgAAAA0"]
[Mon Jul 27 11:20:11.606096 2026] [:error] [pid 12275:tid 140706920216320] [client 172.69.11.132:13146] [client 172.69.11.132] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amciy3FwI8r7BFXGkAuzFgAAAA0"]
[Mon Jul 27 11:20:11.606748 2026] [:error] [pid 12275:tid 140706920216320] [client 172.69.11.132:13146] [client 172.69.11.132] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amciy3FwI8r7BFXGkAuzFgAAAA0"]
[Mon Jul 27 11:20:23.749999 2026] [:error] [pid 12275:tid 140706962179840] [client 172.69.59.27:13944] [client 172.69.59.27] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amci13FwI8r7BFXGkAuzKQAAAAg"]
[Mon Jul 27 11:20:23.750993 2026] [:error] [pid 12275:tid 140706962179840] [client 172.69.59.27:13944] [client 172.69.59.27] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amci13FwI8r7BFXGkAuzKQAAAAg"]
[Mon Jul 27 11:20:23.751937 2026] [:error] [pid 12275:tid 140706962179840] [client 172.69.59.27:13944] [client 172.69.59.27] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amci13FwI8r7BFXGkAuzKQAAAAg"]
[Mon Jul 27 11:25:32.665000 2026] [:error] [pid 24106:tid 140706953787136] [client 172.71.22.169:9235] [client 172.71.22.169] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amckDDs8oMu6f6EYbxTpOwAAAUk"]
[Mon Jul 27 11:25:32.666254 2026] [:error] [pid 24106:tid 140706953787136] [client 172.71.22.169:9235] [client 172.71.22.169] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amckDDs8oMu6f6EYbxTpOwAAAUk"]
[Mon Jul 27 11:25:32.666886 2026] [:error] [pid 24106:tid 140706953787136] [client 172.71.22.169:9235] [client 172.71.22.169] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:from outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:from=oai-searchbot(at)openai.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amckDDs8oMu6f6EYbxTpOwAAAUk"]
[Mon Jul 27 11:25:32.666945 2026] [:error] [pid 24106:tid 140706953787136] [client 172.71.22.169:9235] [client 172.71.22.169] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amckDDs8oMu6f6EYbxTpOwAAAUk"]
[Mon Jul 27 11:30:12.134463 2026] [:error] [pid 24106:tid 140706937001728] [client 162.159.108.9:12687] [client 162.159.108.9] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amclJDs8oMu6f6EYbxTrRAAAAUs"], referer: https://www.sbf-consultancy.com/
[Mon Jul 27 11:30:12.135649 2026] [:error] [pid 24106:tid 140706937001728] [client 162.159.108.9:12687] [client 162.159.108.9] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amclJDs8oMu6f6EYbxTrRAAAAUs"], referer: https://www.sbf-consultancy.com/
[Mon Jul 27 11:30:12.136304 2026] [:error] [pid 24106:tid 140706937001728] [client 162.159.108.9:12687] [client 162.159.108.9] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amclJDs8oMu6f6EYbxTrRAAAAUs"], referer: https://www.sbf-consultancy.com/
[Mon Jul 27 11:30:50.314584 2026] [:error] [pid 10035:tid 140707103270656] [client 104.22.10.14:14288] [client 104.22.10.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amclSrM5Xj3nsMbGSqsiBQAAAcA"]
[Mon Jul 27 11:30:50.315398 2026] [:error] [pid 10035:tid 140707103270656] [client 104.22.10.14:14288] [client 104.22.10.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amclSrM5Xj3nsMbGSqsiBQAAAcA"]
[Mon Jul 27 11:30:50.315984 2026] [:error] [pid 10035:tid 140707103270656] [client 104.22.10.14:14288] [client 104.22.10.14] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amclSrM5Xj3nsMbGSqsiBQAAAcA"]
[Mon Jul 27 11:30:50.316049 2026] [:error] [pid 10035:tid 140707103270656] [client 104.22.10.14:14288] [client 104.22.10.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amclSrM5Xj3nsMbGSqsiBQAAAcA"]
[Mon Jul 27 11:43:40.942670 2026] [:error] [pid 12275:tid 140706945394432] [client 172.71.170.34:11123] [client 172.71.170.34] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcoTHFwI8r7BFXGkAu7CQAAAAo"]
[Mon Jul 27 11:43:40.960650 2026] [:error] [pid 12275:tid 140706945394432] [client 172.71.170.34:11123] [client 172.71.170.34] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcoTHFwI8r7BFXGkAu7CQAAAAo"]
[Mon Jul 27 11:43:40.961187 2026] [:error] [pid 12275:tid 140706945394432] [client 172.71.170.34:11123] [client 172.71.170.34] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcoTHFwI8r7BFXGkAu7CQAAAAo"]
[Mon Jul 27 11:43:41.591304 2026] [:error] [pid 12277:tid 140706878252800] [client 104.23.243.18:10655] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcoTRwjcb8HQE21kA6sMAAAAJI"]
[Mon Jul 27 11:43:41.591913 2026] [:error] [pid 12277:tid 140706878252800] [client 104.23.243.18:10655] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcoTRwjcb8HQE21kA6sMAAAAJI"]
[Mon Jul 27 11:43:41.592340 2026] [:error] [pid 12277:tid 140706878252800] [client 104.23.243.18:10655] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcoTRwjcb8HQE21kA6sMAAAAJI"]
[Mon Jul 27 11:53:24.621887 2026] [:error] [pid 12380:tid 140706869860096] [client 162.159.113.3:13768] [client 162.159.113.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcqlKaChfbWW0CZ_hppLgAAANM"]
[Mon Jul 27 11:53:24.622865 2026] [:error] [pid 12380:tid 140706869860096] [client 162.159.113.3:13768] [client 162.159.113.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcqlKaChfbWW0CZ_hppLgAAANM"]
[Mon Jul 27 11:53:24.623301 2026] [:error] [pid 12380:tid 140706869860096] [client 162.159.113.3:13768] [client 162.159.113.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amcqlKaChfbWW0CZ_hppLgAAANM"]
[Mon Jul 27 11:59:24.241804 2026] [:error] [pid 12380:tid 140706836289280] [client 141.101.105.103:10944] [client 141.101.105.103] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcr_KaChfbWW0CZ_hpvXQAAANc"]
[Mon Jul 27 11:59:24.242746 2026] [:error] [pid 12380:tid 140706836289280] [client 141.101.105.103:10944] [client 141.101.105.103] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcr_KaChfbWW0CZ_hpvXQAAANc"]
[Mon Jul 27 11:59:24.243255 2026] [:error] [pid 12380:tid 140706836289280] [client 141.101.105.103:10944] [client 141.101.105.103] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcr_KaChfbWW0CZ_hpvXQAAANc"]
[Mon Jul 27 12:06:28.990460 2026] [:error] [pid 17228:tid 140707012536064] [client 162.159.106.33:10179] [client 162.159.106.33] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amctpJjBQLO4t9VCDfpS1wAAAQI"]
[Mon Jul 27 12:06:28.991362 2026] [:error] [pid 17228:tid 140707012536064] [client 162.159.106.33:10179] [client 162.159.106.33] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amctpJjBQLO4t9VCDfpS1wAAAQI"]
[Mon Jul 27 12:06:28.991941 2026] [:error] [pid 17228:tid 140707012536064] [client 162.159.106.33:10179] [client 162.159.106.33] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amctpJjBQLO4t9VCDfpS1wAAAQI"]
[Mon Jul 27 12:06:29.887759 2026] [:error] [pid 17228:tid 140706945394432] [client 162.159.106.60:9359] [client 162.159.106.60] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amctpZjBQLO4t9VCDfpS3QAAAQo"]
[Mon Jul 27 12:06:29.888689 2026] [:error] [pid 17228:tid 140706945394432] [client 162.159.106.60:9359] [client 162.159.106.60] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amctpZjBQLO4t9VCDfpS3QAAAQo"]
[Mon Jul 27 12:06:29.889387 2026] [:error] [pid 17228:tid 140706945394432] [client 162.159.106.60:9359] [client 162.159.106.60] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amctpZjBQLO4t9VCDfpS3QAAAQo"]
[Mon Jul 27 12:13:37.760701 2026] [:error] [pid 17228:tid 140706928609024] [client 172.70.248.40:13904] [client 172.70.248.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amcvUZjBQLO4t9VCDfpglQAAAQw"]
[Mon Jul 27 12:13:37.761842 2026] [:error] [pid 17228:tid 140706928609024] [client 172.70.248.40:13904] [client 172.70.248.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amcvUZjBQLO4t9VCDfpglQAAAQw"]
[Mon Jul 27 12:13:37.762476 2026] [:error] [pid 17228:tid 140706928609024] [client 172.70.248.40:13904] [client 172.70.248.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amcvUZjBQLO4t9VCDfpglQAAAQw"]
[Mon Jul 27 12:15:57.288399 2026] [:error] [pid 23952:tid 140706995750656] [client 141.101.105.104:12302] [client 141.101.105.104] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcv3S8h5OE555JiBB9M4wAAAkQ"]
[Mon Jul 27 12:15:57.289298 2026] [:error] [pid 23952:tid 140706995750656] [client 141.101.105.104:12302] [client 141.101.105.104] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcv3S8h5OE555JiBB9M4wAAAkQ"]
[Mon Jul 27 12:15:57.289720 2026] [:error] [pid 23952:tid 140706995750656] [client 141.101.105.104:12302] [client 141.101.105.104] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcv3S8h5OE555JiBB9M4wAAAkQ"]
[Mon Jul 27 12:23:02.570200 2026] [:error] [pid 17228:tid 140707020928768] [client 141.101.105.104:12431] [client 141.101.105.104] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcxhpjBQLO4t9VCDfpubAAAAQE"]
[Mon Jul 27 12:23:02.570843 2026] [:error] [pid 17228:tid 140707020928768] [client 141.101.105.104:12431] [client 141.101.105.104] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcxhpjBQLO4t9VCDfpubAAAAQE"]
[Mon Jul 27 12:23:02.571236 2026] [:error] [pid 17228:tid 140707020928768] [client 141.101.105.104:12431] [client 141.101.105.104] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcxhpjBQLO4t9VCDfpubAAAAQE"]
[Mon Jul 27 12:23:29.602608 2026] [:error] [pid 12276:tid 140706920216320] [client 104.23.245.28:13183] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_rNd9xZ7kL3"] [unique_id "amcxoecsEMuHmMYmk67K_AAAAE0"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:29.603842 2026] [:error] [pid 12276:tid 140706920216320] [client 104.23.245.28:13183] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_rNd9xZ7kL3"] [unique_id "amcxoecsEMuHmMYmk67K_AAAAE0"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:29.604489 2026] [:error] [pid 12276:tid 140706920216320] [client 104.23.245.28:13183] [client 104.23.245.28] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_rNd9xZ7kL3"] [unique_id "amcxoecsEMuHmMYmk67K_AAAAE0"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:32.665748 2026] [:error] [pid 23693:tid 140706853074688] [client 108.162.237.146:12186] [client 108.162.237.146] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcxpDECtsZH8ymO6R0WTwAAAhU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:32.666626 2026] [:error] [pid 23693:tid 140706853074688] [client 108.162.237.146:12186] [client 108.162.237.146] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcxpDECtsZH8ymO6R0WTwAAAhU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:32.667208 2026] [:error] [pid 23693:tid 140706853074688] [client 108.162.237.146:12186] [client 108.162.237.146] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amcxpDECtsZH8ymO6R0WTwAAAhU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:35.880545 2026] [:error] [pid 12276:tid 140706953787136] [client 104.22.24.170:9375] [client 104.22.24.170] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcxp-csEMuHmMYmk67LLQAAAEk"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:35.881193 2026] [:error] [pid 12276:tid 140706953787136] [client 104.22.24.170:9375] [client 104.22.24.170] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcxp-csEMuHmMYmk67LLQAAAEk"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:35.881612 2026] [:error] [pid 12276:tid 140706953787136] [client 104.22.24.170:9375] [client 104.22.24.170] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amcxp-csEMuHmMYmk67LLQAAAEk"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:39.419496 2026] [:error] [pid 12276:tid 140707103270656] [client 104.23.245.28:11332] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amcxq-csEMuHmMYmk67LTQAAAEA"]
[Mon Jul 27 12:23:39.420592 2026] [:error] [pid 12276:tid 140707103270656] [client 104.23.245.28:11332] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amcxq-csEMuHmMYmk67LTQAAAEA"]
[Mon Jul 27 12:23:39.421382 2026] [:error] [pid 12276:tid 140707103270656] [client 104.23.245.28:11332] [client 104.23.245.28] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amcxq-csEMuHmMYmk67LTQAAAEA"]
[Mon Jul 27 12:23:39.421434 2026] [:error] [pid 12276:tid 140707103270656] [client 104.23.245.28:11332] [client 104.23.245.28] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amcxq-csEMuHmMYmk67LTQAAAEA"]
[Mon Jul 27 12:23:43.971082 2026] [:error] [pid 23952:tid 140706962179840] [client 172.71.22.116:9957] [client 172.71.22.116] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sitemap_index.xml"] [unique_id "amcxry8h5OE555JiBB9RGwAAAkg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:43.972042 2026] [:error] [pid 23952:tid 140706962179840] [client 172.71.22.116:9957] [client 172.71.22.116] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sitemap_index.xml"] [unique_id "amcxry8h5OE555JiBB9RGwAAAkg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:43.972664 2026] [:error] [pid 23952:tid 140706962179840] [client 172.71.22.116:9957] [client 172.71.22.116] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sitemap_index.xml"] [unique_id "amcxry8h5OE555JiBB9RGwAAAkg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:47.258194 2026] [:error] [pid 12276:tid 140707020928768] [client 108.162.237.146:12945] [client 108.162.237.146] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sitemap-index.xml"] [unique_id "amcxs-csEMuHmMYmk67LcAAAAEE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:47.259164 2026] [:error] [pid 12276:tid 140707020928768] [client 108.162.237.146:12945] [client 108.162.237.146] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sitemap-index.xml"] [unique_id "amcxs-csEMuHmMYmk67LcAAAAEE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:47.259770 2026] [:error] [pid 12276:tid 140707020928768] [client 108.162.237.146:12945] [client 108.162.237.146] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sitemap-index.xml"] [unique_id "amcxs-csEMuHmMYmk67LcAAAAEE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.033340 2026] [:error] [pid 12276:tid 140706878252800] [client 172.68.70.68:9883] [client 172.68.70.68] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcxtucsEMuHmMYmk67LgAAAAFI"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.034354 2026] [:error] [pid 12276:tid 140706878252800] [client 172.68.70.68:9883] [client 172.68.70.68] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcxtucsEMuHmMYmk67LgAAAAFI"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.034960 2026] [:error] [pid 12276:tid 140706878252800] [client 172.68.70.68:9883] [client 172.68.70.68] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcxtucsEMuHmMYmk67LgAAAAFI"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.035243 2026] [:error] [pid 12276:tid 140706962179840] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcxtucsEMuHmMYmk67LgQAAAEg"]
[Mon Jul 27 12:23:50.035299 2026] [:error] [pid 12276:tid 140706878252800] [client 172.68.70.68:9883] [client 172.68.70.68] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcxtucsEMuHmMYmk67LgAAAAFI"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.035794 2026] [:error] [pid 12276:tid 140706962179840] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcxtucsEMuHmMYmk67LgQAAAEg"]
[Mon Jul 27 12:23:50.036417 2026] [:error] [pid 12276:tid 140706962179840] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcxtucsEMuHmMYmk67LgQAAAEg"]
[Mon Jul 27 12:23:50.036478 2026] [:error] [pid 12276:tid 140706962179840] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcxtucsEMuHmMYmk67LgQAAAEg"]
[Mon Jul 27 12:23:50.036783 2026] [:error] [pid 12276:tid 140706962179840] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcxtucsEMuHmMYmk67LgQAAAEg"]
[Mon Jul 27 12:23:50.038006 2026] [:error] [pid 17228:tid 140706987357952] [client 104.22.57.46:13014] [client 104.22.57.46] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcxtpjBQLO4t9VCDfpvhQAAAQU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.038107 2026] [:error] [pid 12276:tid 140706953787136] [client 104.22.57.45:14127] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.dev.vars"] [unique_id "amcxtucsEMuHmMYmk67LggAAAEk"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.038638 2026] [:error] [pid 17228:tid 140706987357952] [client 104.22.57.46:13014] [client 104.22.57.46] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcxtpjBQLO4t9VCDfpvhQAAAQU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.038640 2026] [:error] [pid 12276:tid 140706953787136] [client 104.22.57.45:14127] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.dev.vars"] [unique_id "amcxtucsEMuHmMYmk67LggAAAEk"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.039215 2026] [:error] [pid 12276:tid 140706953787136] [client 104.22.57.45:14127] [client 104.22.57.45] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.dev.vars"] [unique_id "amcxtucsEMuHmMYmk67LggAAAEk"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.039217 2026] [:error] [pid 17228:tid 140706987357952] [client 104.22.57.46:13014] [client 104.22.57.46] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcxtpjBQLO4t9VCDfpvhQAAAQU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.039281 2026] [:error] [pid 12276:tid 140706953787136] [client 104.22.57.45:14127] [client 104.22.57.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.dev.vars"] [unique_id "amcxtucsEMuHmMYmk67LggAAAEk"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.039310 2026] [:error] [pid 17228:tid 140706987357952] [client 104.22.57.46:13014] [client 104.22.57.46] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcxtpjBQLO4t9VCDfpvhQAAAQU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.041210 2026] [:error] [pid 12276:tid 140706861467392] [client 172.69.71.179:10239] [client 172.69.71.179] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcxtucsEMuHmMYmk67LhAAAAFQ"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.041217 2026] [:error] [pid 12276:tid 140706978965248] [client 172.68.70.69:10920] [client 172.68.70.69] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amcxtucsEMuHmMYmk67LgwAAAEY"]
[Mon Jul 27 12:23:50.041647 2026] [:error] [pid 12276:tid 140706978965248] [client 172.68.70.69:10920] [client 172.68.70.69] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amcxtucsEMuHmMYmk67LgwAAAEY"]
[Mon Jul 27 12:23:50.041745 2026] [:error] [pid 12276:tid 140706861467392] [client 172.69.71.179:10239] [client 172.69.71.179] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcxtucsEMuHmMYmk67LhAAAAFQ"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.042213 2026] [:error] [pid 12276:tid 140706978965248] [client 172.68.70.69:10920] [client 172.68.70.69] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amcxtucsEMuHmMYmk67LgwAAAEY"]
[Mon Jul 27 12:23:50.042229 2026] [:error] [pid 12276:tid 140706861467392] [client 172.69.71.179:10239] [client 172.69.71.179] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcxtucsEMuHmMYmk67LhAAAAFQ"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.042272 2026] [:error] [pid 12276:tid 140706978965248] [client 172.68.70.69:10920] [client 172.68.70.69] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amcxtucsEMuHmMYmk67LgwAAAEY"]
[Mon Jul 27 12:23:50.042486 2026] [:error] [pid 12276:tid 140706861467392] [client 172.69.71.179:10239] [client 172.69.71.179] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcxtucsEMuHmMYmk67LhAAAAFQ"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.042619 2026] [:error] [pid 12276:tid 140706978965248] [client 172.68.70.69:10920] [client 172.68.70.69] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amcxtucsEMuHmMYmk67LgwAAAEY"]
[Mon Jul 27 12:23:50.044028 2026] [:error] [pid 12276:tid 140707020928768] [client 172.69.71.179:10245] [client 172.69.71.179] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amcxtucsEMuHmMYmk67LhQAAAEE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.044323 2026] [:error] [pid 12277:tid 140706869860096] [client 172.69.71.180:10756] [client 172.69.71.180] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcxthwjcb8HQE21kA6t1AAAAJM"]
[Mon Jul 27 12:23:50.044570 2026] [:error] [pid 12276:tid 140707020928768] [client 172.69.71.179:10245] [client 172.69.71.179] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amcxtucsEMuHmMYmk67LhQAAAEE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.044938 2026] [:error] [pid 23693:tid 140706861467392] [client 104.22.24.57:12092] [client 104.22.24.57] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcxtjECtsZH8ymO6R0WUQAAAhQ"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.044997 2026] [:error] [pid 12277:tid 140706869860096] [client 172.69.71.180:10756] [client 172.69.71.180] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcxthwjcb8HQE21kA6t1AAAAJM"]
[Mon Jul 27 12:23:50.045189 2026] [:error] [pid 12276:tid 140707020928768] [client 172.69.71.179:10245] [client 172.69.71.179] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amcxtucsEMuHmMYmk67LhQAAAEE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.045248 2026] [:error] [pid 12276:tid 140707020928768] [client 172.69.71.179:10245] [client 172.69.71.179] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amcxtucsEMuHmMYmk67LhQAAAEE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.045437 2026] [:error] [pid 23693:tid 140706861467392] [client 104.22.24.57:12092] [client 104.22.24.57] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcxtjECtsZH8ymO6R0WUQAAAhQ"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.045481 2026] [:error] [pid 12276:tid 140707020928768] [client 172.69.71.179:10245] [client 172.69.71.179] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amcxtucsEMuHmMYmk67LhQAAAEE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.045633 2026] [:error] [pid 12277:tid 140706869860096] [client 172.69.71.180:10756] [client 172.69.71.180] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcxthwjcb8HQE21kA6t1AAAAJM"]
[Mon Jul 27 12:23:50.045683 2026] [:error] [pid 12277:tid 140706869860096] [client 172.69.71.180:10756] [client 172.69.71.180] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcxthwjcb8HQE21kA6t1AAAAJM"]
[Mon Jul 27 12:23:50.045889 2026] [:error] [pid 23693:tid 140706861467392] [client 104.22.24.57:12092] [client 104.22.24.57] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcxtjECtsZH8ymO6R0WUQAAAhQ"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:50.045948 2026] [:error] [pid 12277:tid 140706869860096] [client 172.69.71.180:10756] [client 172.69.71.180] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcxthwjcb8HQE21kA6t1AAAAJM"]
[Mon Jul 27 12:23:50.113500 2026] [:error] [pid 23952:tid 140706895038208] [client 172.68.70.69:10922] [client 172.68.70.69] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcxti8h5OE555JiBB9RHwAAAlA"]
[Mon Jul 27 12:23:50.114382 2026] [:error] [pid 23952:tid 140706895038208] [client 172.68.70.69:10922] [client 172.68.70.69] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcxti8h5OE555JiBB9RHwAAAlA"]
[Mon Jul 27 12:23:50.114908 2026] [:error] [pid 23952:tid 140706895038208] [client 172.68.70.69:10922] [client 172.68.70.69] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcxti8h5OE555JiBB9RHwAAAlA"]
[Mon Jul 27 12:23:50.115178 2026] [:error] [pid 23952:tid 140706895038208] [client 172.68.70.69:10922] [client 172.68.70.69] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcxti8h5OE555JiBB9RHwAAAlA"]
[Mon Jul 27 12:23:53.062054 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.22.117:13899] [client 172.71.22.117] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcxuecsEMuHmMYmk67LkgAAAEg"]
[Mon Jul 27 12:23:53.062960 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.22.117:13899] [client 172.71.22.117] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcxuecsEMuHmMYmk67LkgAAAEg"]
[Mon Jul 27 12:23:53.063571 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.22.117:13899] [client 172.71.22.117] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcxuecsEMuHmMYmk67LkgAAAEg"]
[Mon Jul 27 12:23:53.063644 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.22.117:13899] [client 172.71.22.117] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcxuecsEMuHmMYmk67LkgAAAEg"]
[Mon Jul 27 12:23:53.063982 2026] [:error] [pid 12276:tid 140706962179840] [client 172.71.22.117:13899] [client 172.71.22.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcxuecsEMuHmMYmk67LkgAAAEg"]
[Mon Jul 27 12:23:53.093632 2026] [:error] [pid 12276:tid 140706953787136] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcxuecsEMuHmMYmk67LkwAAAEk"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.094499 2026] [:error] [pid 12276:tid 140706953787136] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcxuecsEMuHmMYmk67LkwAAAEk"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.095170 2026] [:error] [pid 12276:tid 140706953787136] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcxuecsEMuHmMYmk67LkwAAAEk"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.095245 2026] [:error] [pid 12276:tid 140706953787136] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcxuecsEMuHmMYmk67LkwAAAEk"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.095590 2026] [:error] [pid 12276:tid 140706953787136] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcxuecsEMuHmMYmk67LkwAAAEk"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.453225 2026] [:error] [pid 12276:tid 140707020928768] [client 172.71.22.117:13899] [client 172.71.22.117] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcxuecsEMuHmMYmk67LlQAAAEE"]
[Mon Jul 27 12:23:53.454188 2026] [:error] [pid 12276:tid 140707020928768] [client 172.71.22.117:13899] [client 172.71.22.117] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcxuecsEMuHmMYmk67LlQAAAEE"]
[Mon Jul 27 12:23:53.454788 2026] [:error] [pid 12276:tid 140707020928768] [client 172.71.22.117:13899] [client 172.71.22.117] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcxuecsEMuHmMYmk67LlQAAAEE"]
[Mon Jul 27 12:23:53.455120 2026] [:error] [pid 12276:tid 140707020928768] [client 172.71.22.117:13899] [client 172.71.22.117] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amcxuecsEMuHmMYmk67LlQAAAEE"]
[Mon Jul 27 12:23:53.492183 2026] [:error] [pid 12276:tid 140706928609024] [client 172.68.70.68:9883] [client 172.68.70.68] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcxuecsEMuHmMYmk67LlgAAAEw"]
[Mon Jul 27 12:23:53.492516 2026] [:error] [pid 12276:tid 140707103270656] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcxuecsEMuHmMYmk67LlwAAAEA"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.492938 2026] [:error] [pid 12276:tid 140706928609024] [client 172.68.70.68:9883] [client 172.68.70.68] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcxuecsEMuHmMYmk67LlgAAAEw"]
[Mon Jul 27 12:23:53.493051 2026] [:error] [pid 12276:tid 140707103270656] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcxuecsEMuHmMYmk67LlwAAAEA"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.493368 2026] [:error] [pid 12276:tid 140706928609024] [client 172.68.70.68:9883] [client 172.68.70.68] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcxuecsEMuHmMYmk67LlgAAAEw"]
[Mon Jul 27 12:23:53.493583 2026] [:error] [pid 12276:tid 140706928609024] [client 172.68.70.68:9883] [client 172.68.70.68] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amcxuecsEMuHmMYmk67LlgAAAEw"]
[Mon Jul 27 12:23:53.493583 2026] [:error] [pid 12276:tid 140707103270656] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcxuecsEMuHmMYmk67LlwAAAEA"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.493933 2026] [:error] [pid 12276:tid 140707103270656] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amcxuecsEMuHmMYmk67LlwAAAEA"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.500584 2026] [:error] [pid 12276:tid 140706869860096] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcxuecsEMuHmMYmk67LmAAAAFM"]
[Mon Jul 27 12:23:53.501476 2026] [:error] [pid 12276:tid 140706869860096] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcxuecsEMuHmMYmk67LmAAAAFM"]
[Mon Jul 27 12:23:53.501980 2026] [:error] [pid 12276:tid 140706869860096] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcxuecsEMuHmMYmk67LmAAAAFM"]
[Mon Jul 27 12:23:53.502032 2026] [:error] [pid 12276:tid 140706869860096] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcxuecsEMuHmMYmk67LmAAAAFM"]
[Mon Jul 27 12:23:53.502322 2026] [:error] [pid 12276:tid 140706869860096] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcxuecsEMuHmMYmk67LmAAAAFM"]
[Mon Jul 27 12:23:53.529744 2026] [:error] [pid 12276:tid 140706836289280] [client 172.69.71.179:10239] [client 172.69.71.179] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcxuecsEMuHmMYmk67LmQAAAFc"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.530614 2026] [:error] [pid 12276:tid 140706836289280] [client 172.69.71.179:10239] [client 172.69.71.179] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcxuecsEMuHmMYmk67LmQAAAFc"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.531344 2026] [:error] [pid 12276:tid 140706836289280] [client 172.69.71.179:10239] [client 172.69.71.179] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcxuecsEMuHmMYmk67LmQAAAFc"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.531400 2026] [:error] [pid 12276:tid 140706836289280] [client 172.69.71.179:10239] [client 172.69.71.179] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amcxuecsEMuHmMYmk67LmQAAAFc"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.533976 2026] [:error] [pid 12276:tid 140706836289280] [client 172.69.71.179:10245] [client 172.69.71.179] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcxuecsEMuHmMYmk67LmgAAAFc"]
[Mon Jul 27 12:23:53.534469 2026] [:error] [pid 12276:tid 140706836289280] [client 172.69.71.179:10245] [client 172.69.71.179] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcxuecsEMuHmMYmk67LmgAAAFc"]
[Mon Jul 27 12:23:53.534958 2026] [:error] [pid 12276:tid 140706836289280] [client 172.69.71.179:10245] [client 172.69.71.179] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcxuecsEMuHmMYmk67LmgAAAFc"]
[Mon Jul 27 12:23:53.535003 2026] [:error] [pid 12276:tid 140706836289280] [client 172.69.71.179:10245] [client 172.69.71.179] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amcxuecsEMuHmMYmk67LmgAAAFc"]
[Mon Jul 27 12:23:53.582532 2026] [:error] [pid 12276:tid 140706911823616] [client 172.68.70.69:10920] [client 172.68.70.69] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcxuecsEMuHmMYmk67LnAAAAE4"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.583683 2026] [:error] [pid 12276:tid 140706911823616] [client 172.68.70.69:10920] [client 172.68.70.69] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcxuecsEMuHmMYmk67LnAAAAE4"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.584292 2026] [:error] [pid 12276:tid 140706911823616] [client 172.68.70.69:10920] [client 172.68.70.69] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcxuecsEMuHmMYmk67LnAAAAE4"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.584579 2026] [:error] [pid 12276:tid 140706911823616] [client 172.68.70.69:10920] [client 172.68.70.69] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcxuecsEMuHmMYmk67LnAAAAE4"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.861761 2026] [:error] [pid 17228:tid 140706928609024] [client 172.69.70.61:9508] [client 172.69.70.61] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcxuZjBQLO4t9VCDfpvpgAAAQw"]
[Mon Jul 27 12:23:53.862692 2026] [:error] [pid 17228:tid 140706928609024] [client 172.69.70.61:9508] [client 172.69.70.61] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcxuZjBQLO4t9VCDfpvpgAAAQw"]
[Mon Jul 27 12:23:53.863109 2026] [:error] [pid 17228:tid 140706928609024] [client 172.69.70.61:9508] [client 172.69.70.61] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcxuZjBQLO4t9VCDfpvpgAAAQw"]
[Mon Jul 27 12:23:53.863332 2026] [:error] [pid 17228:tid 140706928609024] [client 172.69.70.61:9508] [client 172.69.70.61] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcxuZjBQLO4t9VCDfpvpgAAAQw"]
[Mon Jul 27 12:23:53.895921 2026] [:error] [pid 17228:tid 140706886645504] [client 104.23.245.28:9442] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcxuZjBQLO4t9VCDfpvqAAAARE"]
[Mon Jul 27 12:23:53.897039 2026] [:error] [pid 17228:tid 140706886645504] [client 104.23.245.28:9442] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcxuZjBQLO4t9VCDfpvqAAAARE"]
[Mon Jul 27 12:23:53.897700 2026] [:error] [pid 17228:tid 140706886645504] [client 104.23.245.28:9442] [client 104.23.245.28] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcxuZjBQLO4t9VCDfpvqAAAARE"]
[Mon Jul 27 12:23:53.898010 2026] [:error] [pid 17228:tid 140706886645504] [client 104.23.245.28:9442] [client 104.23.245.28] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amcxuZjBQLO4t9VCDfpvqAAAARE"]
[Mon Jul 27 12:23:53.918586 2026] [:error] [pid 17228:tid 140706962179840] [client 104.23.245.29:14023] [client 104.23.245.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcxuZjBQLO4t9VCDfpvqgAAAQg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.919752 2026] [:error] [pid 17228:tid 140706962179840] [client 104.23.245.29:14023] [client 104.23.245.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcxuZjBQLO4t9VCDfpvqgAAAQg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.920885 2026] [:error] [pid 17228:tid 140706962179840] [client 104.23.245.29:14023] [client 104.23.245.29] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcxuZjBQLO4t9VCDfpvqgAAAQg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.920949 2026] [:error] [pid 17228:tid 140706962179840] [client 104.23.245.29:14023] [client 104.23.245.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcxuZjBQLO4t9VCDfpvqgAAAQg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:53.921347 2026] [:error] [pid 17228:tid 140706962179840] [client 104.23.245.29:14023] [client 104.23.245.29] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amcxuZjBQLO4t9VCDfpvqgAAAQg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.363637 2026] [:error] [pid 12276:tid 140706911823616] [client 172.69.71.179:10239] [client 172.69.71.179] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcxvOcsEMuHmMYmk67LqwAAAE4"]
[Mon Jul 27 12:23:56.364690 2026] [:error] [pid 12276:tid 140706911823616] [client 172.69.71.179:10239] [client 172.69.71.179] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcxvOcsEMuHmMYmk67LqwAAAE4"]
[Mon Jul 27 12:23:56.365269 2026] [:error] [pid 12276:tid 140706911823616] [client 172.69.71.179:10239] [client 172.69.71.179] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcxvOcsEMuHmMYmk67LqwAAAE4"]
[Mon Jul 27 12:23:56.365525 2026] [:error] [pid 12276:tid 140706911823616] [client 172.69.71.179:10239] [client 172.69.71.179] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amcxvOcsEMuHmMYmk67LqwAAAE4"]
[Mon Jul 27 12:23:56.638457 2026] [:error] [pid 12276:tid 140706903430912] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amcxvOcsEMuHmMYmk67LrwAAAE8"]
[Mon Jul 27 12:23:56.639212 2026] [:error] [pid 12276:tid 140706903430912] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amcxvOcsEMuHmMYmk67LrwAAAE8"]
[Mon Jul 27 12:23:56.639730 2026] [:error] [pid 12276:tid 140706903430912] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amcxvOcsEMuHmMYmk67LrwAAAE8"]
[Mon Jul 27 12:23:56.640000 2026] [:error] [pid 12276:tid 140706903430912] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amcxvOcsEMuHmMYmk67LrwAAAE8"]
[Mon Jul 27 12:23:56.644799 2026] [:error] [pid 12276:tid 140706886645504] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcxvOcsEMuHmMYmk67LsAAAAFE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.645654 2026] [:error] [pid 12276:tid 140706886645504] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcxvOcsEMuHmMYmk67LsAAAAFE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.646327 2026] [:error] [pid 12276:tid 140706886645504] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcxvOcsEMuHmMYmk67LsAAAAFE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.646383 2026] [:error] [pid 12276:tid 140706886645504] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcxvOcsEMuHmMYmk67LsAAAAFE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.646743 2026] [:error] [pid 12276:tid 140706886645504] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amcxvOcsEMuHmMYmk67LsAAAAFE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.753116 2026] [:error] [pid 17228:tid 140706937001728] [client 104.22.57.45:14129] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcxvJjBQLO4t9VCDfpvugAAAQs"]
[Mon Jul 27 12:23:56.754190 2026] [:error] [pid 17228:tid 140706937001728] [client 104.22.57.45:14129] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcxvJjBQLO4t9VCDfpvugAAAQs"]
[Mon Jul 27 12:23:56.754809 2026] [:error] [pid 17228:tid 140706937001728] [client 104.22.57.45:14129] [client 104.22.57.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcxvJjBQLO4t9VCDfpvugAAAQs"]
[Mon Jul 27 12:23:56.755096 2026] [:error] [pid 17228:tid 140706937001728] [client 104.22.57.45:14129] [client 104.22.57.45] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amcxvJjBQLO4t9VCDfpvugAAAQs"]
[Mon Jul 27 12:23:56.870478 2026] [:error] [pid 12276:tid 140706853074688] [client 172.68.70.68:9883] [client 172.68.70.68] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcxvOcsEMuHmMYmk67LswAAAFU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.870855 2026] [:error] [pid 12276:tid 140706827896576] [client 104.22.57.45:14131] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcxvOcsEMuHmMYmk67LtAAAAFg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.871681 2026] [:error] [pid 12276:tid 140706827896576] [client 104.22.57.45:14131] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcxvOcsEMuHmMYmk67LtAAAAFg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.871740 2026] [:error] [pid 12276:tid 140706853074688] [client 172.68.70.68:9883] [client 172.68.70.68] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcxvOcsEMuHmMYmk67LswAAAFU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.872245 2026] [:error] [pid 12276:tid 140706827896576] [client 104.22.57.45:14131] [client 104.22.57.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcxvOcsEMuHmMYmk67LtAAAAFg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.872367 2026] [:error] [pid 12276:tid 140706853074688] [client 172.68.70.68:9883] [client 172.68.70.68] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcxvOcsEMuHmMYmk67LswAAAFU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.872412 2026] [:error] [pid 12276:tid 140706827896576] [client 104.22.57.45:14131] [client 104.22.57.45] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcxvOcsEMuHmMYmk67LtAAAAFg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.872677 2026] [:error] [pid 12276:tid 140706853074688] [client 172.68.70.68:9883] [client 172.68.70.68] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcxvOcsEMuHmMYmk67LswAAAFU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.879459 2026] [:error] [pid 17228:tid 140706827896576] [client 104.22.57.46:13022] [client 104.22.57.46] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amcxvJjBQLO4t9VCDfpvuwAAARg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.880339 2026] [:error] [pid 17228:tid 140706827896576] [client 104.22.57.46:13022] [client 104.22.57.46] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amcxvJjBQLO4t9VCDfpvuwAAARg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.880902 2026] [:error] [pid 17228:tid 140706827896576] [client 104.22.57.46:13022] [client 104.22.57.46] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amcxvJjBQLO4t9VCDfpvuwAAARg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.910438 2026] [:error] [pid 12276:tid 140707004143360] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcxvOcsEMuHmMYmk67LtQAAAEM"]
[Mon Jul 27 12:23:56.911567 2026] [:error] [pid 12276:tid 140707004143360] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcxvOcsEMuHmMYmk67LtQAAAEM"]
[Mon Jul 27 12:23:56.912351 2026] [:error] [pid 12276:tid 140707004143360] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcxvOcsEMuHmMYmk67LtQAAAEM"]
[Mon Jul 27 12:23:56.912402 2026] [:error] [pid 12276:tid 140707004143360] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcxvOcsEMuHmMYmk67LtQAAAEM"]
[Mon Jul 27 12:23:56.912771 2026] [:error] [pid 12276:tid 140707004143360] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amcxvOcsEMuHmMYmk67LtQAAAEM"]
[Mon Jul 27 12:23:56.998609 2026] [:error] [pid 17228:tid 140706844681984] [client 104.22.57.46:13025] [client 104.22.57.46] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcxvJjBQLO4t9VCDfpvvQAAARY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:56.999595 2026] [:error] [pid 17228:tid 140706844681984] [client 104.22.57.46:13025] [client 104.22.57.46] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcxvJjBQLO4t9VCDfpvvQAAARY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:57.000514 2026] [:error] [pid 17228:tid 140706844681984] [client 104.22.57.46:13025] [client 104.22.57.46] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcxvJjBQLO4t9VCDfpvvQAAARY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:57.000643 2026] [:error] [pid 17228:tid 140706844681984] [client 104.22.57.46:13025] [client 104.22.57.46] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcxvJjBQLO4t9VCDfpvvQAAARY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:57.001022 2026] [:error] [pid 17228:tid 140706844681984] [client 104.22.57.46:13025] [client 104.22.57.46] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcxvJjBQLO4t9VCDfpvvQAAARY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:57.044382 2026] [:error] [pid 12276:tid 140706844681984] [client 104.22.24.57:9595] [client 104.22.24.57] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcxvecsEMuHmMYmk67LuAAAAFY"]
[Mon Jul 27 12:23:57.045393 2026] [:error] [pid 12276:tid 140706844681984] [client 104.22.24.57:9595] [client 104.22.24.57] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcxvecsEMuHmMYmk67LuAAAAFY"]
[Mon Jul 27 12:23:57.046170 2026] [:error] [pid 12276:tid 140706844681984] [client 104.22.24.57:9595] [client 104.22.24.57] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcxvecsEMuHmMYmk67LuAAAAFY"]
[Mon Jul 27 12:23:57.046223 2026] [:error] [pid 12276:tid 140706844681984] [client 104.22.24.57:9595] [client 104.22.24.57] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcxvecsEMuHmMYmk67LuAAAAFY"]
[Mon Jul 27 12:23:57.046614 2026] [:error] [pid 12276:tid 140706844681984] [client 104.22.24.57:9595] [client 104.22.24.57] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amcxvecsEMuHmMYmk67LuAAAAFY"]
[Mon Jul 27 12:23:57.051384 2026] [:error] [pid 17228:tid 140706853074688] [client 104.22.57.45:14136] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.pypirc"] [unique_id "amcxvZjBQLO4t9VCDfpvvgAAARU"]
[Mon Jul 27 12:23:57.052271 2026] [:error] [pid 17228:tid 140706853074688] [client 104.22.57.45:14136] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.pypirc"] [unique_id "amcxvZjBQLO4t9VCDfpvvgAAARU"]
[Mon Jul 27 12:23:57.052981 2026] [:error] [pid 17228:tid 140706853074688] [client 104.22.57.45:14136] [client 104.22.57.45] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.pypirc"] [unique_id "amcxvZjBQLO4t9VCDfpvvgAAARU"]
[Mon Jul 27 12:23:57.053038 2026] [:error] [pid 17228:tid 140706853074688] [client 104.22.57.45:14136] [client 104.22.57.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.pypirc"] [unique_id "amcxvZjBQLO4t9VCDfpvvgAAARU"]
[Mon Jul 27 12:23:57.167516 2026] [:error] [pid 23952:tid 140706953787136] [client 108.162.237.146:13976] [client 108.162.237.146] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amcxvS8h5OE555JiBB9RJAAAAkk"]
[Mon Jul 27 12:23:57.168180 2026] [:error] [pid 23952:tid 140706953787136] [client 108.162.237.146:13976] [client 108.162.237.146] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amcxvS8h5OE555JiBB9RJAAAAkk"]
[Mon Jul 27 12:23:57.168534 2026] [:error] [pid 23952:tid 140706953787136] [client 108.162.237.146:13976] [client 108.162.237.146] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amcxvS8h5OE555JiBB9RJAAAAkk"]
[Mon Jul 27 12:23:59.217786 2026] [:error] [pid 12276:tid 140706978965248] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.netrc"] [unique_id "amcxv-csEMuHmMYmk67LxwAAAEY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.218852 2026] [:error] [pid 12276:tid 140706978965248] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.netrc"] [unique_id "amcxv-csEMuHmMYmk67LxwAAAEY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.219448 2026] [:error] [pid 12276:tid 140706978965248] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.netrc"] [unique_id "amcxv-csEMuHmMYmk67LxwAAAEY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.219934 2026] [:error] [pid 12276:tid 140706978965248] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Matched phrase ".netrc" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .netrc found within REQUEST_FILENAME: /.netrc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.netrc"] [unique_id "amcxv-csEMuHmMYmk67LxwAAAEY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.493805 2026] [:error] [pid 12276:tid 140706928609024] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.vscode/settings.json"] [unique_id "amcxv-csEMuHmMYmk67LyAAAAEw"]
[Mon Jul 27 12:23:59.494701 2026] [:error] [pid 12276:tid 140706928609024] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.vscode/settings.json"] [unique_id "amcxv-csEMuHmMYmk67LyAAAAEw"]
[Mon Jul 27 12:23:59.495239 2026] [:error] [pid 12276:tid 140706928609024] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.vscode/settings.json"] [unique_id "amcxv-csEMuHmMYmk67LyAAAAEw"]
[Mon Jul 27 12:23:59.578912 2026] [:error] [pid 12276:tid 140706903430912] [client 104.22.24.57:9595] [client 104.22.24.57] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amcxv-csEMuHmMYmk67LywAAAE8"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.579690 2026] [:error] [pid 12276:tid 140706903430912] [client 104.22.24.57:9595] [client 104.22.24.57] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amcxv-csEMuHmMYmk67LywAAAE8"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.580259 2026] [:error] [pid 12276:tid 140706903430912] [client 104.22.24.57:9595] [client 104.22.24.57] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amcxv-csEMuHmMYmk67LywAAAE8"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.580295 2026] [:error] [pid 12276:tid 140706903430912] [client 104.22.24.57:9595] [client 104.22.24.57] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amcxv-csEMuHmMYmk67LywAAAE8"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.580525 2026] [:error] [pid 12276:tid 140706903430912] [client 104.22.24.57:9595] [client 104.22.24.57] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amcxv-csEMuHmMYmk67LywAAAE8"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.665248 2026] [:error] [pid 17228:tid 140706836289280] [client 104.22.57.45:14129] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.cursor/mcp.json"] [unique_id "amcxv5jBQLO4t9VCDfpvzAAAARc"]
[Mon Jul 27 12:23:59.666147 2026] [:error] [pid 17228:tid 140706836289280] [client 104.22.57.45:14129] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.cursor/mcp.json"] [unique_id "amcxv5jBQLO4t9VCDfpvzAAAARc"]
[Mon Jul 27 12:23:59.666690 2026] [:error] [pid 17228:tid 140706836289280] [client 104.22.57.45:14129] [client 104.22.57.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.cursor/mcp.json"] [unique_id "amcxv5jBQLO4t9VCDfpvzAAAARc"]
[Mon Jul 27 12:23:59.721648 2026] [:error] [pid 12276:tid 140706827896576] [client 104.22.57.45:14131] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcxv-csEMuHmMYmk67LzAAAAFg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.722377 2026] [:error] [pid 12276:tid 140706827896576] [client 104.22.57.45:14131] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcxv-csEMuHmMYmk67LzAAAAFg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.722936 2026] [:error] [pid 12276:tid 140706827896576] [client 104.22.57.45:14131] [client 104.22.57.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcxv-csEMuHmMYmk67LzAAAAFg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.722972 2026] [:error] [pid 12276:tid 140706827896576] [client 104.22.57.45:14131] [client 104.22.57.45] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcxv-csEMuHmMYmk67LzAAAAFg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.723229 2026] [:error] [pid 12276:tid 140706827896576] [client 104.22.57.45:14131] [client 104.22.57.45] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amcxv-csEMuHmMYmk67LzAAAAFg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.733398 2026] [:error] [pid 12276:tid 140706853074688] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amcxv-csEMuHmMYmk67LzQAAAFU"]
[Mon Jul 27 12:23:59.734117 2026] [:error] [pid 12276:tid 140706853074688] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amcxv-csEMuHmMYmk67LzQAAAFU"]
[Mon Jul 27 12:23:59.734615 2026] [:error] [pid 12276:tid 140706853074688] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amcxv-csEMuHmMYmk67LzQAAAFU"]
[Mon Jul 27 12:23:59.734677 2026] [:error] [pid 12276:tid 140706853074688] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amcxv-csEMuHmMYmk67LzQAAAFU"]
[Mon Jul 27 12:23:59.753569 2026] [:error] [pid 12276:tid 140707020928768] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amcxv-csEMuHmMYmk67LzwAAAEE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.754395 2026] [:error] [pid 12276:tid 140707020928768] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amcxv-csEMuHmMYmk67LzwAAAEE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.754961 2026] [:error] [pid 12276:tid 140707020928768] [client 104.22.24.56:10551] [client 104.22.24.56] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amcxv-csEMuHmMYmk67LzwAAAEE"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.819602 2026] [:error] [pid 12276:tid 140707004143360] [client 104.22.24.57:9595] [client 104.22.24.57] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/cache/config.php"] [unique_id "amcxv-csEMuHmMYmk67L0AAAAEM"]
[Mon Jul 27 12:23:59.820477 2026] [:error] [pid 12276:tid 140707004143360] [client 104.22.24.57:9595] [client 104.22.24.57] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/cache/config.php"] [unique_id "amcxv-csEMuHmMYmk67L0AAAAEM"]
[Mon Jul 27 12:23:59.820958 2026] [:error] [pid 12276:tid 140707004143360] [client 104.22.24.57:9595] [client 104.22.24.57] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/cache/config.php"] [unique_id "amcxv-csEMuHmMYmk67L0AAAAEM"]
[Mon Jul 27 12:23:59.855862 2026] [:error] [pid 17228:tid 140706978965248] [client 104.22.57.46:13022] [client 104.22.57.46] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcxv5jBQLO4t9VCDfpvzQAAAQY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.856459 2026] [:error] [pid 17228:tid 140706978965248] [client 104.22.57.46:13022] [client 104.22.57.46] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcxv5jBQLO4t9VCDfpvzQAAAQY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.856962 2026] [:error] [pid 17228:tid 140706978965248] [client 104.22.57.46:13022] [client 104.22.57.46] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcxv5jBQLO4t9VCDfpvzQAAAQY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.856995 2026] [:error] [pid 17228:tid 140706978965248] [client 104.22.57.46:13022] [client 104.22.57.46] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcxv5jBQLO4t9VCDfpvzQAAAQY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:23:59.857225 2026] [:error] [pid 17228:tid 140706978965248] [client 104.22.57.46:13022] [client 104.22.57.46] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amcxv5jBQLO4t9VCDfpvzQAAAQY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:00.025524 2026] [:error] [pid 12276:tid 140706995750656] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amcxwOcsEMuHmMYmk67L0gAAAEQ"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:00.026228 2026] [:error] [pid 12276:tid 140706995750656] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amcxwOcsEMuHmMYmk67L0gAAAEQ"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:00.026655 2026] [:error] [pid 12276:tid 140706995750656] [client 104.23.245.28:9438] [client 104.23.245.28] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amcxwOcsEMuHmMYmk67L0gAAAEQ"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:00.070584 2026] [:error] [pid 23952:tid 140706861467392] [client 104.23.245.28:14219] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcxwC8h5OE555JiBB9RJQAAAlQ"]
[Mon Jul 27 12:24:00.071405 2026] [:error] [pid 23952:tid 140706861467392] [client 104.23.245.28:14219] [client 104.23.245.28] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcxwC8h5OE555JiBB9RJQAAAlQ"]
[Mon Jul 27 12:24:00.071966 2026] [:error] [pid 23952:tid 140706861467392] [client 104.23.245.28:14219] [client 104.23.245.28] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcxwC8h5OE555JiBB9RJQAAAlQ"]
[Mon Jul 27 12:24:00.072215 2026] [:error] [pid 23952:tid 140706861467392] [client 104.23.245.28:14219] [client 104.23.245.28] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amcxwC8h5OE555JiBB9RJQAAAlQ"]
[Mon Jul 27 12:24:02.739784 2026] [:error] [pid 17228:tid 140707012536064] [client 104.22.57.45:14129] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amcxwpjBQLO4t9VCDfpv3wAAAQI"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:02.740698 2026] [:error] [pid 17228:tid 140707012536064] [client 104.22.57.45:14129] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amcxwpjBQLO4t9VCDfpv3wAAAQI"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:02.741419 2026] [:error] [pid 17228:tid 140707012536064] [client 104.22.57.45:14129] [client 104.22.57.45] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amcxwpjBQLO4t9VCDfpv3wAAAQI"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:02.741474 2026] [:error] [pid 17228:tid 140707012536064] [client 104.22.57.45:14129] [client 104.22.57.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amcxwpjBQLO4t9VCDfpv3wAAAQI"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:03.149581 2026] [:error] [pid 12276:tid 140706861467392] [client 172.68.70.69:10824] [client 172.68.70.69] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/cache/config.php"] [unique_id "amcxw-csEMuHmMYmk67L5QAAAFQ"]
[Mon Jul 27 12:24:03.150452 2026] [:error] [pid 12276:tid 140706861467392] [client 172.68.70.69:10824] [client 172.68.70.69] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/cache/config.php"] [unique_id "amcxw-csEMuHmMYmk67L5QAAAFQ"]
[Mon Jul 27 12:24:03.151314 2026] [:error] [pid 12276:tid 140706861467392] [client 172.68.70.69:10824] [client 172.68.70.69] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/cache/config.php"] [unique_id "amcxw-csEMuHmMYmk67L5QAAAFQ"]
[Mon Jul 27 12:24:03.151391 2026] [:error] [pid 12276:tid 140706861467392] [client 172.68.70.69:10824] [client 172.68.70.69] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/cache/config.php"] [unique_id "amcxw-csEMuHmMYmk67L5QAAAFQ"]
[Mon Jul 27 12:24:07.024159 2026] [:error] [pid 17228:tid 140706945394432] [client 104.22.57.45:14129] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/app"] [unique_id "amcxx5jBQLO4t9VCDfpv-wAAAQo"]
[Mon Jul 27 12:24:07.025195 2026] [:error] [pid 17228:tid 140706945394432] [client 104.22.57.45:14129] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/app"] [unique_id "amcxx5jBQLO4t9VCDfpv-wAAAQo"]
[Mon Jul 27 12:24:07.025785 2026] [:error] [pid 17228:tid 140706945394432] [client 104.22.57.45:14129] [client 104.22.57.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app"] [unique_id "amcxx5jBQLO4t9VCDfpv-wAAAQo"]
[Mon Jul 27 12:24:07.056106 2026] [:error] [pid 12276:tid 140706937001728] [client 172.68.70.69:10824] [client 172.68.70.69] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dashboard"] [unique_id "amcxx-csEMuHmMYmk67L9wAAAEs"]
[Mon Jul 27 12:24:07.057222 2026] [:error] [pid 12276:tid 140706937001728] [client 172.68.70.69:10824] [client 172.68.70.69] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dashboard"] [unique_id "amcxx-csEMuHmMYmk67L9wAAAEs"]
[Mon Jul 27 12:24:07.057846 2026] [:error] [pid 12276:tid 140706937001728] [client 172.68.70.69:10824] [client 172.68.70.69] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dashboard"] [unique_id "amcxx-csEMuHmMYmk67L9wAAAEs"]
[Mon Jul 27 12:24:07.320642 2026] [:error] [pid 23952:tid 140706853074688] [client 172.69.71.180:11773] [client 172.69.71.180] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/checkout"] [unique_id "amcxxy8h5OE555JiBB9RJwAAAlU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.321542 2026] [:error] [pid 23952:tid 140706853074688] [client 172.69.71.180:11773] [client 172.69.71.180] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/checkout"] [unique_id "amcxxy8h5OE555JiBB9RJwAAAlU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.322239 2026] [:error] [pid 23952:tid 140706853074688] [client 172.69.71.180:11773] [client 172.69.71.180] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/checkout"] [unique_id "amcxxy8h5OE555JiBB9RJwAAAlU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.337356 2026] [:error] [pid 12276:tid 140706911823616] [client 172.71.22.117:13679] [client 172.71.22.117] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin"] [unique_id "amcxx-csEMuHmMYmk67L-gAAAE4"]
[Mon Jul 27 12:24:07.338239 2026] [:error] [pid 12276:tid 140706911823616] [client 172.71.22.117:13679] [client 172.71.22.117] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin"] [unique_id "amcxx-csEMuHmMYmk67L-gAAAE4"]
[Mon Jul 27 12:24:07.338784 2026] [:error] [pid 12276:tid 140706911823616] [client 172.71.22.117:13679] [client 172.71.22.117] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin"] [unique_id "amcxx-csEMuHmMYmk67L-gAAAE4"]
[Mon Jul 27 12:24:07.343035 2026] [:error] [pid 12277:tid 140706987357952] [client 172.69.71.179:11724] [client 172.69.71.179] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/pricing"] [unique_id "amcxxxwjcb8HQE21kA6t1QAAAIU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.343916 2026] [:error] [pid 12277:tid 140706987357952] [client 172.69.71.179:11724] [client 172.69.71.179] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/pricing"] [unique_id "amcxxxwjcb8HQE21kA6t1QAAAIU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.344493 2026] [:error] [pid 12277:tid 140706987357952] [client 172.69.71.179:11724] [client 172.69.71.179] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/pricing"] [unique_id "amcxxxwjcb8HQE21kA6t1QAAAIU"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.345587 2026] [:error] [pid 10035:tid 140706844681984] [client 172.71.22.116:13294] [client 172.71.22.116] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/login"] [unique_id "amcxx7M5Xj3nsMbGSqttDAAAAdY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.346092 2026] [:error] [pid 10035:tid 140706844681984] [client 172.71.22.116:13294] [client 172.71.22.116] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/login"] [unique_id "amcxx7M5Xj3nsMbGSqttDAAAAdY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.346540 2026] [:error] [pid 10035:tid 140706844681984] [client 172.71.22.116:13294] [client 172.71.22.116] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/login"] [unique_id "amcxx7M5Xj3nsMbGSqttDAAAAdY"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.351714 2026] [:error] [pid 17228:tid 140706827896576] [client 104.22.57.45:11097] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amcxx5jBQLO4t9VCDfpv_wAAARg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.352497 2026] [:error] [pid 17228:tid 140706827896576] [client 104.22.57.45:11097] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amcxx5jBQLO4t9VCDfpv_wAAARg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.353177 2026] [:error] [pid 17228:tid 140706827896576] [client 104.22.57.45:11097] [client 104.22.57.45] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amcxx5jBQLO4t9VCDfpv_wAAARg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.353232 2026] [:error] [pid 17228:tid 140706827896576] [client 104.22.57.45:11097] [client 104.22.57.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amcxx5jBQLO4t9VCDfpv_wAAARg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.354958 2026] [:error] [pid 17228:tid 140706861467392] [client 108.162.237.146:12738] [client 108.162.237.146] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/settings"] [unique_id "amcxx5jBQLO4t9VCDfpwAAAAARQ"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.355615 2026] [:error] [pid 17228:tid 140706861467392] [client 108.162.237.146:12738] [client 108.162.237.146] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/settings"] [unique_id "amcxx5jBQLO4t9VCDfpwAAAAARQ"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.355796 2026] [:error] [pid 12275:tid 140706827896576] [client 172.69.71.180:11778] [client 172.69.71.180] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/signup"] [unique_id "amcxx3FwI8r7BFXGkAvDOQAAABg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.356269 2026] [:error] [pid 17228:tid 140706861467392] [client 108.162.237.146:12738] [client 108.162.237.146] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/settings"] [unique_id "amcxx5jBQLO4t9VCDfpwAAAAARQ"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.356321 2026] [:error] [pid 17228:tid 140706861467392] [client 108.162.237.146:12738] [client 108.162.237.146] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/settings"] [unique_id "amcxx5jBQLO4t9VCDfpwAAAAARQ"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.356337 2026] [:error] [pid 12275:tid 140706827896576] [client 172.69.71.180:11778] [client 172.69.71.180] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/signup"] [unique_id "amcxx3FwI8r7BFXGkAvDOQAAABg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:24:07.356798 2026] [:error] [pid 12275:tid 140706827896576] [client 172.69.71.180:11778] [client 172.69.71.180] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/signup"] [unique_id "amcxx3FwI8r7BFXGkAvDOQAAABg"], referer: https://www.google.com/search?q=sbf-consultancy.com
[Mon Jul 27 12:35:34.478922 2026] [:error] [pid 12277:tid 140706844681984] [client 172.64.198.97:10055] [client 172.64.198.97] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amc0dhwjcb8HQE21kA6vRgAAAJY"]
[Mon Jul 27 12:35:34.484431 2026] [:error] [pid 12277:tid 140706844681984] [client 172.64.198.97:10055] [client 172.64.198.97] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amc0dhwjcb8HQE21kA6vRgAAAJY"]
[Mon Jul 27 12:35:34.484809 2026] [:error] [pid 12277:tid 140706844681984] [client 172.64.198.97:10055] [client 172.64.198.97] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amc0dhwjcb8HQE21kA6vRgAAAJY"]
[Mon Jul 27 12:37:53.266143 2026] [:error] [pid 21545:tid 140706878252800] [client 104.23.170.163:13340] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amc1AZhXfYDIcpslIWPIdwAAAZI"]
[Mon Jul 27 12:37:53.267037 2026] [:error] [pid 21545:tid 140706878252800] [client 104.23.170.163:13340] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amc1AZhXfYDIcpslIWPIdwAAAZI"]
[Mon Jul 27 12:37:53.267519 2026] [:error] [pid 21545:tid 140706878252800] [client 104.23.170.163:13340] [client 104.23.170.163] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amc1AZhXfYDIcpslIWPIdwAAAZI"]
[Mon Jul 27 12:52:10.184948 2026] [:error] [pid 12380:tid 140706945394432] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/_rNd9xZ7kL3"] [unique_id "amc4WqaChfbWW0CZ_hqIFAAAAMo"]
[Mon Jul 27 12:52:10.185994 2026] [:error] [pid 12380:tid 140706945394432] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/_rNd9xZ7kL3"] [unique_id "amc4WqaChfbWW0CZ_hqIFAAAAMo"]
[Mon Jul 27 12:52:10.186659 2026] [:error] [pid 12380:tid 140706945394432] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/_rNd9xZ7kL3"] [unique_id "amc4WqaChfbWW0CZ_hqIFAAAAMo"]
[Mon Jul 27 12:52:10.186713 2026] [:error] [pid 12380:tid 140706945394432] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/_rNd9xZ7kL3"] [unique_id "amc4WqaChfbWW0CZ_hqIFAAAAMo"]
[Mon Jul 27 12:52:13.264402 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amc4XaaChfbWW0CZ_hqIHQAAAMg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:13.265328 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amc4XaaChfbWW0CZ_hqIHQAAAMg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:13.266169 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amc4XaaChfbWW0CZ_hqIHQAAAMg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:13.266226 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amc4XaaChfbWW0CZ_hqIHQAAAMg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:14.350546 2026] [:error] [pid 24106:tid 140706945394432] [client 172.64.223.9:11552] [client 172.64.223.9] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amc4Xjs8oMu6f6EYbxQIkwAAAUo"]
[Mon Jul 27 12:52:14.351392 2026] [:error] [pid 24106:tid 140706945394432] [client 172.64.223.9:11552] [client 172.64.223.9] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amc4Xjs8oMu6f6EYbxQIkwAAAUo"]
[Mon Jul 27 12:52:14.351990 2026] [:error] [pid 24106:tid 140706945394432] [client 172.64.223.9:11552] [client 172.64.223.9] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amc4Xjs8oMu6f6EYbxQIkwAAAUo"]
[Mon Jul 27 12:52:14.724069 2026] [:error] [pid 12380:tid 140706853074688] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amc4XqaChfbWW0CZ_hqIIwAAANU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:14.724826 2026] [:error] [pid 12380:tid 140706853074688] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amc4XqaChfbWW0CZ_hqIIwAAANU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:14.725344 2026] [:error] [pid 12380:tid 140706853074688] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amc4XqaChfbWW0CZ_hqIIwAAANU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:16.005359 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap_index.xml"] [unique_id "amc4YKaChfbWW0CZ_hqIJQAAAMA"]
[Mon Jul 27 12:52:16.006010 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap_index.xml"] [unique_id "amc4YKaChfbWW0CZ_hqIJQAAAMA"]
[Mon Jul 27 12:52:16.006629 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap_index.xml"] [unique_id "amc4YKaChfbWW0CZ_hqIJQAAAMA"]
[Mon Jul 27 12:52:16.006677 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.238.82:10663] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap_index.xml"] [unique_id "amc4YKaChfbWW0CZ_hqIJQAAAMA"]
[Mon Jul 27 12:52:21.980054 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap_index.xml"] [unique_id "amc4ZecsEMuHmMYmk67XywAAAEg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:21.980741 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap_index.xml"] [unique_id "amc4ZecsEMuHmMYmk67XywAAAEg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:21.981251 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap_index.xml"] [unique_id "amc4ZecsEMuHmMYmk67XywAAAEg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:22.500885 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap-index.xml"] [unique_id "amc4ZucsEMuHmMYmk67XzQAAAFY"]
[Mon Jul 27 12:52:22.501870 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap-index.xml"] [unique_id "amc4ZucsEMuHmMYmk67XzQAAAFY"]
[Mon Jul 27 12:52:22.502437 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap-index.xml"] [unique_id "amc4ZucsEMuHmMYmk67XzQAAAFY"]
[Mon Jul 27 12:52:22.894596 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amc4ZucsEMuHmMYmk67XzwAAAFU"]
[Mon Jul 27 12:52:22.895260 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amc4ZucsEMuHmMYmk67XzwAAAFU"]
[Mon Jul 27 12:52:22.895701 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amc4ZucsEMuHmMYmk67XzwAAAFU"]
[Mon Jul 27 12:52:22.895738 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amc4ZucsEMuHmMYmk67XzwAAAFU"]
[Mon Jul 27 12:52:22.895955 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amc4ZucsEMuHmMYmk67XzwAAAFU"]
[Mon Jul 27 12:52:22.947997 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amc4ZucsEMuHmMYmk67X0AAAAEw"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:22.948887 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amc4ZucsEMuHmMYmk67X0AAAAEw"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:22.949636 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amc4ZucsEMuHmMYmk67X0AAAAEw"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:22.949693 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amc4ZucsEMuHmMYmk67X0AAAAEw"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:22.950118 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amc4ZucsEMuHmMYmk67X0AAAAEw"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:22.987056 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amc4ZucsEMuHmMYmk67X0QAAAEo"]
[Mon Jul 27 12:52:22.987499 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amc4ZucsEMuHmMYmk67X0QAAAEo"]
[Mon Jul 27 12:52:22.987770 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amc4ZucsEMuHmMYmk67X0QAAAEo"]
[Mon Jul 27 12:52:22.987937 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amc4ZucsEMuHmMYmk67X0QAAAEo"]
[Mon Jul 27 12:52:23.033709 2026] [:error] [pid 12380:tid 140706895038208] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amc4Z6aChfbWW0CZ_hqILQAAANA"]
[Mon Jul 27 12:52:23.034900 2026] [:error] [pid 12380:tid 140706895038208] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amc4Z6aChfbWW0CZ_hqILQAAANA"]
[Mon Jul 27 12:52:23.035494 2026] [:error] [pid 12380:tid 140706895038208] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amc4Z6aChfbWW0CZ_hqILQAAANA"]
[Mon Jul 27 12:52:23.035805 2026] [:error] [pid 12380:tid 140706895038208] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amc4Z6aChfbWW0CZ_hqILQAAANA"]
[Mon Jul 27 12:52:23.078997 2026] [:error] [pid 12380:tid 140706903430912] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amc4Z6aChfbWW0CZ_hqILgAAAM8"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.079878 2026] [:error] [pid 12380:tid 140706903430912] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amc4Z6aChfbWW0CZ_hqILgAAAM8"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.080389 2026] [:error] [pid 12380:tid 140706903430912] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amc4Z6aChfbWW0CZ_hqILgAAAM8"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.080437 2026] [:error] [pid 12380:tid 140706903430912] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amc4Z6aChfbWW0CZ_hqILgAAAM8"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.161643 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amc4Z-csEMuHmMYmk67X0gAAAFE"]
[Mon Jul 27 12:52:23.162494 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amc4Z-csEMuHmMYmk67X0gAAAFE"]
[Mon Jul 27 12:52:23.162987 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amc4Z-csEMuHmMYmk67X0gAAAFE"]
[Mon Jul 27 12:52:23.163026 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amc4Z-csEMuHmMYmk67X0gAAAFE"]
[Mon Jul 27 12:52:23.163309 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amc4Z-csEMuHmMYmk67X0gAAAFE"]
[Mon Jul 27 12:52:23.172269 2026] [:error] [pid 12380:tid 140706886645504] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.dev.vars"] [unique_id "amc4Z6aChfbWW0CZ_hqILwAAANE"]
[Mon Jul 27 12:52:23.172873 2026] [:error] [pid 12380:tid 140706886645504] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.dev.vars"] [unique_id "amc4Z6aChfbWW0CZ_hqILwAAANE"]
[Mon Jul 27 12:52:23.173346 2026] [:error] [pid 12380:tid 140706886645504] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.dev.vars"] [unique_id "amc4Z6aChfbWW0CZ_hqILwAAANE"]
[Mon Jul 27 12:52:23.173381 2026] [:error] [pid 12380:tid 140706886645504] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.dev.vars"] [unique_id "amc4Z6aChfbWW0CZ_hqILwAAANE"]
[Mon Jul 27 12:52:23.529138 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amc4Z6aChfbWW0CZ_hqIMQAAAM0"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.530074 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amc4Z6aChfbWW0CZ_hqIMQAAAM0"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.530775 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amc4Z6aChfbWW0CZ_hqIMQAAAM0"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.530853 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amc4Z6aChfbWW0CZ_hqIMQAAAM0"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.531194 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amc4Z6aChfbWW0CZ_hqIMQAAAM0"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.823934 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amc4Z-csEMuHmMYmk67X1AAAAFQ"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.824780 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amc4Z-csEMuHmMYmk67X1AAAAFQ"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.825475 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amc4Z-csEMuHmMYmk67X1AAAAFQ"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.825513 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amc4Z-csEMuHmMYmk67X1AAAAFQ"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.825804 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amc4Z-csEMuHmMYmk67X1AAAAFQ"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.877344 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4Z6aChfbWW0CZ_hqIMgAAAMA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.878209 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4Z6aChfbWW0CZ_hqIMgAAAMA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.878946 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4Z6aChfbWW0CZ_hqIMgAAAMA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.878999 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4Z6aChfbWW0CZ_hqIMgAAAMA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.879354 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4Z6aChfbWW0CZ_hqIMgAAAMA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:23.936125 2026] [:error] [pid 12380:tid 140706928609024] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amc4Z6aChfbWW0CZ_hqIMwAAAMw"]
[Mon Jul 27 12:52:23.937027 2026] [:error] [pid 12380:tid 140706928609024] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amc4Z6aChfbWW0CZ_hqIMwAAAMw"]
[Mon Jul 27 12:52:23.937641 2026] [:error] [pid 12380:tid 140706928609024] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amc4Z6aChfbWW0CZ_hqIMwAAAMw"]
[Mon Jul 27 12:52:24.044499 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amc4aOcsEMuHmMYmk67X1gAAAEM"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.045547 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amc4aOcsEMuHmMYmk67X1gAAAEM"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.046246 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amc4aOcsEMuHmMYmk67X1gAAAEM"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.046313 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amc4aOcsEMuHmMYmk67X1gAAAEM"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.046637 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amc4aOcsEMuHmMYmk67X1gAAAEM"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.240490 2026] [:error] [pid 12380:tid 140706911823616] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amc4aKaChfbWW0CZ_hqINQAAAM4"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.241146 2026] [:error] [pid 12380:tid 140706911823616] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amc4aKaChfbWW0CZ_hqINQAAAM4"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.241527 2026] [:error] [pid 12380:tid 140706911823616] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amc4aKaChfbWW0CZ_hqINQAAAM4"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.241721 2026] [:error] [pid 12380:tid 140706911823616] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amc4aKaChfbWW0CZ_hqINQAAAM4"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.491421 2026] [:error] [pid 12380:tid 140706987357952] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amc4aKaChfbWW0CZ_hqINgAAAMU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.492280 2026] [:error] [pid 12380:tid 140706987357952] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amc4aKaChfbWW0CZ_hqINgAAAMU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.492895 2026] [:error] [pid 12380:tid 140706987357952] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amc4aKaChfbWW0CZ_hqINgAAAMU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.493225 2026] [:error] [pid 12380:tid 140706987357952] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amc4aKaChfbWW0CZ_hqINgAAAMU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.549810 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amc4aOcsEMuHmMYmk67X1wAAAEk"]
[Mon Jul 27 12:52:24.550457 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amc4aOcsEMuHmMYmk67X1wAAAEk"]
[Mon Jul 27 12:52:24.550904 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amc4aOcsEMuHmMYmk67X1wAAAEk"]
[Mon Jul 27 12:52:24.551082 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amc4aOcsEMuHmMYmk67X1wAAAEk"]
[Mon Jul 27 12:52:24.711650 2026] [:error] [pid 12380:tid 140706869860096] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amc4aKaChfbWW0CZ_hqINwAAANM"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.712535 2026] [:error] [pid 12380:tid 140706869860096] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amc4aKaChfbWW0CZ_hqINwAAANM"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.713104 2026] [:error] [pid 12380:tid 140706869860096] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amc4aKaChfbWW0CZ_hqINwAAANM"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.713381 2026] [:error] [pid 12380:tid 140706869860096] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amc4aKaChfbWW0CZ_hqINwAAANM"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.736718 2026] [:error] [pid 12380:tid 140706978965248] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amc4aKaChfbWW0CZ_hqIOAAAAMY"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.737652 2026] [:error] [pid 12380:tid 140706978965248] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amc4aKaChfbWW0CZ_hqIOAAAAMY"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.738376 2026] [:error] [pid 12380:tid 140706978965248] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amc4aKaChfbWW0CZ_hqIOAAAAMY"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.738436 2026] [:error] [pid 12380:tid 140706978965248] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amc4aKaChfbWW0CZ_hqIOAAAAMY"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.738674 2026] [:error] [pid 12380:tid 140706978965248] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amc4aKaChfbWW0CZ_hqIOAAAAMY"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.975901 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amc4aOcsEMuHmMYmk67X2gAAAFA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.976928 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amc4aOcsEMuHmMYmk67X2gAAAFA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.977482 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amc4aOcsEMuHmMYmk67X2gAAAFA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.977516 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amc4aOcsEMuHmMYmk67X2gAAAFA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.986725 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amc4aKaChfbWW0CZ_hqIOgAAAMg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.987617 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amc4aKaChfbWW0CZ_hqIOgAAAMg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.988296 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amc4aKaChfbWW0CZ_hqIOgAAAMg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.988350 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amc4aKaChfbWW0CZ_hqIOgAAAMg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:24.988671 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amc4aKaChfbWW0CZ_hqIOgAAAMg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:25.540078 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.239.112:12607] [client 162.158.239.112] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/assets/index-o-9Bhaif.js"] [unique_id "amc4aRwjcb8HQE21kA60KgAAAJA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:25.541055 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.239.112:12607] [client 162.158.239.112] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/assets/index-o-9Bhaif.js"] [unique_id "amc4aRwjcb8HQE21kA60KgAAAJA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:25.542236 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.239.112:12607] [client 162.158.239.112] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/assets/index-o-9Bhaif.js"] [unique_id "amc4aRwjcb8HQE21kA60KgAAAJA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:25.642605 2026] [:error] [pid 12380:tid 140707020928768] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amc4aaaChfbWW0CZ_hqIOwAAAME"]
[Mon Jul 27 12:52:25.643450 2026] [:error] [pid 12380:tid 140707020928768] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amc4aaaChfbWW0CZ_hqIOwAAAME"]
[Mon Jul 27 12:52:25.644028 2026] [:error] [pid 12380:tid 140707020928768] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amc4aaaChfbWW0CZ_hqIOwAAAME"]
[Mon Jul 27 12:52:25.644326 2026] [:error] [pid 12380:tid 140707020928768] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amc4aaaChfbWW0CZ_hqIOwAAAME"]
[Mon Jul 27 12:52:25.797626 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amc4aecsEMuHmMYmk67X3AAAAE0"]
[Mon Jul 27 12:52:25.798356 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amc4aecsEMuHmMYmk67X3AAAAE0"]
[Mon Jul 27 12:52:25.798916 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amc4aecsEMuHmMYmk67X3AAAAE0"]
[Mon Jul 27 12:52:25.799142 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amc4aecsEMuHmMYmk67X3AAAAE0"]
[Mon Jul 27 12:52:26.190483 2026] [:error] [pid 12380:tid 140706886645504] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amc4aqaChfbWW0CZ_hqIPQAAANE"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.191173 2026] [:error] [pid 12380:tid 140706886645504] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amc4aqaChfbWW0CZ_hqIPQAAANE"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.191688 2026] [:error] [pid 12380:tid 140706886645504] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amc4aqaChfbWW0CZ_hqIPQAAANE"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.191725 2026] [:error] [pid 12380:tid 140706886645504] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amc4aqaChfbWW0CZ_hqIPQAAANE"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.191948 2026] [:error] [pid 12380:tid 140706886645504] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amc4aqaChfbWW0CZ_hqIPQAAANE"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.295801 2026] [:error] [pid 12380:tid 140706995750656] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4aqaChfbWW0CZ_hqIPgAAAMQ"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.296639 2026] [:error] [pid 12380:tid 140706995750656] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4aqaChfbWW0CZ_hqIPgAAAMQ"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.297310 2026] [:error] [pid 12380:tid 140706995750656] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4aqaChfbWW0CZ_hqIPgAAAMQ"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.297358 2026] [:error] [pid 12380:tid 140706995750656] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4aqaChfbWW0CZ_hqIPgAAAMQ"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.297707 2026] [:error] [pid 12380:tid 140706995750656] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4aqaChfbWW0CZ_hqIPgAAAMQ"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.412424 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amc4aucsEMuHmMYmk67X3QAAAFI"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.413092 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amc4aucsEMuHmMYmk67X3QAAAFI"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.413521 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.yml"] [unique_id "amc4aucsEMuHmMYmk67X3QAAAFI"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.939994 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amc4aqaChfbWW0CZ_hqIPwAAAM0"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.940666 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amc4aqaChfbWW0CZ_hqIPwAAAM0"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.941166 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amc4aqaChfbWW0CZ_hqIPwAAAM0"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:26.941476 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amc4aqaChfbWW0CZ_hqIPwAAAM0"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:27.129604 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amc4a6aChfbWW0CZ_hqIQAAAAMA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:27.130347 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amc4a6aChfbWW0CZ_hqIQAAAAMA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:27.130947 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amc4a6aChfbWW0CZ_hqIQAAAAMA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:27.131010 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amc4a6aChfbWW0CZ_hqIQAAAAMA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:27.131332 2026] [:error] [pid 12380:tid 140707103270656] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amc4a6aChfbWW0CZ_hqIQAAAAMA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:27.778505 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amc4a-csEMuHmMYmk67X3gAAAEs"]
[Mon Jul 27 12:52:27.779250 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amc4a-csEMuHmMYmk67X3gAAAEs"]
[Mon Jul 27 12:52:27.779995 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amc4a-csEMuHmMYmk67X3gAAAEs"]
[Mon Jul 27 12:52:27.780293 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production.local"] [unique_id "amc4a-csEMuHmMYmk67X3gAAAEs"]
[Mon Jul 27 12:52:27.833849 2026] [:error] [pid 12380:tid 140706928609024] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amc4a6aChfbWW0CZ_hqIQQAAAMw"]
[Mon Jul 27 12:52:27.834656 2026] [:error] [pid 12380:tid 140706928609024] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amc4a6aChfbWW0CZ_hqIQQAAAMw"]
[Mon Jul 27 12:52:27.835095 2026] [:error] [pid 12380:tid 140706928609024] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amc4a6aChfbWW0CZ_hqIQQAAAMw"]
[Mon Jul 27 12:52:27.835317 2026] [:error] [pid 12380:tid 140706928609024] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amc4a6aChfbWW0CZ_hqIQQAAAMw"]
[Mon Jul 27 12:52:27.929135 2026] [:error] [pid 12380:tid 140706827896576] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amc4a6aChfbWW0CZ_hqIQgAAANg"]
[Mon Jul 27 12:52:27.930050 2026] [:error] [pid 12380:tid 140706827896576] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amc4a6aChfbWW0CZ_hqIQgAAANg"]
[Mon Jul 27 12:52:27.930612 2026] [:error] [pid 12380:tid 140706827896576] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amc4a6aChfbWW0CZ_hqIQgAAANg"]
[Mon Jul 27 12:52:28.101783 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.pypirc"] [unique_id "amc4bOcsEMuHmMYmk67X3wAAAEc"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:28.102705 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.pypirc"] [unique_id "amc4bOcsEMuHmMYmk67X3wAAAEc"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:28.103281 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.pypirc"] [unique_id "amc4bOcsEMuHmMYmk67X3wAAAEc"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:28.232115 2026] [:error] [pid 12380:tid 140706987357952] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amc4bKaChfbWW0CZ_hqIRAAAAMU"]
[Mon Jul 27 12:52:28.233238 2026] [:error] [pid 12380:tid 140706987357952] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amc4bKaChfbWW0CZ_hqIRAAAAMU"]
[Mon Jul 27 12:52:28.233949 2026] [:error] [pid 12380:tid 140706987357952] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amc4bKaChfbWW0CZ_hqIRAAAAMU"]
[Mon Jul 27 12:52:28.234010 2026] [:error] [pid 12380:tid 140706987357952] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amc4bKaChfbWW0CZ_hqIRAAAAMU"]
[Mon Jul 27 12:52:28.322211 2026] [:error] [pid 12380:tid 140706945394432] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amc4bKaChfbWW0CZ_hqIRQAAAMo"]
[Mon Jul 27 12:52:28.323145 2026] [:error] [pid 12380:tid 140706945394432] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amc4bKaChfbWW0CZ_hqIRQAAAMo"]
[Mon Jul 27 12:52:28.323857 2026] [:error] [pid 12380:tid 140706945394432] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amc4bKaChfbWW0CZ_hqIRQAAAMo"]
[Mon Jul 27 12:52:28.323921 2026] [:error] [pid 12380:tid 140706945394432] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amc4bKaChfbWW0CZ_hqIRQAAAMo"]
[Mon Jul 27 12:52:28.324176 2026] [:error] [pid 12380:tid 140706945394432] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amc4bKaChfbWW0CZ_hqIRQAAAMo"]
[Mon Jul 27 12:52:28.418091 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amc4bOcsEMuHmMYmk67X4AAAAE4"]
[Mon Jul 27 12:52:28.418935 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amc4bOcsEMuHmMYmk67X4AAAAE4"]
[Mon Jul 27 12:52:28.419386 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amc4bOcsEMuHmMYmk67X4AAAAE4"]
[Mon Jul 27 12:52:28.419680 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amc4bOcsEMuHmMYmk67X4AAAAE4"]
[Mon Jul 27 12:52:28.595300 2026] [:error] [pid 12380:tid 140707004143360] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amc4bKaChfbWW0CZ_hqIRgAAAMM"]
[Mon Jul 27 12:52:28.595925 2026] [:error] [pid 12380:tid 140707004143360] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amc4bKaChfbWW0CZ_hqIRgAAAMM"]
[Mon Jul 27 12:52:28.596294 2026] [:error] [pid 12380:tid 140707004143360] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amc4bKaChfbWW0CZ_hqIRgAAAMM"]
[Mon Jul 27 12:52:28.596524 2026] [:error] [pid 12380:tid 140707004143360] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amc4bKaChfbWW0CZ_hqIRgAAAMM"]
[Mon Jul 27 12:52:28.641254 2026] [:error] [pid 12380:tid 140706869860096] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amc4bKaChfbWW0CZ_hqIRwAAANM"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:28.641966 2026] [:error] [pid 12380:tid 140706869860096] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amc4bKaChfbWW0CZ_hqIRwAAANM"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:28.642566 2026] [:error] [pid 12380:tid 140706869860096] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amc4bKaChfbWW0CZ_hqIRwAAANM"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:28.642865 2026] [:error] [pid 12380:tid 140706869860096] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amc4bKaChfbWW0CZ_hqIRwAAANM"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:28.775387 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.dev.vars"] [unique_id "amc4bOcsEMuHmMYmk67X4QAAAEE"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:28.776242 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.dev.vars"] [unique_id "amc4bOcsEMuHmMYmk67X4QAAAEE"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:28.776960 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.dev.vars"] [unique_id "amc4bOcsEMuHmMYmk67X4QAAAEE"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:28.777019 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.dev.vars"] [unique_id "amc4bOcsEMuHmMYmk67X4QAAAEE"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:28.891621 2026] [:error] [pid 12380:tid 140706853074688] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/settings.json"] [unique_id "amc4bKaChfbWW0CZ_hqISQAAANU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:28.892321 2026] [:error] [pid 12380:tid 140706853074688] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/settings.json"] [unique_id "amc4bKaChfbWW0CZ_hqISQAAANU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:28.892760 2026] [:error] [pid 12380:tid 140706853074688] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/settings.json"] [unique_id "amc4bKaChfbWW0CZ_hqISQAAANU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:28.944754 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.netrc"] [unique_id "amc4bKaChfbWW0CZ_hqISgAAAMg"]
[Mon Jul 27 12:52:28.945664 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.netrc"] [unique_id "amc4bKaChfbWW0CZ_hqISgAAAMg"]
[Mon Jul 27 12:52:28.946113 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.netrc"] [unique_id "amc4bKaChfbWW0CZ_hqISgAAAMg"]
[Mon Jul 27 12:52:28.946433 2026] [:error] [pid 12380:tid 140706962179840] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Matched phrase ".netrc" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .netrc found within REQUEST_FILENAME: /.netrc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.netrc"] [unique_id "amc4bKaChfbWW0CZ_hqISgAAAMg"]
[Mon Jul 27 12:52:29.472842 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amc4becsEMuHmMYmk67X4gAAAEI"]
[Mon Jul 27 12:52:29.473456 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amc4becsEMuHmMYmk67X4gAAAEI"]
[Mon Jul 27 12:52:29.473893 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amc4becsEMuHmMYmk67X4gAAAEI"]
[Mon Jul 27 12:52:29.474069 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.docker/config.json"] [unique_id "amc4becsEMuHmMYmk67X4gAAAEI"]
[Mon Jul 27 12:52:29.669866 2026] [:error] [pid 12380:tid 140706970572544] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amc4baaChfbWW0CZ_hqISwAAAMc"]
[Mon Jul 27 12:52:29.670506 2026] [:error] [pid 12380:tid 140706970572544] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amc4baaChfbWW0CZ_hqISwAAAMc"]
[Mon Jul 27 12:52:29.671009 2026] [:error] [pid 12380:tid 140706970572544] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amc4baaChfbWW0CZ_hqISwAAAMc"]
[Mon Jul 27 12:52:29.671188 2026] [:error] [pid 12380:tid 140706970572544] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amc4baaChfbWW0CZ_hqISwAAAMc"]
[Mon Jul 27 12:52:30.056253 2026] [:error] [pid 12380:tid 140706895038208] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.cursor/mcp.json"] [unique_id "amc4bqaChfbWW0CZ_hqITwAAANA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:30.057238 2026] [:error] [pid 12380:tid 140706895038208] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.cursor/mcp.json"] [unique_id "amc4bqaChfbWW0CZ_hqITwAAANA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:30.057946 2026] [:error] [pid 12380:tid 140706895038208] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.cursor/mcp.json"] [unique_id "amc4bqaChfbWW0CZ_hqITwAAANA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:30.057996 2026] [:error] [pid 12380:tid 140706895038208] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.cursor/mcp.json"] [unique_id "amc4bqaChfbWW0CZ_hqITwAAANA"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:30.232582 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amc4bucsEMuHmMYmk67X4wAAAEg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:30.233596 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amc4bucsEMuHmMYmk67X4wAAAEg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:30.234216 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amc4bucsEMuHmMYmk67X4wAAAEg"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:30.588927 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/bootstrap/cache/config.php"] [unique_id "amc4bqaChfbWW0CZ_hqIVAAAAM0"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:30.590116 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/bootstrap/cache/config.php"] [unique_id "amc4bqaChfbWW0CZ_hqIVAAAAM0"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:30.590906 2026] [:error] [pid 12380:tid 140706920216320] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/bootstrap/cache/config.php"] [unique_id "amc4bqaChfbWW0CZ_hqIVAAAAM0"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:31.463391 2026] [:error] [pid 12380:tid 140707012536064] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/bootstrap/cache/config.php"] [unique_id "amc4b6aChfbWW0CZ_hqIWAAAAMI"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:31.464083 2026] [:error] [pid 12380:tid 140707012536064] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/bootstrap/cache/config.php"] [unique_id "amc4b6aChfbWW0CZ_hqIWAAAAMI"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:31.464488 2026] [:error] [pid 12380:tid 140707012536064] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/bootstrap/cache/config.php"] [unique_id "amc4b6aChfbWW0CZ_hqIWAAAAMI"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:31.991913 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4b-csEMuHmMYmk67X5AAAAFU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:31.992763 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4b-csEMuHmMYmk67X5AAAAFU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:31.993462 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4b-csEMuHmMYmk67X5AAAAFU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:31.993535 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4b-csEMuHmMYmk67X5AAAAFU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:31.993945 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amc4b-csEMuHmMYmk67X5AAAAFU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:33.860368 2026] [:error] [pid 12380:tid 140706903430912] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amc4caaChfbWW0CZ_hqIaQAAAM8"]
[Mon Jul 27 12:52:33.861311 2026] [:error] [pid 12380:tid 140706903430912] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amc4caaChfbWW0CZ_hqIaQAAAM8"]
[Mon Jul 27 12:52:33.861976 2026] [:error] [pid 12380:tid 140706903430912] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amc4caaChfbWW0CZ_hqIaQAAAM8"]
[Mon Jul 27 12:52:33.862042 2026] [:error] [pid 12380:tid 140706903430912] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amc4caaChfbWW0CZ_hqIaQAAAM8"]
[Mon Jul 27 12:52:33.862352 2026] [:error] [pid 12380:tid 140706903430912] [client 162.158.238.82:12680] [client 162.158.238.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development.local"] [unique_id "amc4caaChfbWW0CZ_hqIaQAAAM8"]
[Mon Jul 27 12:52:34.198751 2026] [:error] [pid 12380:tid 140706886645504] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/settings.json"] [unique_id "amc4cqaChfbWW0CZ_hqIawAAANE"]
[Mon Jul 27 12:52:34.199762 2026] [:error] [pid 12380:tid 140706886645504] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/settings.json"] [unique_id "amc4cqaChfbWW0CZ_hqIawAAANE"]
[Mon Jul 27 12:52:34.200433 2026] [:error] [pid 12380:tid 140706886645504] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/settings.json"] [unique_id "amc4cqaChfbWW0CZ_hqIawAAANE"]
[Mon Jul 27 12:52:34.200508 2026] [:error] [pid 12380:tid 140706886645504] [client 162.158.238.83:12984] [client 162.158.238.83] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.vscode/settings.json"] [unique_id "amc4cqaChfbWW0CZ_hqIawAAANE"]
[Mon Jul 27 12:52:36.704312 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amc4dOcsEMuHmMYmk67X5QAAAEw"]
[Mon Jul 27 12:52:36.705218 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amc4dOcsEMuHmMYmk67X5QAAAEw"]
[Mon Jul 27 12:52:36.705918 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amc4dOcsEMuHmMYmk67X5QAAAEw"]
[Mon Jul 27 12:52:36.705975 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.238.82:12704] [client 162.158.238.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.yaml"] [unique_id "amc4dOcsEMuHmMYmk67X5QAAAEw"]
[Mon Jul 27 12:52:46.140874 2026] [:error] [pid 12275:tid 140707012536064] [client 162.158.238.83:13496] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amc4fnFwI8r7BFXGkAveYQAAAAI"]
[Mon Jul 27 12:52:46.141857 2026] [:error] [pid 12275:tid 140707012536064] [client 162.158.238.83:13496] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amc4fnFwI8r7BFXGkAveYQAAAAI"]
[Mon Jul 27 12:52:46.142382 2026] [:error] [pid 12275:tid 140707012536064] [client 162.158.238.83:13496] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amc4fnFwI8r7BFXGkAveYQAAAAI"]
[Mon Jul 27 12:52:46.142418 2026] [:error] [pid 12275:tid 140707012536064] [client 162.158.238.83:13496] [client 162.158.238.83] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amc4fnFwI8r7BFXGkAveYQAAAAI"]
[Mon Jul 27 12:52:57.728344 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.238.83:11004] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amc4iXFwI8r7BFXGkAveowAAABU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:57.729380 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.238.83:11004] [client 162.158.238.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amc4iXFwI8r7BFXGkAveowAAABU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 12:52:57.730127 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.238.83:11004] [client 162.158.238.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.continue/config.json"] [unique_id "amc4iXFwI8r7BFXGkAveowAAABU"], referer: https://www.google.com/search?q=www.sbf-consultancy.com
[Mon Jul 27 13:27:11.745232 2026] [:error] [pid 10035:tid 140707020928768] [client 104.23.243.18:11507] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amdAj7M5Xj3nsMbGSqt23AAAAcE"]
[Mon Jul 27 13:27:11.746055 2026] [:error] [pid 10035:tid 140707020928768] [client 104.23.243.18:11507] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amdAj7M5Xj3nsMbGSqt23AAAAcE"]
[Mon Jul 27 13:27:11.746484 2026] [:error] [pid 10035:tid 140707020928768] [client 104.23.243.18:11507] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amdAj7M5Xj3nsMbGSqt23AAAAcE"]
[Mon Jul 27 13:43:55.471494 2026] [:error] [pid 12380:tid 140707004143360] [client 172.71.110.30:10876] [client 172.71.110.30] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdEe6aChfbWW0CZ_hrbmgAAAMM"]
[Mon Jul 27 13:43:55.475671 2026] [:error] [pid 12380:tid 140707004143360] [client 172.71.110.30:10876] [client 172.71.110.30] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdEe6aChfbWW0CZ_hrbmgAAAMM"]
[Mon Jul 27 13:43:55.476288 2026] [:error] [pid 12380:tid 140707004143360] [client 172.71.110.30:10876] [client 172.71.110.30] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdEe6aChfbWW0CZ_hrbmgAAAMM"]
[Mon Jul 27 13:59:40.084957 2026] [:error] [pid 12275:tid 140706953787136] [client 172.64.192.181:10503] [client 172.64.192.181] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amdILHFwI8r7BFXGkAsyPQAAAAk"]
[Mon Jul 27 13:59:40.085683 2026] [:error] [pid 12275:tid 140706953787136] [client 172.64.192.181:10503] [client 172.64.192.181] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amdILHFwI8r7BFXGkAsyPQAAAAk"]
[Mon Jul 27 13:59:40.086097 2026] [:error] [pid 12275:tid 140706953787136] [client 172.64.192.181:10503] [client 172.64.192.181] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amdILHFwI8r7BFXGkAsyPQAAAAk"]
[Mon Jul 27 14:19:49.341336 2026] [:error] [pid 21545:tid 140706937001728] [client 172.70.240.103:10398] [client 172.70.240.103] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdM5ZhXfYDIcpslIWM1ewAAAYs"]
[Mon Jul 27 14:19:49.342084 2026] [:error] [pid 21545:tid 140706937001728] [client 172.70.240.103:10398] [client 172.70.240.103] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdM5ZhXfYDIcpslIWM1ewAAAYs"]
[Mon Jul 27 14:19:49.342411 2026] [:error] [pid 21545:tid 140706937001728] [client 172.70.240.103:10398] [client 172.70.240.103] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdM5ZhXfYDIcpslIWM1ewAAAYs"]
[Mon Jul 27 14:21:29.281812 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.103.41:11698] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amdNSZhXfYDIcpslIWM4zQAAAYs"]
[Mon Jul 27 14:21:29.282950 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.103.41:11698] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amdNSZhXfYDIcpslIWM4zQAAAYs"]
[Mon Jul 27 14:21:29.283669 2026] [:error] [pid 21545:tid 140706937001728] [client 172.71.103.41:11698] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amdNSZhXfYDIcpslIWM4zQAAAYs"]
[Mon Jul 27 14:39:34.005495 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.243.18:12805] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amdRhphXfYDIcpslIWNfYAAAAYE"]
[Mon Jul 27 14:39:34.011589 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.243.18:12805] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amdRhphXfYDIcpslIWNfYAAAAYE"]
[Mon Jul 27 14:39:34.012035 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.243.18:12805] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amdRhphXfYDIcpslIWNfYAAAAYE"]
[Mon Jul 27 14:39:34.520645 2026] [:error] [pid 24106:tid 140706895038208] [client 104.23.197.76:9648] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amdRhjs8oMu6f6EYbxQgVAAAAVA"]
[Mon Jul 27 14:39:34.521616 2026] [:error] [pid 24106:tid 140706895038208] [client 104.23.197.76:9648] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amdRhjs8oMu6f6EYbxQgVAAAAVA"]
[Mon Jul 27 14:39:34.522144 2026] [:error] [pid 24106:tid 140706895038208] [client 104.23.197.76:9648] [client 104.23.197.76] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amdRhjs8oMu6f6EYbxQgVAAAAVA"]
[Mon Jul 27 15:12:55.281479 2026] [:error] [pid 12277:tid 140706978965248] [client 172.69.130.115:12186] [client 172.69.130.115] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdZVxwjcb8HQE21kA7wqwAAAIY"]
[Mon Jul 27 15:12:55.282350 2026] [:error] [pid 12277:tid 140706978965248] [client 172.69.130.115:12186] [client 172.69.130.115] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdZVxwjcb8HQE21kA7wqwAAAIY"]
[Mon Jul 27 15:12:55.282895 2026] [:error] [pid 12277:tid 140706978965248] [client 172.69.130.115:12186] [client 172.69.130.115] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdZVxwjcb8HQE21kA7wqwAAAIY"]
[Mon Jul 27 15:40:31.517213 2026] [:error] [pid 12277:tid 140706836289280] [client 104.23.213.108:10447] [client 104.23.213.108] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdfzxwjcb8HQE21kA78XQAAAJc"]
[Mon Jul 27 15:40:31.522001 2026] [:error] [pid 12277:tid 140706836289280] [client 104.23.213.108:10447] [client 104.23.213.108] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdfzxwjcb8HQE21kA78XQAAAJc"]
[Mon Jul 27 15:40:31.522459 2026] [:error] [pid 12277:tid 140706836289280] [client 104.23.213.108:10447] [client 104.23.213.108] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdfzxwjcb8HQE21kA78XQAAAJc"]
[Mon Jul 27 15:41:29.475394 2026] [:error] [pid 21545:tid 140706970572544] [client 104.22.100.89:14148] [client 104.22.100.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdgCZhXfYDIcpslIWPEKAAAAYc"]
[Mon Jul 27 15:41:29.476265 2026] [:error] [pid 21545:tid 140706970572544] [client 104.22.100.89:14148] [client 104.22.100.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdgCZhXfYDIcpslIWPEKAAAAYc"]
[Mon Jul 27 15:41:29.476911 2026] [:error] [pid 21545:tid 140706970572544] [client 104.22.100.89:14148] [client 104.22.100.89] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua=\\x22Not)A;Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22138\\x22, \\x22HeadlessChrome\\x22;v=\\x22138\\x22"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdgCZhXfYDIcpslIWPEKAAAAYc"]
[Mon Jul 27 15:41:29.476977 2026] [:error] [pid 21545:tid 140706970572544] [client 104.22.100.89:14148] [client 104.22.100.89] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdgCZhXfYDIcpslIWPEKAAAAYc"]
[Mon Jul 27 15:41:29.477027 2026] [:error] [pid 21545:tid 140706970572544] [client 104.22.100.89:14148] [client 104.22.100.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdgCZhXfYDIcpslIWPEKAAAAYc"]
[Mon Jul 27 15:45:19.916010 2026] [:error] [pid 21545:tid 140706962179840] [client 172.70.248.40:11266] [client 172.70.248.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amdg75hXfYDIcpslIWPJ3wAAAYg"]
[Mon Jul 27 15:45:19.916834 2026] [:error] [pid 21545:tid 140706962179840] [client 172.70.248.40:11266] [client 172.70.248.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amdg75hXfYDIcpslIWPJ3wAAAYg"]
[Mon Jul 27 15:45:19.917299 2026] [:error] [pid 21545:tid 140706962179840] [client 172.70.248.40:11266] [client 172.70.248.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amdg75hXfYDIcpslIWPJ3wAAAYg"]
[Mon Jul 27 15:52:44.546917 2026] [:error] [pid 21545:tid 140706903430912] [client 104.22.93.88:12378] [client 104.22.93.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdirJhXfYDIcpslIWPV8gAAAY8"]
[Mon Jul 27 15:52:44.547823 2026] [:error] [pid 21545:tid 140706903430912] [client 104.22.93.88:12378] [client 104.22.93.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdirJhXfYDIcpslIWPV8gAAAY8"]
[Mon Jul 27 15:52:44.548295 2026] [:error] [pid 21545:tid 140706903430912] [client 104.22.93.88:12378] [client 104.22.93.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdirJhXfYDIcpslIWPV8gAAAY8"]
[Mon Jul 27 15:53:42.934617 2026] [:error] [pid 12277:tid 140706987357952] [client 104.23.209.98:10485] [client 104.23.209.98] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdi5hwjcb8HQE21kA4BUgAAAIU"]
[Mon Jul 27 15:53:42.935064 2026] [:error] [pid 12277:tid 140706987357952] [client 104.23.209.98:10485] [client 104.23.209.98] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdi5hwjcb8HQE21kA4BUgAAAIU"]
[Mon Jul 27 15:53:42.935478 2026] [:error] [pid 12277:tid 140706987357952] [client 104.23.209.98:10485] [client 104.23.209.98] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua=\\x22Not)A;Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22138\\x22, \\x22HeadlessChrome\\x22;v=\\x22138\\x22"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdi5hwjcb8HQE21kA4BUgAAAIU"]
[Mon Jul 27 15:53:42.935576 2026] [:error] [pid 12277:tid 140706987357952] [client 104.23.209.98:10485] [client 104.23.209.98] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdi5hwjcb8HQE21kA4BUgAAAIU"]
[Mon Jul 27 15:53:42.935634 2026] [:error] [pid 12277:tid 140706987357952] [client 104.23.209.98:10485] [client 104.23.209.98] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdi5hwjcb8HQE21kA4BUgAAAIU"]
[Mon Jul 27 15:55:39.847090 2026] [:error] [pid 17228:tid 140706853074688] [client 104.23.243.19:9746] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amdjW5jBQLO4t9VCDfqgTwAAARU"]
[Mon Jul 27 15:55:39.847903 2026] [:error] [pid 17228:tid 140706853074688] [client 104.23.243.19:9746] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amdjW5jBQLO4t9VCDfqgTwAAARU"]
[Mon Jul 27 15:55:39.848391 2026] [:error] [pid 17228:tid 140706853074688] [client 104.23.243.19:9746] [client 104.23.243.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amdjW5jBQLO4t9VCDfqgTwAAARU"]
[Mon Jul 27 15:55:40.279245 2026] [:error] [pid 17228:tid 140706978965248] [client 104.23.243.181:13579] [client 104.23.243.181] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amdjXJjBQLO4t9VCDfqgUQAAAQY"]
[Mon Jul 27 15:55:40.280120 2026] [:error] [pid 17228:tid 140706978965248] [client 104.23.243.181:13579] [client 104.23.243.181] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amdjXJjBQLO4t9VCDfqgUQAAAQY"]
[Mon Jul 27 15:55:40.280722 2026] [:error] [pid 17228:tid 140706978965248] [client 104.23.243.181:13579] [client 104.23.243.181] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amdjXJjBQLO4t9VCDfqgUQAAAQY"]
[Mon Jul 27 16:12:59.072073 2026] [:error] [pid 21545:tid 140707012536064] [client 172.68.55.165:12021] [client 172.68.55.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdna5hXfYDIcpslIWP0aQAAAYI"]
[Mon Jul 27 16:12:59.073055 2026] [:error] [pid 21545:tid 140707012536064] [client 172.68.55.165:12021] [client 172.68.55.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdna5hXfYDIcpslIWP0aQAAAYI"]
[Mon Jul 27 16:12:59.073593 2026] [:error] [pid 21545:tid 140707012536064] [client 172.68.55.165:12021] [client 172.68.55.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdna5hXfYDIcpslIWP0aQAAAYI"]
[Mon Jul 27 16:42:38.509387 2026] [:error] [pid 23693:tid 140706895038208] [client 104.23.223.54:12242] [client 104.23.223.54] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amduXjECtsZH8ymO6R0qeAAAAhA"]
[Mon Jul 27 16:42:38.531896 2026] [:error] [pid 23693:tid 140706895038208] [client 104.23.223.54:12242] [client 104.23.223.54] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amduXjECtsZH8ymO6R0qeAAAAhA"]
[Mon Jul 27 16:42:38.532367 2026] [:error] [pid 23693:tid 140706895038208] [client 104.23.223.54:12242] [client 104.23.223.54] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amduXjECtsZH8ymO6R0qeAAAAhA"]
[Mon Jul 27 16:57:31.826034 2026] [:error] [pid 12380:tid 140706861467392] [client 162.158.79.90:12105] [client 162.158.79.90] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdx26aChfbWW0CZ_hqzngAAANQ"]
[Mon Jul 27 16:57:31.826942 2026] [:error] [pid 12380:tid 140706861467392] [client 162.158.79.90:12105] [client 162.158.79.90] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdx26aChfbWW0CZ_hqzngAAANQ"]
[Mon Jul 27 16:57:31.827421 2026] [:error] [pid 12380:tid 140706861467392] [client 162.158.79.90:12105] [client 162.158.79.90] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdx26aChfbWW0CZ_hqzngAAANQ"]
[Mon Jul 27 16:57:32.028685 2026] [:error] [pid 24106:tid 140706827896576] [client 172.70.134.218:12946] [client 172.70.134.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdx3Ds8oMu6f6EYbxRRBAAAAVg"]
[Mon Jul 27 16:57:32.029516 2026] [:error] [pid 24106:tid 140706827896576] [client 172.70.134.218:12946] [client 172.70.134.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdx3Ds8oMu6f6EYbxRRBAAAAVg"]
[Mon Jul 27 16:57:32.030031 2026] [:error] [pid 24106:tid 140706827896576] [client 172.70.134.218:12946] [client 172.70.134.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdx3Ds8oMu6f6EYbxRRBAAAAVg"]
[Mon Jul 27 16:59:19.711314 2026] [:error] [pid 23952:tid 140707004143360] [client 198.41.227.73:13179] [client 198.41.227.73] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdyRy8h5OE555JiBB9zXQAAAkM"]
[Mon Jul 27 16:59:19.711884 2026] [:error] [pid 23952:tid 140707004143360] [client 198.41.227.73:13179] [client 198.41.227.73] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdyRy8h5OE555JiBB9zXQAAAkM"]
[Mon Jul 27 16:59:19.712323 2026] [:error] [pid 23952:tid 140707004143360] [client 198.41.227.73:13179] [client 198.41.227.73] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdyRy8h5OE555JiBB9zXQAAAkM"]
[Mon Jul 27 16:59:19.712353 2026] [:error] [pid 23952:tid 140707004143360] [client 198.41.227.73:13179] [client 198.41.227.73] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amdyRy8h5OE555JiBB9zXQAAAkM"]
[Mon Jul 27 17:23:21.741545 2026] [:error] [pid 17228:tid 140707004143360] [client 172.69.134.203:14217] [client 172.69.134.203] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amd36ZjBQLO4t9VCDfq3OwAAAQM"]
[Mon Jul 27 17:23:21.742576 2026] [:error] [pid 17228:tid 140707004143360] [client 172.69.134.203:14217] [client 172.69.134.203] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amd36ZjBQLO4t9VCDfq3OwAAAQM"]
[Mon Jul 27 17:23:21.743208 2026] [:error] [pid 17228:tid 140707004143360] [client 172.69.134.203:14217] [client 172.69.134.203] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amd36ZjBQLO4t9VCDfq3OwAAAQM"]
[Mon Jul 27 17:35:30.219844 2026] [:error] [pid 12277:tid 140706978965248] [client 172.69.195.220:12027] [client 172.69.195.220] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amd6whwjcb8HQE21kA4wpwAAAIY"]
[Mon Jul 27 17:35:30.225843 2026] [:error] [pid 12277:tid 140706978965248] [client 172.69.195.220:12027] [client 172.69.195.220] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amd6whwjcb8HQE21kA4wpwAAAIY"]
[Mon Jul 27 17:35:30.226546 2026] [:error] [pid 12277:tid 140706978965248] [client 172.69.195.220:12027] [client 172.69.195.220] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amd6whwjcb8HQE21kA4wpwAAAIY"]
[Mon Jul 27 17:59:12.227638 2026] [:error] [pid 21545:tid 140706861467392] [client 104.23.243.18:13455] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ameAUJhXfYDIcpslIWOFGgAAAZQ"]
[Mon Jul 27 17:59:12.228446 2026] [:error] [pid 21545:tid 140706861467392] [client 104.23.243.18:13455] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ameAUJhXfYDIcpslIWOFGgAAAZQ"]
[Mon Jul 27 17:59:12.228982 2026] [:error] [pid 21545:tid 140706861467392] [client 104.23.243.18:13455] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ameAUJhXfYDIcpslIWOFGgAAAZQ"]
[Mon Jul 27 17:59:12.677407 2026] [:error] [pid 12275:tid 140706861467392] [client 104.23.197.76:10461] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ameAUHFwI8r7BFXGkAvLeQAAABQ"]
[Mon Jul 27 17:59:12.678243 2026] [:error] [pid 12275:tid 140706861467392] [client 104.23.197.76:10461] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ameAUHFwI8r7BFXGkAvLeQAAABQ"]
[Mon Jul 27 17:59:12.678772 2026] [:error] [pid 12275:tid 140706861467392] [client 104.23.197.76:10461] [client 104.23.197.76] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ameAUHFwI8r7BFXGkAvLeQAAABQ"]
[Mon Jul 27 18:07:05.127875 2026] [:error] [pid 17228:tid 140706886645504] [client 162.158.106.184:11639] [client 162.158.106.184] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ameCKZjBQLO4t9VCDfrBggAAARE"]
[Mon Jul 27 18:07:05.128727 2026] [:error] [pid 17228:tid 140706886645504] [client 162.158.106.184:11639] [client 162.158.106.184] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ameCKZjBQLO4t9VCDfrBggAAARE"]
[Mon Jul 27 18:07:05.129168 2026] [:error] [pid 17228:tid 140706886645504] [client 162.158.106.184:11639] [client 162.158.106.184] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ameCKZjBQLO4t9VCDfrBggAAARE"]
[Mon Jul 27 18:10:47.471630 2026] [:error] [pid 21545:tid 140706903430912] [client 162.158.41.231:13845] [client 162.158.41.231] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ameDB5hXfYDIcpslIWOScAAAAY8"]
[Mon Jul 27 18:10:47.472441 2026] [:error] [pid 21545:tid 140706903430912] [client 162.158.41.231:13845] [client 162.158.41.231] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ameDB5hXfYDIcpslIWOScAAAAY8"]
[Mon Jul 27 18:10:47.472883 2026] [:error] [pid 21545:tid 140706903430912] [client 162.158.41.231:13845] [client 162.158.41.231] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ameDB5hXfYDIcpslIWOScAAAAY8"]
[Mon Jul 27 18:10:47.473004 2026] [:error] [pid 21545:tid 140706903430912] [client 162.158.41.231:13845] [client 162.158.41.231] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ameDB5hXfYDIcpslIWOScAAAAY8"]
[Mon Jul 27 18:13:55.143713 2026] [:error] [pid 12277:tid 140706962179840] [client 172.71.103.41:13423] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ameDwxwjcb8HQE21kA4_eQAAAIg"]
[Mon Jul 27 18:13:55.144568 2026] [:error] [pid 12277:tid 140706962179840] [client 172.71.103.41:13423] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ameDwxwjcb8HQE21kA4_eQAAAIg"]
[Mon Jul 27 18:13:55.145088 2026] [:error] [pid 12277:tid 140706962179840] [client 172.71.103.41:13423] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ameDwxwjcb8HQE21kA4_eQAAAIg"]
[Mon Jul 27 18:19:57.163619 2026] [:error] [pid 23952:tid 140706895038208] [client 104.22.24.170:12944] [client 104.22.24.170] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ameFLS8h5OE555JiBB9-7AAAAlA"]
[Mon Jul 27 18:19:57.164408 2026] [:error] [pid 23952:tid 140706895038208] [client 104.22.24.170:12944] [client 104.22.24.170] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ameFLS8h5OE555JiBB9-7AAAAlA"]
[Mon Jul 27 18:19:57.164973 2026] [:error] [pid 23952:tid 140706895038208] [client 104.22.24.170:12944] [client 104.22.24.170] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:from outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:from=oai-searchbot(at)openai.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ameFLS8h5OE555JiBB9-7AAAAlA"]
[Mon Jul 27 18:19:57.165028 2026] [:error] [pid 23952:tid 140706895038208] [client 104.22.24.170:12944] [client 104.22.24.170] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ameFLS8h5OE555JiBB9-7AAAAlA"]
[Mon Jul 27 18:48:19.175272 2026] [:error] [pid 21545:tid 140707012536064] [client 162.158.41.51:13166] [client 162.158.41.51] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ameL05hXfYDIcpslIWPZcAAAAYI"]
[Mon Jul 27 18:48:19.179645 2026] [:error] [pid 21545:tid 140707012536064] [client 162.158.41.51:13166] [client 162.158.41.51] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ameL05hXfYDIcpslIWPZcAAAAYI"]
[Mon Jul 27 18:48:19.180060 2026] [:error] [pid 21545:tid 140707012536064] [client 162.158.41.51:13166] [client 162.158.41.51] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ameL05hXfYDIcpslIWPZcAAAAYI"]
[Mon Jul 27 18:48:19.180205 2026] [:error] [pid 21545:tid 140707012536064] [client 162.158.41.51:13166] [client 162.158.41.51] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ameL05hXfYDIcpslIWPZcAAAAYI"]
[Mon Jul 27 19:17:41.095714 2026] [:error] [pid 24106:tid 140706962179840] [client 104.23.243.19:10203] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ameStTs8oMu6f6EYbxSCuwAAAUg"]
[Mon Jul 27 19:17:41.096347 2026] [:error] [pid 24106:tid 140706962179840] [client 104.23.243.19:10203] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ameStTs8oMu6f6EYbxSCuwAAAUg"]
[Mon Jul 27 19:17:41.096655 2026] [:error] [pid 24106:tid 140706962179840] [client 104.23.243.19:10203] [client 104.23.243.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ameStTs8oMu6f6EYbxSCuwAAAUg"]
[Mon Jul 27 19:17:41.534854 2026] [:error] [pid 21545:tid 140707103270656] [client 104.23.197.76:10436] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ameStZhXfYDIcpslIWMOmwAAAYA"]
[Mon Jul 27 19:17:41.535656 2026] [:error] [pid 21545:tid 140707103270656] [client 104.23.197.76:10436] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ameStZhXfYDIcpslIWMOmwAAAYA"]
[Mon Jul 27 19:17:41.535997 2026] [:error] [pid 21545:tid 140707103270656] [client 104.23.197.76:10436] [client 104.23.197.76] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ameStZhXfYDIcpslIWMOmwAAAYA"]
[Mon Jul 27 19:18:45.584316 2026] [:error] [pid 12380:tid 140706853074688] [client 104.23.223.55:10812] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ameS9aaChfbWW0CZ_hpESQAAANU"]
[Mon Jul 27 19:18:45.585596 2026] [:error] [pid 12380:tid 140706853074688] [client 104.23.223.55:10812] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ameS9aaChfbWW0CZ_hpESQAAANU"]
[Mon Jul 27 19:18:45.586282 2026] [:error] [pid 12380:tid 140706853074688] [client 104.23.223.55:10812] [client 104.23.223.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ameS9aaChfbWW0CZ_hpESQAAANU"]
[Mon Jul 27 20:06:22.267711 2026] [:error] [pid 21545:tid 140706853074688] [client 172.71.215.160:10412] [client 172.71.215.160] ModSecurity: Warning. Match of "rx ^%{tx.allowed_request_content_type_charset}$" against "TX:1" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "983"] [id "920480"] [msg "Request content type charset is not allowed by policy"] [data "utf-8"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "ameeHphXfYDIcpslIWNmlwAAAZU"]
[Mon Jul 27 20:06:22.268800 2026] [:error] [pid 21545:tid 140706853074688] [client 172.71.215.160:10412] [client 172.71.215.160] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "ameeHphXfYDIcpslIWNmlwAAAZU"]
[Mon Jul 27 20:06:22.272822 2026] [:error] [pid 21545:tid 140706853074688] [client 172.71.215.160:10412] [client 172.71.215.160] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "ameeHphXfYDIcpslIWNmlwAAAZU"]
[Mon Jul 27 20:06:22.273389 2026] [:error] [pid 21545:tid 140706853074688] [client 172.71.215.160:10412] [client 172.71.215.160] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|text/xml|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "ameeHphXfYDIcpslIWNmlwAAAZU"]
[Mon Jul 27 20:06:22.273979 2026] [:error] [pid 21545:tid 140706853074688] [client 172.71.215.160:10412] [client 172.71.215.160] ModSecurity: Warning. Found 177 byte(s) in REQUEST_BODY outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "REQUEST_BODY=<?xml version=\\x221.0\\x22?><methodCall><methodName>metaWeblog.newPost</methodName><params><param><value><string>1</string></value></param><param><value><string>85163</string></value></param><param><value><string>85163</string></value></param><param><value><struct><member><name>title</name><value><string>0xe9a8c36d</string></value></member><member><name>description</name><value><string>0xe9a8c36d</string></value></member><member><name>mt_keywords</name><value><string>0xe9a8c36d</string></valu..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "ameeHphXfYDIcpslIWNmlwAAAZU"]
[Mon Jul 27 20:06:22.274099 2026] [:error] [pid 21545:tid 140706853074688] [client 172.71.215.160:10412] [client 172.71.215.160] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xmlrpc.php"] [unique_id "ameeHphXfYDIcpslIWNmlwAAAZU"]
[Mon Jul 27 20:40:56.051783 2026] [:error] [pid 21545:tid 140706945394432] [client 104.23.243.19:12737] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amemOJhXfYDIcpslIWOc-wAAAYo"]
[Mon Jul 27 20:40:56.056193 2026] [:error] [pid 21545:tid 140706945394432] [client 104.23.243.19:12737] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amemOJhXfYDIcpslIWOc-wAAAYo"]
[Mon Jul 27 20:40:56.056621 2026] [:error] [pid 21545:tid 140706945394432] [client 104.23.243.19:12737] [client 104.23.243.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amemOJhXfYDIcpslIWOc-wAAAYo"]
[Mon Jul 27 20:53:56.524695 2026] [:error] [pid 12380:tid 140706836289280] [client 172.68.12.98:13882] [client 172.68.12.98] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amepRKaChfbWW0CZ_hrR-AAAANc"]
[Mon Jul 27 20:53:56.525620 2026] [:error] [pid 12380:tid 140706836289280] [client 172.68.12.98:13882] [client 172.68.12.98] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amepRKaChfbWW0CZ_hrR-AAAANc"]
[Mon Jul 27 20:53:56.526153 2026] [:error] [pid 12380:tid 140706836289280] [client 172.68.12.98:13882] [client 172.68.12.98] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amepRKaChfbWW0CZ_hrR-AAAANc"]
[Mon Jul 27 20:53:56.831994 2026] [:error] [pid 12380:tid 140706962179840] [client 172.71.156.213:11801] [client 172.71.156.213] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amepRKaChfbWW0CZ_hrR-wAAAMg"]
[Mon Jul 27 20:53:56.833165 2026] [:error] [pid 12380:tid 140706962179840] [client 172.71.156.213:11801] [client 172.71.156.213] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amepRKaChfbWW0CZ_hrR-wAAAMg"]
[Mon Jul 27 20:53:56.833758 2026] [:error] [pid 12380:tid 140706962179840] [client 172.71.156.213:11801] [client 172.71.156.213] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amepRKaChfbWW0CZ_hrR-wAAAMg"]
[Mon Jul 27 20:53:58.720788 2026] [:error] [pid 12277:tid 140706861467392] [client 172.70.255.52:12719] [client 172.70.255.52] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amepRhwjcb8HQE21kA6K0wAAAJQ"]
[Mon Jul 27 20:53:58.721612 2026] [:error] [pid 12277:tid 140706861467392] [client 172.70.255.52:12719] [client 172.70.255.52] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amepRhwjcb8HQE21kA6K0wAAAJQ"]
[Mon Jul 27 20:53:58.722248 2026] [:error] [pid 12277:tid 140706861467392] [client 172.70.255.52:12719] [client 172.70.255.52] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amepRhwjcb8HQE21kA6K0wAAAJQ"]
[Mon Jul 27 20:54:00.124582 2026] [:error] [pid 12380:tid 140706878252800] [client 104.22.86.80:12082] [client 104.22.86.80] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amepSKaChfbWW0CZ_hrSDwAAANI"]
[Mon Jul 27 20:54:00.125638 2026] [:error] [pid 12380:tid 140706878252800] [client 104.22.86.80:12082] [client 104.22.86.80] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amepSKaChfbWW0CZ_hrSDwAAANI"]
[Mon Jul 27 20:54:00.126123 2026] [:error] [pid 12380:tid 140706878252800] [client 104.22.86.80:12082] [client 104.22.86.80] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amepSKaChfbWW0CZ_hrSDwAAANI"]
[Mon Jul 27 20:54:00.956327 2026] [:error] [pid 10035:tid 140706886645504] [client 104.23.248.134:11486] [client 104.23.248.134] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/assets/index-o-9Bhaif.js"] [unique_id "amepSLM5Xj3nsMbGSqvAYgAAAdE"]
[Mon Jul 27 20:54:00.957049 2026] [:error] [pid 10035:tid 140706886645504] [client 104.23.248.134:11486] [client 104.23.248.134] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/assets/index-o-9Bhaif.js"] [unique_id "amepSLM5Xj3nsMbGSqvAYgAAAdE"]
[Mon Jul 27 20:54:00.957505 2026] [:error] [pid 10035:tid 140706886645504] [client 104.23.248.134:11486] [client 104.23.248.134] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/assets/index-o-9Bhaif.js"] [unique_id "amepSLM5Xj3nsMbGSqvAYgAAAdE"]
[Mon Jul 27 20:54:12.353331 2026] [:error] [pid 21545:tid 140706970572544] [client 172.71.156.224:13402] [client 172.71.156.224] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_vercel/insights/script.js"] [unique_id "amepVJhXfYDIcpslIWOtDwAAAYc"]
[Mon Jul 27 20:54:12.354018 2026] [:error] [pid 21545:tid 140706970572544] [client 172.71.156.224:13402] [client 172.71.156.224] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_vercel/insights/script.js"] [unique_id "amepVJhXfYDIcpslIWOtDwAAAYc"]
[Mon Jul 27 20:54:12.354417 2026] [:error] [pid 21545:tid 140706970572544] [client 172.71.156.224:13402] [client 172.71.156.224] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_vercel/insights/script.js"] [unique_id "amepVJhXfYDIcpslIWOtDwAAAYc"]
[Mon Jul 27 21:11:33.379640 2026] [:error] [pid 17228:tid 140706853074688] [client 104.23.217.116:13389] [client 104.23.217.116] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ametZZjBQLO4t9VCDfrwsQAAARU"]
[Mon Jul 27 21:11:33.380647 2026] [:error] [pid 17228:tid 140706853074688] [client 104.23.217.116:13389] [client 104.23.217.116] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ametZZjBQLO4t9VCDfrwsQAAARU"]
[Mon Jul 27 21:11:33.381236 2026] [:error] [pid 17228:tid 140706853074688] [client 104.23.217.116:13389] [client 104.23.217.116] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ametZZjBQLO4t9VCDfrwsQAAARU"]
[Mon Jul 27 21:22:34.591830 2026] [:error] [pid 12380:tid 140707004143360] [client 172.70.194.138:10276] [client 172.70.194.138] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amev-qaChfbWW0CZ_hoBKAAAAMM"]
[Mon Jul 27 21:22:34.592928 2026] [:error] [pid 12380:tid 140707004143360] [client 172.70.194.138:10276] [client 172.70.194.138] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amev-qaChfbWW0CZ_hoBKAAAAMM"]
[Mon Jul 27 21:22:34.593516 2026] [:error] [pid 12380:tid 140707004143360] [client 172.70.194.138:10276] [client 172.70.194.138] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amev-qaChfbWW0CZ_hoBKAAAAMM"]
[Mon Jul 27 21:24:21.580312 2026] [:error] [pid 12277:tid 140706987357952] [client 104.22.24.57:11112] [client 104.22.24.57] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amewZRwjcb8HQE21kA6UmQAAAIU"]
[Mon Jul 27 21:24:21.581159 2026] [:error] [pid 12277:tid 140706987357952] [client 104.22.24.57:11112] [client 104.22.24.57] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amewZRwjcb8HQE21kA6UmQAAAIU"]
[Mon Jul 27 21:24:21.581687 2026] [:error] [pid 12277:tid 140706987357952] [client 104.22.24.57:11112] [client 104.22.24.57] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amewZRwjcb8HQE21kA6UmQAAAIU"]
[Mon Jul 27 21:24:21.581724 2026] [:error] [pid 12277:tid 140706987357952] [client 104.22.24.57:11112] [client 104.22.24.57] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amewZRwjcb8HQE21kA6UmQAAAIU"]
[Mon Jul 27 21:25:53.586271 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.217.56:11335] [client 162.158.217.56] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amewwRwjcb8HQE21kA6VWAAAAIw"]
[Mon Jul 27 21:25:53.587027 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.217.56:11335] [client 162.158.217.56] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amewwRwjcb8HQE21kA6VWAAAAIw"]
[Mon Jul 27 21:25:53.587363 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.217.56:11335] [client 162.158.217.56] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amewwRwjcb8HQE21kA6VWAAAAIw"]
[Mon Jul 27 21:41:10.871333 2026] [:error] [pid 17228:tid 140706895038208] [client 104.23.243.18:9464] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ame0VpjBQLO4t9VCDfr21gAAARA"]
[Mon Jul 27 21:41:10.908085 2026] [:error] [pid 17228:tid 140706895038208] [client 104.23.243.18:9464] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ame0VpjBQLO4t9VCDfr21gAAARA"]
[Mon Jul 27 21:41:10.908580 2026] [:error] [pid 17228:tid 140706895038208] [client 104.23.243.18:9464] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ame0VpjBQLO4t9VCDfr21gAAARA"]
[Mon Jul 27 21:45:33.255610 2026] [:error] [pid 23693:tid 140706895038208] [client 104.23.197.76:12915] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ame1XTECtsZH8ymO6R1HlwAAAhA"]
[Mon Jul 27 21:45:33.256624 2026] [:error] [pid 23693:tid 140706895038208] [client 104.23.197.76:12915] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ame1XTECtsZH8ymO6R1HlwAAAhA"]
[Mon Jul 27 21:45:33.257135 2026] [:error] [pid 23693:tid 140706895038208] [client 104.23.197.76:12915] [client 104.23.197.76] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ame1XTECtsZH8ymO6R1HlwAAAhA"]
[Mon Jul 27 22:56:08.542277 2026] [:error] [pid 12380:tid 140706970572544] [client 104.23.223.55:10752] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amfF6KaChfbWW0CZ_hqF6wAAAMc"]
[Mon Jul 27 22:56:08.547021 2026] [:error] [pid 12380:tid 140706970572544] [client 104.23.223.55:10752] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amfF6KaChfbWW0CZ_hqF6wAAAMc"]
[Mon Jul 27 22:56:08.547673 2026] [:error] [pid 12380:tid 140706970572544] [client 104.23.223.55:10752] [client 104.23.223.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amfF6KaChfbWW0CZ_hqF6wAAAMc"]
[Mon Jul 27 23:07:48.288712 2026] [:error] [pid 12380:tid 140706895038208] [client 172.68.211.16:11972] [client 172.68.211.16] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfIpKaChfbWW0CZ_hqXHgAAANA"]
[Mon Jul 27 23:07:48.290152 2026] [:error] [pid 12380:tid 140706895038208] [client 172.68.211.16:11972] [client 172.68.211.16] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfIpKaChfbWW0CZ_hqXHgAAANA"]
[Mon Jul 27 23:07:48.291210 2026] [:error] [pid 12380:tid 140706895038208] [client 172.68.211.16:11972] [client 172.68.211.16] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfIpKaChfbWW0CZ_hqXHgAAANA"]
[Mon Jul 27 23:35:36.841505 2026] [:error] [pid 12275:tid 140706928609024] [client 104.23.243.18:12617] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amfPKHFwI8r7BFXGkAunUQAAAAw"]
[Mon Jul 27 23:35:36.899291 2026] [:error] [pid 12275:tid 140706928609024] [client 104.23.243.18:12617] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amfPKHFwI8r7BFXGkAunUQAAAAw"]
[Mon Jul 27 23:35:36.899664 2026] [:error] [pid 12275:tid 140706928609024] [client 104.23.243.18:12617] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amfPKHFwI8r7BFXGkAunUQAAAAw"]
[Mon Jul 27 23:35:37.324566 2026] [:error] [pid 12277:tid 140706937001728] [client 104.23.197.77:13717] [client 104.23.197.77] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amfPKRwjcb8HQE21kA7JFQAAAIs"]
[Mon Jul 27 23:35:37.326180 2026] [:error] [pid 12277:tid 140706937001728] [client 104.23.197.77:13717] [client 104.23.197.77] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amfPKRwjcb8HQE21kA7JFQAAAIs"]
[Mon Jul 27 23:35:37.326693 2026] [:error] [pid 12277:tid 140706937001728] [client 104.23.197.77:13717] [client 104.23.197.77] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amfPKRwjcb8HQE21kA7JFQAAAIs"]
[Tue Jul 28 00:07:05.376233 2026] [:error] [pid 12380:tid 140707103270656] [client 172.71.214.192:9952] [client 172.71.214.192] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amfWiaaChfbWW0CZ_hrvkAAAAMA"]
[Tue Jul 28 00:07:05.377157 2026] [:error] [pid 12380:tid 140707103270656] [client 172.71.214.192:9952] [client 172.71.214.192] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amfWiaaChfbWW0CZ_hrvkAAAAMA"]
[Tue Jul 28 00:07:05.377740 2026] [:error] [pid 12380:tid 140707103270656] [client 172.71.214.192:9952] [client 172.71.214.192] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amfWiaaChfbWW0CZ_hrvkAAAAMA"]
[Tue Jul 28 00:13:59.516941 2026] [:error] [pid 12380:tid 140706844681984] [client 172.68.15.205:9810] [client 172.68.15.205] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amfYJ6aChfbWW0CZ_hoBdgAAANY"]
[Tue Jul 28 00:13:59.520511 2026] [:error] [pid 12380:tid 140706844681984] [client 172.68.15.205:9810] [client 172.68.15.205] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amfYJ6aChfbWW0CZ_hoBdgAAANY"]
[Tue Jul 28 00:13:59.521089 2026] [:error] [pid 12380:tid 140706844681984] [client 172.68.15.205:9810] [client 172.68.15.205] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amfYJ6aChfbWW0CZ_hoBdgAAANY"]
[Tue Jul 28 00:14:00.721044 2026] [:error] [pid 21545:tid 140706937001728] [client 172.70.38.128:13182] [client 172.70.38.128] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfYKJhXfYDIcpslIWOJrQAAAYs"]
[Tue Jul 28 00:14:00.721917 2026] [:error] [pid 21545:tid 140706937001728] [client 172.70.38.128:13182] [client 172.70.38.128] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfYKJhXfYDIcpslIWOJrQAAAYs"]
[Tue Jul 28 00:14:00.722396 2026] [:error] [pid 21545:tid 140706937001728] [client 172.70.38.128:13182] [client 172.70.38.128] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfYKJhXfYDIcpslIWOJrQAAAYs"]
[Tue Jul 28 00:25:15.484400 2026] [:error] [pid 21545:tid 140706962179840] [client 104.23.243.180:10932] [client 104.23.243.180] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amfay5hXfYDIcpslIWObkQAAAYg"]
[Tue Jul 28 00:25:15.485208 2026] [:error] [pid 21545:tid 140706962179840] [client 104.23.243.180:10932] [client 104.23.243.180] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amfay5hXfYDIcpslIWObkQAAAYg"]
[Tue Jul 28 00:25:15.485677 2026] [:error] [pid 21545:tid 140706962179840] [client 104.23.243.180:10932] [client 104.23.243.180] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amfay5hXfYDIcpslIWObkQAAAYg"]
[Tue Jul 28 00:34:35.633512 2026] [:error] [pid 12380:tid 140706878252800] [client 172.71.183.36:14071] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfc-6aChfbWW0CZ_hooLgAAANI"]
[Tue Jul 28 00:34:35.637493 2026] [:error] [pid 12380:tid 140706878252800] [client 172.71.183.36:14071] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfc-6aChfbWW0CZ_hooLgAAANI"]
[Tue Jul 28 00:34:35.638021 2026] [:error] [pid 12380:tid 140706878252800] [client 172.71.183.36:14071] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfc-6aChfbWW0CZ_hooLgAAANI"]
[Tue Jul 28 00:41:35.424699 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.183.12:12267] [client 162.158.183.12] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amfenxwjcb8HQE21kA7mHQAAAII"]
[Tue Jul 28 00:41:35.425639 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.183.12:12267] [client 162.158.183.12] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amfenxwjcb8HQE21kA7mHQAAAII"]
[Tue Jul 28 00:41:35.426238 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.183.12:12267] [client 162.158.183.12] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amfenxwjcb8HQE21kA7mHQAAAII"]
[Tue Jul 28 01:37:16.224759 2026] [:error] [pid 24106:tid 140706869860096] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfrrDs8oMu6f6EYbxTbUQAAAVM"]
[Tue Jul 28 01:37:16.248514 2026] [:error] [pid 24106:tid 140706869860096] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfrrDs8oMu6f6EYbxTbUQAAAVM"]
[Tue Jul 28 01:37:16.248983 2026] [:error] [pid 24106:tid 140706869860096] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfrrDs8oMu6f6EYbxTbUQAAAVM"]
[Tue Jul 28 01:37:16.249090 2026] [:error] [pid 24106:tid 140706869860096] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfrrDs8oMu6f6EYbxTbUQAAAVM"]
[Tue Jul 28 01:37:21.086871 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.087759 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.088301 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/index/think\\x5capp/invokeMethod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.088349 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Found 3 byte(s) in ARGS:method[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:method[0]=think\\x5cview\\x5cdriver\\x5cPhp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.088411 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Found 9 byte(s) in ARGS:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:vars[0]=<?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.088513 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:method[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:method[0]=method[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.088603 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:method[1] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:method[1]=method[1]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.088692 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.088793 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.088920 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Pattern match "(?:^|[^\\\\\\\\])\\\\\\\\[cdeghijklmpqwxyz123456789]" at REQUEST_URI. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1593"] [id "920460"] [msg "Abnormal character escapes in request"] [data "Matched Data: w\\x5cd found within REQUEST_URI: /index.php?s=/index/think\\x5capp/invokemethod&method[0]=think\\x5cview\\x5cdriver\\x5cphp&method[1]=display&vars[0]=<?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/4"] [tag "OWASP_CRS"] [tag "capec/1000/153/267"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.089091 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Pattern match "(?:^|[^\\\\\\\\])\\\\\\\\[cdeghijklmpqwxyz123456789]" at ARGS:method[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1593"] [id "920460"] [msg "Abnormal character escapes in request"] [data "Matched Data: w\\x5cd found within ARGS:method[0]: think\\x5cview\\x5cdriver\\x5cphp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/4"] [tag "OWASP_CRS"] [tag "capec/1000/153/267"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.089895 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Pattern match "(?:<\\\\?(?:[^x]|x[^m]|xm[^l]|xml[^\\\\s]|xml$|$)|<\\\\?php|\\\\[(?:\\\\/|\\\\\\\\)?php\\\\])" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "65"] [id "933100"] [msg "PHP Injection Attack: PHP Open Tag Found"] [data "Matched Data: <?p found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.091622 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Pattern match "(?i)\\\\b(?:c(?:o(?:n(?:v(?:ert(?:_tz)?)?|cat(?:_ws)?|nection_id)|(?:mpres)?s|ercibility|(?:un)?t|llation|alesce)|ur(?:rent_(?:time(?:stamp)?|date|user)|(?:dat|tim)e)|h(?:ar(?:(?:acter)?_length|set)?|r)|iel(?:ing)?|ast|r32)|s(?:u(?:b(?:str(?:ing(?:_index ..." at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "628"] [id "942150"] [msg "SQL Injection Attack"] [data "Matched Data: md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.092284 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Pattern match "(?i:\\\\b(?:c(?:o(?:n(?:v(?:ert(?:_tz)?)?|cat(?:_ws)?|nection_id)|(?:mpres)?s|ercibility|(?:un)?t|alesce)|ur(?:rent_(?:time(?:stamp)?|date|user)|(?:dat|tim)e)|h(?:ar(?:(?:acter)?_length|set)?|r)|iel(?:ing)?|ast|r32)|s(?:t(?:d(?:dev(?:_(?:sam|po)p)?)?|r(? ..." at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1056"] [id "942410"] [msg "SQL Injection Attack"] [data "Matched Data: md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.092587 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){6})" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1413"] [id "942431"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6)"] [data "Matched Data: <?php echo md5('a3233a3800f8cba9dd419d1997d27412'); found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.092734 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Pattern match "(?:'((?:[\\\\w\\\\s=_\\\\-+{}()<@]){2,29}|(?:[A-Za-z0-9+\\\\/]{4})+(?:[A-Za-z0-9+\\\\/]{2}==|[A-Za-z0-9+\\\\/]{3}=)?)')" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1527"] [id "942511"] [msg "SQLi bypass attempt by ticks detected"] [data "Matched Data: 'a3233a3800f8cba9dd419d1997d27412' found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.092825 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:method[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:method[0]: method[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.092918 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:method[1]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:method[1]: method[1]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.093044 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:21.093161 2026] [:error] [pid 24106:tid 140706928609024] [client 104.23.199.88:9479] [client 104.23.199.88] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: <?php echo md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsTs8oMu6f6EYbxTbUgAAAUw"]
[Tue Jul 28 01:37:22.015453 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.016209 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.016633 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/admin/think\\x5capp/invokeMethod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.016695 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Found 3 byte(s) in ARGS:method[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:method[0]=think\\x5cview\\x5cdriver\\x5cPhp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.016761 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Found 9 byte(s) in ARGS:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:vars[0]=<?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.016854 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:method[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:method[0]=method[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.016914 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:method[1] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:method[1]=method[1]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.016963 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.017023 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.017120 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Pattern match "(?:^|[^\\\\\\\\])\\\\\\\\[cdeghijklmpqwxyz123456789]" at REQUEST_URI. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1593"] [id "920460"] [msg "Abnormal character escapes in request"] [data "Matched Data: w\\x5cd found within REQUEST_URI: /index.php?s=/admin/think\\x5capp/invokemethod&method[0]=think\\x5cview\\x5cdriver\\x5cphp&method[1]=display&vars[0]=<?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/4"] [tag "OWASP_CRS"] [tag "capec/1000/153/267"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.017212 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Pattern match "(?:^|[^\\\\\\\\])\\\\\\\\[cdeghijklmpqwxyz123456789]" at ARGS:method[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1593"] [id "920460"] [msg "Abnormal character escapes in request"] [data "Matched Data: w\\x5cd found within ARGS:method[0]: think\\x5cview\\x5cdriver\\x5cphp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/4"] [tag "OWASP_CRS"] [tag "capec/1000/153/267"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.017958 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Pattern match "(?:<\\\\?(?:[^x]|x[^m]|xm[^l]|xml[^\\\\s]|xml$|$)|<\\\\?php|\\\\[(?:\\\\/|\\\\\\\\)?php\\\\])" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "65"] [id "933100"] [msg "PHP Injection Attack: PHP Open Tag Found"] [data "Matched Data: <?p found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.019567 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Pattern match "(?i)\\\\b(?:c(?:o(?:n(?:v(?:ert(?:_tz)?)?|cat(?:_ws)?|nection_id)|(?:mpres)?s|ercibility|(?:un)?t|llation|alesce)|ur(?:rent_(?:time(?:stamp)?|date|user)|(?:dat|tim)e)|h(?:ar(?:(?:acter)?_length|set)?|r)|iel(?:ing)?|ast|r32)|s(?:u(?:b(?:str(?:ing(?:_index ..." at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "628"] [id "942150"] [msg "SQL Injection Attack"] [data "Matched Data: md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.020057 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Pattern match "(?i:\\\\b(?:c(?:o(?:n(?:v(?:ert(?:_tz)?)?|cat(?:_ws)?|nection_id)|(?:mpres)?s|ercibility|(?:un)?t|alesce)|ur(?:rent_(?:time(?:stamp)?|date|user)|(?:dat|tim)e)|h(?:ar(?:(?:acter)?_length|set)?|r)|iel(?:ing)?|ast|r32)|s(?:t(?:d(?:dev(?:_(?:sam|po)p)?)?|r(? ..." at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1056"] [id "942410"] [msg "SQL Injection Attack"] [data "Matched Data: md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.020258 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){6})" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1413"] [id "942431"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6)"] [data "Matched Data: <?php echo md5('a3233a3800f8cba9dd419d1997d27412'); found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.020362 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Pattern match "(?:'((?:[\\\\w\\\\s=_\\\\-+{}()<@]){2,29}|(?:[A-Za-z0-9+\\\\/]{4})+(?:[A-Za-z0-9+\\\\/]{2}==|[A-Za-z0-9+\\\\/]{3}=)?)')" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1527"] [id "942511"] [msg "SQLi bypass attempt by ticks detected"] [data "Matched Data: 'a3233a3800f8cba9dd419d1997d27412' found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.020428 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:method[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:method[0]: method[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.020540 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:method[1]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:method[1]: method[1]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.020664 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:22.020756 2026] [:error] [pid 24106:tid 140706903430912] [client 162.158.183.12:14285] [client 162.158.183.12] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: <?php echo md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsjs8oMu6f6EYbxTbUwAAAU8"]
[Tue Jul 28 01:37:23.020871 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.021856 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.022441 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/api/think\\x5capp/invokeMethod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.022490 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Found 3 byte(s) in ARGS:method[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:method[0]=think\\x5cview\\x5cdriver\\x5cPhp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.022581 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Found 9 byte(s) in ARGS:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:vars[0]=<?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.022664 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:method[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:method[0]=method[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.022727 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:method[1] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:method[1]=method[1]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.022801 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.022926 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.023032 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Pattern match "(?:^|[^\\\\\\\\])\\\\\\\\[cdeghijklmpqwxyz123456789]" at REQUEST_URI. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1593"] [id "920460"] [msg "Abnormal character escapes in request"] [data "Matched Data: w\\x5cd found within REQUEST_URI: /index.php?s=/api/think\\x5capp/invokemethod&method[0]=think\\x5cview\\x5cdriver\\x5cphp&method[1]=display&vars[0]=<?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/4"] [tag "OWASP_CRS"] [tag "capec/1000/153/267"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.023150 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Pattern match "(?:^|[^\\\\\\\\])\\\\\\\\[cdeghijklmpqwxyz123456789]" at ARGS:method[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1593"] [id "920460"] [msg "Abnormal character escapes in request"] [data "Matched Data: w\\x5cd found within ARGS:method[0]: think\\x5cview\\x5cdriver\\x5cphp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/4"] [tag "OWASP_CRS"] [tag "capec/1000/153/267"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.023976 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Pattern match "(?:<\\\\?(?:[^x]|x[^m]|xm[^l]|xml[^\\\\s]|xml$|$)|<\\\\?php|\\\\[(?:\\\\/|\\\\\\\\)?php\\\\])" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "65"] [id "933100"] [msg "PHP Injection Attack: PHP Open Tag Found"] [data "Matched Data: <?p found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.025650 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Pattern match "(?i)\\\\b(?:c(?:o(?:n(?:v(?:ert(?:_tz)?)?|cat(?:_ws)?|nection_id)|(?:mpres)?s|ercibility|(?:un)?t|llation|alesce)|ur(?:rent_(?:time(?:stamp)?|date|user)|(?:dat|tim)e)|h(?:ar(?:(?:acter)?_length|set)?|r)|iel(?:ing)?|ast|r32)|s(?:u(?:b(?:str(?:ing(?:_index ..." at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "628"] [id "942150"] [msg "SQL Injection Attack"] [data "Matched Data: md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.026281 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Pattern match "(?i:\\\\b(?:c(?:o(?:n(?:v(?:ert(?:_tz)?)?|cat(?:_ws)?|nection_id)|(?:mpres)?s|ercibility|(?:un)?t|alesce)|ur(?:rent_(?:time(?:stamp)?|date|user)|(?:dat|tim)e)|h(?:ar(?:(?:acter)?_length|set)?|r)|iel(?:ing)?|ast|r32)|s(?:t(?:d(?:dev(?:_(?:sam|po)p)?)?|r(? ..." at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1056"] [id "942410"] [msg "SQL Injection Attack"] [data "Matched Data: md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.026588 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){6})" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1413"] [id "942431"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6)"] [data "Matched Data: <?php echo md5('a3233a3800f8cba9dd419d1997d27412'); found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.026706 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Pattern match "(?:'((?:[\\\\w\\\\s=_\\\\-+{}()<@]){2,29}|(?:[A-Za-z0-9+\\\\/]{4})+(?:[A-Za-z0-9+\\\\/]{2}==|[A-Za-z0-9+\\\\/]{3}=)?)')" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1527"] [id "942511"] [msg "SQLi bypass attempt by ticks detected"] [data "Matched Data: 'a3233a3800f8cba9dd419d1997d27412' found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.026819 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:method[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:method[0]: method[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.026904 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:method[1]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:method[1]: method[1]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.026992 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.027066 2026] [:error] [pid 23952:tid 140706836289280] [client 104.23.162.72:14175] [client 104.23.162.72] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: <?php echo md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrsy8h5OE555JiBB-qcAAAAlc"]
[Tue Jul 28 01:37:23.908108 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.908698 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.909079 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/home/think\\x5capp/invokeMethod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.909109 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Found 3 byte(s) in ARGS:method[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:method[0]=think\\x5cview\\x5cdriver\\x5cPhp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.909144 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Found 9 byte(s) in ARGS:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:vars[0]=<?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.909189 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:method[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:method[0]=method[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.909218 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:method[1] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:method[1]=method[1]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.909243 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.909279 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.909330 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Pattern match "(?:^|[^\\\\\\\\])\\\\\\\\[cdeghijklmpqwxyz123456789]" at REQUEST_URI. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1593"] [id "920460"] [msg "Abnormal character escapes in request"] [data "Matched Data: w\\x5cd found within REQUEST_URI: /index.php?s=/home/think\\x5capp/invokemethod&method[0]=think\\x5cview\\x5cdriver\\x5cphp&method[1]=display&vars[0]=<?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/4"] [tag "OWASP_CRS"] [tag "capec/1000/153/267"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.909432 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Pattern match "(?:^|[^\\\\\\\\])\\\\\\\\[cdeghijklmpqwxyz123456789]" at ARGS:method[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1593"] [id "920460"] [msg "Abnormal character escapes in request"] [data "Matched Data: w\\x5cd found within ARGS:method[0]: think\\x5cview\\x5cdriver\\x5cphp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/4"] [tag "OWASP_CRS"] [tag "capec/1000/153/267"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.909998 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Pattern match "(?:<\\\\?(?:[^x]|x[^m]|xm[^l]|xml[^\\\\s]|xml$|$)|<\\\\?php|\\\\[(?:\\\\/|\\\\\\\\)?php\\\\])" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "65"] [id "933100"] [msg "PHP Injection Attack: PHP Open Tag Found"] [data "Matched Data: <?p found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.911005 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Pattern match "(?i)\\\\b(?:c(?:o(?:n(?:v(?:ert(?:_tz)?)?|cat(?:_ws)?|nection_id)|(?:mpres)?s|ercibility|(?:un)?t|llation|alesce)|ur(?:rent_(?:time(?:stamp)?|date|user)|(?:dat|tim)e)|h(?:ar(?:(?:acter)?_length|set)?|r)|iel(?:ing)?|ast|r32)|s(?:u(?:b(?:str(?:ing(?:_index ..." at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "628"] [id "942150"] [msg "SQL Injection Attack"] [data "Matched Data: md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.911377 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Pattern match "(?i:\\\\b(?:c(?:o(?:n(?:v(?:ert(?:_tz)?)?|cat(?:_ws)?|nection_id)|(?:mpres)?s|ercibility|(?:un)?t|alesce)|ur(?:rent_(?:time(?:stamp)?|date|user)|(?:dat|tim)e)|h(?:ar(?:(?:acter)?_length|set)?|r)|iel(?:ing)?|ast|r32)|s(?:t(?:d(?:dev(?:_(?:sam|po)p)?)?|r(? ..." at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1056"] [id "942410"] [msg "SQL Injection Attack"] [data "Matched Data: md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.911578 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){6})" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1413"] [id "942431"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6)"] [data "Matched Data: <?php echo md5('a3233a3800f8cba9dd419d1997d27412'); found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.911655 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Pattern match "(?:'((?:[\\\\w\\\\s=_\\\\-+{}()<@]){2,29}|(?:[A-Za-z0-9+\\\\/]{4})+(?:[A-Za-z0-9+\\\\/]{2}==|[A-Za-z0-9+\\\\/]{3}=)?)')" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1527"] [id "942511"] [msg "SQLi bypass attempt by ticks detected"] [data "Matched Data: 'a3233a3800f8cba9dd419d1997d27412' found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.911699 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:method[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:method[0]: method[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.911739 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:method[1]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:method[1]: method[1]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.911785 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:23.911825 2026] [:error] [pid 21545:tid 140706978965248] [client 162.158.217.57:12766] [client 162.158.217.57] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: <?php echo md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrs5hXfYDIcpslIWPwRQAAAYY"]
[Tue Jul 28 01:37:24.891061 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.891779 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.892180 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/user/think\\x5capp/invokeMethod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.892224 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Found 3 byte(s) in ARGS:method[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:method[0]=think\\x5cview\\x5cdriver\\x5cPhp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.892267 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Found 9 byte(s) in ARGS:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:vars[0]=<?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.892314 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:method[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:method[0]=method[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.892351 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:method[1] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:method[1]=method[1]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.892392 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.892450 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.892512 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Pattern match "(?:^|[^\\\\\\\\])\\\\\\\\[cdeghijklmpqwxyz123456789]" at REQUEST_URI. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1593"] [id "920460"] [msg "Abnormal character escapes in request"] [data "Matched Data: w\\x5cd found within REQUEST_URI: /index.php?s=/user/think\\x5capp/invokemethod&method[0]=think\\x5cview\\x5cdriver\\x5cphp&method[1]=display&vars[0]=<?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/4"] [tag "OWASP_CRS"] [tag "capec/1000/153/267"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.892612 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Pattern match "(?:^|[^\\\\\\\\])\\\\\\\\[cdeghijklmpqwxyz123456789]" at ARGS:method[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1593"] [id "920460"] [msg "Abnormal character escapes in request"] [data "Matched Data: w\\x5cd found within ARGS:method[0]: think\\x5cview\\x5cdriver\\x5cphp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/4"] [tag "OWASP_CRS"] [tag "capec/1000/153/267"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.893147 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Pattern match "(?:<\\\\?(?:[^x]|x[^m]|xm[^l]|xml[^\\\\s]|xml$|$)|<\\\\?php|\\\\[(?:\\\\/|\\\\\\\\)?php\\\\])" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "65"] [id "933100"] [msg "PHP Injection Attack: PHP Open Tag Found"] [data "Matched Data: <?p found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.894189 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Pattern match "(?i)\\\\b(?:c(?:o(?:n(?:v(?:ert(?:_tz)?)?|cat(?:_ws)?|nection_id)|(?:mpres)?s|ercibility|(?:un)?t|llation|alesce)|ur(?:rent_(?:time(?:stamp)?|date|user)|(?:dat|tim)e)|h(?:ar(?:(?:acter)?_length|set)?|r)|iel(?:ing)?|ast|r32)|s(?:u(?:b(?:str(?:ing(?:_index ..." at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "628"] [id "942150"] [msg "SQL Injection Attack"] [data "Matched Data: md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.894576 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Pattern match "(?i:\\\\b(?:c(?:o(?:n(?:v(?:ert(?:_tz)?)?|cat(?:_ws)?|nection_id)|(?:mpres)?s|ercibility|(?:un)?t|alesce)|ur(?:rent_(?:time(?:stamp)?|date|user)|(?:dat|tim)e)|h(?:ar(?:(?:acter)?_length|set)?|r)|iel(?:ing)?|ast|r32)|s(?:t(?:d(?:dev(?:_(?:sam|po)p)?)?|r(? ..." at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1056"] [id "942410"] [msg "SQL Injection Attack"] [data "Matched Data: md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.894748 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){6})" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1413"] [id "942431"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6)"] [data "Matched Data: <?php echo md5('a3233a3800f8cba9dd419d1997d27412'); found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.894837 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Pattern match "(?:'((?:[\\\\w\\\\s=_\\\\-+{}()<@]){2,29}|(?:[A-Za-z0-9+\\\\/]{4})+(?:[A-Za-z0-9+\\\\/]{2}==|[A-Za-z0-9+\\\\/]{3}=)?)')" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1527"] [id "942511"] [msg "SQLi bypass attempt by ticks detected"] [data "Matched Data: 'a3233a3800f8cba9dd419d1997d27412' found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.894913 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:method[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:method[0]: method[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.895008 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:method[1]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:method[1]: method[1]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.895068 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:24.895125 2026] [:error] [pid 21545:tid 140707020928768] [client 172.71.118.224:12978] [client 172.71.118.224] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: <?php echo md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtJhXfYDIcpslIWPwTgAAAYE"]
[Tue Jul 28 01:37:26.069812 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.070732 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.071235 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=//think\\x5capp/invokeMethod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.071279 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Found 3 byte(s) in ARGS:method[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:method[0]=think\\x5cview\\x5cdriver\\x5cPhp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.071326 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Found 9 byte(s) in ARGS:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:vars[0]=<?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.071373 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:method[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:method[0]=method[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.071445 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:method[1] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:method[1]=method[1]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.071488 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.071542 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.071627 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Pattern match "(?:^|[^\\\\\\\\])\\\\\\\\[cdeghijklmpqwxyz123456789]" at REQUEST_URI. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1593"] [id "920460"] [msg "Abnormal character escapes in request"] [data "Matched Data: w\\x5cd found within REQUEST_URI: /index.php?s=//think\\x5capp/invokemethod&method[0]=think\\x5cview\\x5cdriver\\x5cphp&method[1]=display&vars[0]=<?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/4"] [tag "OWASP_CRS"] [tag "capec/1000/153/267"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.071758 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Pattern match "(?:^|[^\\\\\\\\])\\\\\\\\[cdeghijklmpqwxyz123456789]" at ARGS:method[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1593"] [id "920460"] [msg "Abnormal character escapes in request"] [data "Matched Data: w\\x5cd found within ARGS:method[0]: think\\x5cview\\x5cdriver\\x5cphp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/4"] [tag "OWASP_CRS"] [tag "capec/1000/153/267"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.072476 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Pattern match "(?:<\\\\?(?:[^x]|x[^m]|xm[^l]|xml[^\\\\s]|xml$|$)|<\\\\?php|\\\\[(?:\\\\/|\\\\\\\\)?php\\\\])" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "65"] [id "933100"] [msg "PHP Injection Attack: PHP Open Tag Found"] [data "Matched Data: <?p found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.074070 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Pattern match "(?i)\\\\b(?:c(?:o(?:n(?:v(?:ert(?:_tz)?)?|cat(?:_ws)?|nection_id)|(?:mpres)?s|ercibility|(?:un)?t|llation|alesce)|ur(?:rent_(?:time(?:stamp)?|date|user)|(?:dat|tim)e)|h(?:ar(?:(?:acter)?_length|set)?|r)|iel(?:ing)?|ast|r32)|s(?:u(?:b(?:str(?:ing(?:_index ..." at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "628"] [id "942150"] [msg "SQL Injection Attack"] [data "Matched Data: md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.074662 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Pattern match "(?i:\\\\b(?:c(?:o(?:n(?:v(?:ert(?:_tz)?)?|cat(?:_ws)?|nection_id)|(?:mpres)?s|ercibility|(?:un)?t|alesce)|ur(?:rent_(?:time(?:stamp)?|date|user)|(?:dat|tim)e)|h(?:ar(?:(?:acter)?_length|set)?|r)|iel(?:ing)?|ast|r32)|s(?:t(?:d(?:dev(?:_(?:sam|po)p)?)?|r(? ..." at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1056"] [id "942410"] [msg "SQL Injection Attack"] [data "Matched Data: md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.074936 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){6})" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1413"] [id "942431"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6)"] [data "Matched Data: <?php echo md5('a3233a3800f8cba9dd419d1997d27412'); found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.075058 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Pattern match "(?:'((?:[\\\\w\\\\s=_\\\\-+{}()<@]){2,29}|(?:[A-Za-z0-9+\\\\/]{4})+(?:[A-Za-z0-9+\\\\/]{2}==|[A-Za-z0-9+\\\\/]{3}=)?)')" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1527"] [id "942511"] [msg "SQLi bypass attempt by ticks detected"] [data "Matched Data: 'a3233a3800f8cba9dd419d1997d27412' found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.075128 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:method[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:method[0]: method[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.075190 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:method[1]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:method[1]: method[1]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.075248 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:26.075322 2026] [:error] [pid 12380:tid 140706995750656] [client 172.71.98.106:11959] [client 172.71.98.106] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: <?php echo md5( found within ARGS:vars[0]: <?php echo md5('a3233a3800f8cba9dd419d1997d27412');"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrtqaChfbWW0CZ_hqJjgAAAMQ"]
[Tue Jul 28 01:37:27.869648 2026] [:error] [pid 12275:tid 140706836289280] [client 172.69.208.132:13841] [client 172.69.208.132] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrt3FwI8r7BFXGkAv9NQAAABc"]
[Tue Jul 28 01:37:27.871150 2026] [:error] [pid 12275:tid 140706836289280] [client 172.69.208.132:13841] [client 172.69.208.132] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrt3FwI8r7BFXGkAv9NQAAABc"]
[Tue Jul 28 01:37:27.871654 2026] [:error] [pid 12275:tid 140706836289280] [client 172.69.208.132:13841] [client 172.69.208.132] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/index/think\\x5capp/invokefunction"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrt3FwI8r7BFXGkAv9NQAAABc"]
[Tue Jul 28 01:37:27.871707 2026] [:error] [pid 12275:tid 140706836289280] [client 172.69.208.132:13841] [client 172.69.208.132] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrt3FwI8r7BFXGkAv9NQAAABc"]
[Tue Jul 28 01:37:27.871768 2026] [:error] [pid 12275:tid 140706836289280] [client 172.69.208.132:13841] [client 172.69.208.132] ModSecurity: Warning. Found 4 byte(s) in ARGS_NAMES:vars[1][] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[1][]=vars[1][]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrt3FwI8r7BFXGkAv9NQAAABc"]
[Tue Jul 28 01:37:27.871835 2026] [:error] [pid 12275:tid 140706836289280] [client 172.69.208.132:13841] [client 172.69.208.132] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrt3FwI8r7BFXGkAv9NQAAABc"]
[Tue Jul 28 01:37:27.872795 2026] [:error] [pid 12275:tid 140706836289280] [client 172.69.208.132:13841] [client 172.69.208.132] ModSecurity: Warning. Matched phrase "call_user_func" at ARGS:function. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "294"] [id "933150"] [msg "PHP Injection Attack: High-Risk PHP Function Name Found"] [data "Matched Data: call_user_func found within ARGS:function: call_user_func_array"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrt3FwI8r7BFXGkAv9NQAAABc"]
[Tue Jul 28 01:37:27.874634 2026] [:error] [pid 12275:tid 140706836289280] [client 172.69.208.132:13841] [client 172.69.208.132] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrt3FwI8r7BFXGkAv9NQAAABc"]
[Tue Jul 28 01:37:27.874718 2026] [:error] [pid 12275:tid 140706836289280] [client 172.69.208.132:13841] [client 172.69.208.132] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[1][]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:vars[1][]: vars[1][]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrt3FwI8r7BFXGkAv9NQAAABc"]
[Tue Jul 28 01:37:29.556251 2026] [:error] [pid 24106:tid 140707103270656] [client 104.23.199.89:10619] [client 104.23.199.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruTs8oMu6f6EYbxTbVQAAAUA"]
[Tue Jul 28 01:37:29.557248 2026] [:error] [pid 24106:tid 140707103270656] [client 104.23.199.89:10619] [client 104.23.199.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruTs8oMu6f6EYbxTbVQAAAUA"]
[Tue Jul 28 01:37:29.557843 2026] [:error] [pid 24106:tid 140707103270656] [client 104.23.199.89:10619] [client 104.23.199.89] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/admin/think\\x5capp/invokefunction"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruTs8oMu6f6EYbxTbVQAAAUA"]
[Tue Jul 28 01:37:29.557920 2026] [:error] [pid 24106:tid 140707103270656] [client 104.23.199.89:10619] [client 104.23.199.89] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruTs8oMu6f6EYbxTbVQAAAUA"]
[Tue Jul 28 01:37:29.557980 2026] [:error] [pid 24106:tid 140707103270656] [client 104.23.199.89:10619] [client 104.23.199.89] ModSecurity: Warning. Found 4 byte(s) in ARGS_NAMES:vars[1][] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[1][]=vars[1][]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruTs8oMu6f6EYbxTbVQAAAUA"]
[Tue Jul 28 01:37:29.558068 2026] [:error] [pid 24106:tid 140707103270656] [client 104.23.199.89:10619] [client 104.23.199.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruTs8oMu6f6EYbxTbVQAAAUA"]
[Tue Jul 28 01:37:29.559006 2026] [:error] [pid 24106:tid 140707103270656] [client 104.23.199.89:10619] [client 104.23.199.89] ModSecurity: Warning. Matched phrase "call_user_func" at ARGS:function. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "294"] [id "933150"] [msg "PHP Injection Attack: High-Risk PHP Function Name Found"] [data "Matched Data: call_user_func found within ARGS:function: call_user_func_array"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruTs8oMu6f6EYbxTbVQAAAUA"]
[Tue Jul 28 01:37:29.561031 2026] [:error] [pid 24106:tid 140707103270656] [client 104.23.199.89:10619] [client 104.23.199.89] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruTs8oMu6f6EYbxTbVQAAAUA"]
[Tue Jul 28 01:37:29.561138 2026] [:error] [pid 24106:tid 140707103270656] [client 104.23.199.89:10619] [client 104.23.199.89] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[1][]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:vars[1][]: vars[1][]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruTs8oMu6f6EYbxTbVQAAAUA"]
[Tue Jul 28 01:37:30.736092 2026] [:error] [pid 12275:tid 140707103270656] [client 104.23.166.83:12276] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrunFwI8r7BFXGkAv9OAAAAAA"]
[Tue Jul 28 01:37:30.736989 2026] [:error] [pid 12275:tid 140707103270656] [client 104.23.166.83:12276] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrunFwI8r7BFXGkAv9OAAAAAA"]
[Tue Jul 28 01:37:30.737450 2026] [:error] [pid 12275:tid 140707103270656] [client 104.23.166.83:12276] [client 104.23.166.83] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/api/think\\x5capp/invokefunction"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrunFwI8r7BFXGkAv9OAAAAAA"]
[Tue Jul 28 01:37:30.737502 2026] [:error] [pid 12275:tid 140707103270656] [client 104.23.166.83:12276] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrunFwI8r7BFXGkAv9OAAAAAA"]
[Tue Jul 28 01:37:30.737543 2026] [:error] [pid 12275:tid 140707103270656] [client 104.23.166.83:12276] [client 104.23.166.83] ModSecurity: Warning. Found 4 byte(s) in ARGS_NAMES:vars[1][] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[1][]=vars[1][]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrunFwI8r7BFXGkAv9OAAAAAA"]
[Tue Jul 28 01:37:30.737620 2026] [:error] [pid 12275:tid 140707103270656] [client 104.23.166.83:12276] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrunFwI8r7BFXGkAv9OAAAAAA"]
[Tue Jul 28 01:37:30.738421 2026] [:error] [pid 12275:tid 140707103270656] [client 104.23.166.83:12276] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "call_user_func" at ARGS:function. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "294"] [id "933150"] [msg "PHP Injection Attack: High-Risk PHP Function Name Found"] [data "Matched Data: call_user_func found within ARGS:function: call_user_func_array"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrunFwI8r7BFXGkAv9OAAAAAA"]
[Tue Jul 28 01:37:30.740227 2026] [:error] [pid 12275:tid 140707103270656] [client 104.23.166.83:12276] [client 104.23.166.83] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrunFwI8r7BFXGkAv9OAAAAAA"]
[Tue Jul 28 01:37:30.740308 2026] [:error] [pid 12275:tid 140707103270656] [client 104.23.166.83:12276] [client 104.23.166.83] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[1][]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:vars[1][]: vars[1][]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrunFwI8r7BFXGkAv9OAAAAAA"]
[Tue Jul 28 01:37:30.989297 2026] [:error] [pid 12380:tid 140706878252800] [client 104.23.166.130:13768] [client 104.23.166.130] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruqaChfbWW0CZ_hqJmgAAANI"]
[Tue Jul 28 01:37:30.990265 2026] [:error] [pid 12380:tid 140706878252800] [client 104.23.166.130:13768] [client 104.23.166.130] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruqaChfbWW0CZ_hqJmgAAANI"]
[Tue Jul 28 01:37:30.990807 2026] [:error] [pid 12380:tid 140706878252800] [client 104.23.166.130:13768] [client 104.23.166.130] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/home/think\\x5capp/invokefunction"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruqaChfbWW0CZ_hqJmgAAANI"]
[Tue Jul 28 01:37:30.990879 2026] [:error] [pid 12380:tid 140706878252800] [client 104.23.166.130:13768] [client 104.23.166.130] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruqaChfbWW0CZ_hqJmgAAANI"]
[Tue Jul 28 01:37:30.990929 2026] [:error] [pid 12380:tid 140706878252800] [client 104.23.166.130:13768] [client 104.23.166.130] ModSecurity: Warning. Found 4 byte(s) in ARGS_NAMES:vars[1][] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[1][]=vars[1][]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruqaChfbWW0CZ_hqJmgAAANI"]
[Tue Jul 28 01:37:30.990994 2026] [:error] [pid 12380:tid 140706878252800] [client 104.23.166.130:13768] [client 104.23.166.130] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruqaChfbWW0CZ_hqJmgAAANI"]
[Tue Jul 28 01:37:30.991922 2026] [:error] [pid 12380:tid 140706878252800] [client 104.23.166.130:13768] [client 104.23.166.130] ModSecurity: Warning. Matched phrase "call_user_func" at ARGS:function. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "294"] [id "933150"] [msg "PHP Injection Attack: High-Risk PHP Function Name Found"] [data "Matched Data: call_user_func found within ARGS:function: call_user_func_array"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruqaChfbWW0CZ_hqJmgAAANI"]
[Tue Jul 28 01:37:30.993965 2026] [:error] [pid 12380:tid 140706878252800] [client 104.23.166.130:13768] [client 104.23.166.130] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruqaChfbWW0CZ_hqJmgAAANI"]
[Tue Jul 28 01:37:30.994075 2026] [:error] [pid 12380:tid 140706878252800] [client 104.23.166.130:13768] [client 104.23.166.130] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[1][]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:vars[1][]: vars[1][]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfruqaChfbWW0CZ_hqJmgAAANI"]
[Tue Jul 28 01:37:31.740541 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.168.5:13648] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfru5hXfYDIcpslIWPwbgAAAYE"]
[Tue Jul 28 01:37:31.741224 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.168.5:13648] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfru5hXfYDIcpslIWPwbgAAAYE"]
[Tue Jul 28 01:37:31.741618 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.168.5:13648] [client 104.23.168.5] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/user/think\\x5capp/invokefunction"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfru5hXfYDIcpslIWPwbgAAAYE"]
[Tue Jul 28 01:37:31.741656 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.168.5:13648] [client 104.23.168.5] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfru5hXfYDIcpslIWPwbgAAAYE"]
[Tue Jul 28 01:37:31.741684 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.168.5:13648] [client 104.23.168.5] ModSecurity: Warning. Found 4 byte(s) in ARGS_NAMES:vars[1][] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[1][]=vars[1][]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfru5hXfYDIcpslIWPwbgAAAYE"]
[Tue Jul 28 01:37:31.741722 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.168.5:13648] [client 104.23.168.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfru5hXfYDIcpslIWPwbgAAAYE"]
[Tue Jul 28 01:37:31.742289 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.168.5:13648] [client 104.23.168.5] ModSecurity: Warning. Matched phrase "call_user_func" at ARGS:function. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "294"] [id "933150"] [msg "PHP Injection Attack: High-Risk PHP Function Name Found"] [data "Matched Data: call_user_func found within ARGS:function: call_user_func_array"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfru5hXfYDIcpslIWPwbgAAAYE"]
[Tue Jul 28 01:37:31.743571 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.168.5:13648] [client 104.23.168.5] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfru5hXfYDIcpslIWPwbgAAAYE"]
[Tue Jul 28 01:37:31.743633 2026] [:error] [pid 21545:tid 140707020928768] [client 104.23.168.5:13648] [client 104.23.168.5] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[1][]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:vars[1][]: vars[1][]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfru5hXfYDIcpslIWPwbgAAAYE"]
[Tue Jul 28 01:37:38.723037 2026] [:error] [pid 12380:tid 140707012536064] [client 172.69.130.115:9295] [client 172.69.130.115] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrwqaChfbWW0CZ_hqJtQAAAMI"]
[Tue Jul 28 01:37:38.723954 2026] [:error] [pid 12380:tid 140707012536064] [client 172.69.130.115:9295] [client 172.69.130.115] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrwqaChfbWW0CZ_hqJtQAAAMI"]
[Tue Jul 28 01:37:38.724438 2026] [:error] [pid 12380:tid 140707012536064] [client 172.69.130.115:9295] [client 172.69.130.115] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/index/think\\x5capp/invokefunction"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrwqaChfbWW0CZ_hqJtQAAAMI"]
[Tue Jul 28 01:37:38.724537 2026] [:error] [pid 12380:tid 140707012536064] [client 172.69.130.115:9295] [client 172.69.130.115] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrwqaChfbWW0CZ_hqJtQAAAMI"]
[Tue Jul 28 01:37:38.724610 2026] [:error] [pid 12380:tid 140707012536064] [client 172.69.130.115:9295] [client 172.69.130.115] ModSecurity: Warning. Found 4 byte(s) in ARGS_NAMES:vars[1][] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[1][]=vars[1][]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrwqaChfbWW0CZ_hqJtQAAAMI"]
[Tue Jul 28 01:37:38.724672 2026] [:error] [pid 12380:tid 140707012536064] [client 172.69.130.115:9295] [client 172.69.130.115] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrwqaChfbWW0CZ_hqJtQAAAMI"]
[Tue Jul 28 01:37:38.725494 2026] [:error] [pid 12380:tid 140707012536064] [client 172.69.130.115:9295] [client 172.69.130.115] ModSecurity: Warning. Matched phrase "call_user_func" at ARGS:function. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "294"] [id "933150"] [msg "PHP Injection Attack: High-Risk PHP Function Name Found"] [data "Matched Data: call_user_func found within ARGS:function: call_user_func_array"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrwqaChfbWW0CZ_hqJtQAAAMI"]
[Tue Jul 28 01:37:38.726875 2026] [:error] [pid 12380:tid 140707012536064] [client 172.69.130.115:9295] [client 172.69.130.115] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrwqaChfbWW0CZ_hqJtQAAAMI"]
[Tue Jul 28 01:37:38.726987 2026] [:error] [pid 12380:tid 140707012536064] [client 172.69.130.115:9295] [client 172.69.130.115] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[1][]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:vars[1][]: vars[1][]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrwqaChfbWW0CZ_hqJtQAAAMI"]
[Tue Jul 28 01:37:40.367767 2026] [:error] [pid 12380:tid 140706911823616] [client 172.68.129.148:13788] [client 172.68.129.148] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxKaChfbWW0CZ_hqJvwAAAM4"]
[Tue Jul 28 01:37:40.368781 2026] [:error] [pid 12380:tid 140706911823616] [client 172.68.129.148:13788] [client 172.68.129.148] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxKaChfbWW0CZ_hqJvwAAAM4"]
[Tue Jul 28 01:37:40.369429 2026] [:error] [pid 12380:tid 140706911823616] [client 172.68.129.148:13788] [client 172.68.129.148] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/admin/think\\x5capp/invokefunction"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxKaChfbWW0CZ_hqJvwAAAM4"]
[Tue Jul 28 01:37:40.369525 2026] [:error] [pid 12380:tid 140706911823616] [client 172.68.129.148:13788] [client 172.68.129.148] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxKaChfbWW0CZ_hqJvwAAAM4"]
[Tue Jul 28 01:37:40.369637 2026] [:error] [pid 12380:tid 140706911823616] [client 172.68.129.148:13788] [client 172.68.129.148] ModSecurity: Warning. Found 4 byte(s) in ARGS_NAMES:vars[1][] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[1][]=vars[1][]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxKaChfbWW0CZ_hqJvwAAAM4"]
[Tue Jul 28 01:37:40.369721 2026] [:error] [pid 12380:tid 140706911823616] [client 172.68.129.148:13788] [client 172.68.129.148] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxKaChfbWW0CZ_hqJvwAAAM4"]
[Tue Jul 28 01:37:40.370724 2026] [:error] [pid 12380:tid 140706911823616] [client 172.68.129.148:13788] [client 172.68.129.148] ModSecurity: Warning. Matched phrase "call_user_func" at ARGS:function. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "294"] [id "933150"] [msg "PHP Injection Attack: High-Risk PHP Function Name Found"] [data "Matched Data: call_user_func found within ARGS:function: call_user_func_array"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxKaChfbWW0CZ_hqJvwAAAM4"]
[Tue Jul 28 01:37:40.372894 2026] [:error] [pid 12380:tid 140706911823616] [client 172.68.129.148:13788] [client 172.68.129.148] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxKaChfbWW0CZ_hqJvwAAAM4"]
[Tue Jul 28 01:37:40.373013 2026] [:error] [pid 12380:tid 140706911823616] [client 172.68.129.148:13788] [client 172.68.129.148] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[1][]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:vars[1][]: vars[1][]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxKaChfbWW0CZ_hqJvwAAAM4"]
[Tue Jul 28 01:37:41.566983 2026] [:error] [pid 21545:tid 140706970572544] [client 172.69.151.108:9431] [client 172.69.151.108] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxZhXfYDIcpslIWPwsAAAAYc"]
[Tue Jul 28 01:37:41.567967 2026] [:error] [pid 21545:tid 140706970572544] [client 172.69.151.108:9431] [client 172.69.151.108] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxZhXfYDIcpslIWPwsAAAAYc"]
[Tue Jul 28 01:37:41.568535 2026] [:error] [pid 21545:tid 140706970572544] [client 172.69.151.108:9431] [client 172.69.151.108] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/api/think\\x5capp/invokefunction"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxZhXfYDIcpslIWPwsAAAAYc"]
[Tue Jul 28 01:37:41.568629 2026] [:error] [pid 21545:tid 140706970572544] [client 172.69.151.108:9431] [client 172.69.151.108] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxZhXfYDIcpslIWPwsAAAAYc"]
[Tue Jul 28 01:37:41.568693 2026] [:error] [pid 21545:tid 140706970572544] [client 172.69.151.108:9431] [client 172.69.151.108] ModSecurity: Warning. Found 4 byte(s) in ARGS_NAMES:vars[1][] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[1][]=vars[1][]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxZhXfYDIcpslIWPwsAAAAYc"]
[Tue Jul 28 01:37:41.568802 2026] [:error] [pid 21545:tid 140706970572544] [client 172.69.151.108:9431] [client 172.69.151.108] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxZhXfYDIcpslIWPwsAAAAYc"]
[Tue Jul 28 01:37:41.569697 2026] [:error] [pid 21545:tid 140706970572544] [client 172.69.151.108:9431] [client 172.69.151.108] ModSecurity: Warning. Matched phrase "call_user_func" at ARGS:function. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "294"] [id "933150"] [msg "PHP Injection Attack: High-Risk PHP Function Name Found"] [data "Matched Data: call_user_func found within ARGS:function: call_user_func_array"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxZhXfYDIcpslIWPwsAAAAYc"]
[Tue Jul 28 01:37:41.571692 2026] [:error] [pid 21545:tid 140706970572544] [client 172.69.151.108:9431] [client 172.69.151.108] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxZhXfYDIcpslIWPwsAAAAYc"]
[Tue Jul 28 01:37:41.571823 2026] [:error] [pid 21545:tid 140706970572544] [client 172.69.151.108:9431] [client 172.69.151.108] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[1][]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:vars[1][]: vars[1][]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxZhXfYDIcpslIWPwsAAAAYc"]
[Tue Jul 28 01:37:42.392606 2026] [:error] [pid 21545:tid 140707004143360] [client 104.23.162.73:10223] [client 104.23.162.73] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxphXfYDIcpslIWPwtwAAAYM"]
[Tue Jul 28 01:37:42.393545 2026] [:error] [pid 21545:tid 140707004143360] [client 104.23.162.73:10223] [client 104.23.162.73] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxphXfYDIcpslIWPwtwAAAYM"]
[Tue Jul 28 01:37:42.394126 2026] [:error] [pid 21545:tid 140707004143360] [client 104.23.162.73:10223] [client 104.23.162.73] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/home/think\\x5capp/invokefunction"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxphXfYDIcpslIWPwtwAAAYM"]
[Tue Jul 28 01:37:42.394200 2026] [:error] [pid 21545:tid 140707004143360] [client 104.23.162.73:10223] [client 104.23.162.73] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxphXfYDIcpslIWPwtwAAAYM"]
[Tue Jul 28 01:37:42.394258 2026] [:error] [pid 21545:tid 140707004143360] [client 104.23.162.73:10223] [client 104.23.162.73] ModSecurity: Warning. Found 4 byte(s) in ARGS_NAMES:vars[1][] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[1][]=vars[1][]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxphXfYDIcpslIWPwtwAAAYM"]
[Tue Jul 28 01:37:42.394347 2026] [:error] [pid 21545:tid 140707004143360] [client 104.23.162.73:10223] [client 104.23.162.73] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxphXfYDIcpslIWPwtwAAAYM"]
[Tue Jul 28 01:37:42.395270 2026] [:error] [pid 21545:tid 140707004143360] [client 104.23.162.73:10223] [client 104.23.162.73] ModSecurity: Warning. Matched phrase "call_user_func" at ARGS:function. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "294"] [id "933150"] [msg "PHP Injection Attack: High-Risk PHP Function Name Found"] [data "Matched Data: call_user_func found within ARGS:function: call_user_func_array"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxphXfYDIcpslIWPwtwAAAYM"]
[Tue Jul 28 01:37:42.397284 2026] [:error] [pid 21545:tid 140707004143360] [client 104.23.162.73:10223] [client 104.23.162.73] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxphXfYDIcpslIWPwtwAAAYM"]
[Tue Jul 28 01:37:42.397375 2026] [:error] [pid 21545:tid 140707004143360] [client 104.23.162.73:10223] [client 104.23.162.73] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[1][]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:vars[1][]: vars[1][]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrxphXfYDIcpslIWPwtwAAAYM"]
[Tue Jul 28 01:37:44.698292 2026] [:error] [pid 12380:tid 140706970572544] [client 172.71.98.106:9282] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfryKaChfbWW0CZ_hqJzwAAAMc"]
[Tue Jul 28 01:37:44.699025 2026] [:error] [pid 12380:tid 140706970572544] [client 172.71.98.106:9282] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfryKaChfbWW0CZ_hqJzwAAAMc"]
[Tue Jul 28 01:37:44.699443 2026] [:error] [pid 12380:tid 140706970572544] [client 172.71.98.106:9282] [client 172.71.98.106] ModSecurity: Warning. Found 4 byte(s) in ARGS:s outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:s=/user/think\\x5capp/invokefunction"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfryKaChfbWW0CZ_hqJzwAAAMc"]
[Tue Jul 28 01:37:44.699488 2026] [:error] [pid 12380:tid 140706970572544] [client 172.71.98.106:9282] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:vars[0] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[0]=vars[0]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfryKaChfbWW0CZ_hqJzwAAAMc"]
[Tue Jul 28 01:37:44.699518 2026] [:error] [pid 12380:tid 140706970572544] [client 172.71.98.106:9282] [client 172.71.98.106] ModSecurity: Warning. Found 4 byte(s) in ARGS_NAMES:vars[1][] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:vars[1][]=vars[1][]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfryKaChfbWW0CZ_hqJzwAAAMc"]
[Tue Jul 28 01:37:44.699591 2026] [:error] [pid 12380:tid 140706970572544] [client 172.71.98.106:9282] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfryKaChfbWW0CZ_hqJzwAAAMc"]
[Tue Jul 28 01:37:44.700342 2026] [:error] [pid 12380:tid 140706970572544] [client 172.71.98.106:9282] [client 172.71.98.106] ModSecurity: Warning. Matched phrase "call_user_func" at ARGS:function. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "294"] [id "933150"] [msg "PHP Injection Attack: High-Risk PHP Function Name Found"] [data "Matched Data: call_user_func found within ARGS:function: call_user_func_array"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfryKaChfbWW0CZ_hqJzwAAAMc"]
[Tue Jul 28 01:37:44.701666 2026] [:error] [pid 12380:tid 140706970572544] [client 172.71.98.106:9282] [client 172.71.98.106] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[0]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [0] found within ARGS_NAMES:vars[0]: vars[0]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfryKaChfbWW0CZ_hqJzwAAAMc"]
[Tue Jul 28 01:37:44.701729 2026] [:error] [pid 12380:tid 140706970572544] [client 172.71.98.106:9282] [client 172.71.98.106] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:vars[1][]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [1] found within ARGS_NAMES:vars[1][]: vars[1][]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfryKaChfbWW0CZ_hqJzwAAAMc"]
[Tue Jul 28 01:37:51.165067 2026] [:error] [pid 12380:tid 140706970572544] [client 104.23.199.89:12648] [client 104.23.199.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrz6aChfbWW0CZ_hqJ7wAAAMc"]
[Tue Jul 28 01:37:51.165968 2026] [:error] [pid 12380:tid 140706970572544] [client 104.23.199.89:12648] [client 104.23.199.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrz6aChfbWW0CZ_hqJ7wAAAMc"]
[Tue Jul 28 01:37:51.166282 2026] [:error] [pid 12380:tid 140706970572544] [client 104.23.199.89:12648] [client 104.23.199.89] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/x-www-form-urlencoded|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrz6aChfbWW0CZ_hqJ7wAAAMc"]
[Tue Jul 28 01:37:51.166609 2026] [:error] [pid 12380:tid 140706970572544] [client 104.23.199.89:12648] [client 104.23.199.89] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:filter[] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:filter[]=filter[]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrz6aChfbWW0CZ_hqJ7wAAAMc"]
[Tue Jul 28 01:37:51.166652 2026] [:error] [pid 12380:tid 140706970572544] [client 104.23.199.89:12648] [client 104.23.199.89] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:SERVER[REQUEST_METHOD] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:SERVER[REQUEST_METHOD]=SERVER[REQUEST_METHOD]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrz6aChfbWW0CZ_hqJ7wAAAMc"]
[Tue Jul 28 01:37:51.166707 2026] [:error] [pid 12380:tid 140706970572544] [client 104.23.199.89:12648] [client 104.23.199.89] ModSecurity: Warning. Found 4 byte(s) in REQUEST_BODY outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "REQUEST_BODY=_method=__construct&filter[]=phpinfo&method=get&SERVER[REQUEST_METHOD]=pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrz6aChfbWW0CZ_hqJ7wAAAMc"]
[Tue Jul 28 01:37:51.166783 2026] [:error] [pid 12380:tid 140706970572544] [client 104.23.199.89:12648] [client 104.23.199.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrz6aChfbWW0CZ_hqJ7wAAAMc"]
[Tue Jul 28 01:37:51.169360 2026] [:error] [pid 12380:tid 140706970572544] [client 104.23.199.89:12648] [client 104.23.199.89] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:filter[]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [] found within ARGS_NAMES:filter[]: filter[]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrz6aChfbWW0CZ_hqJ7wAAAMc"]
[Tue Jul 28 01:37:51.169475 2026] [:error] [pid 12380:tid 140706970572544] [client 104.23.199.89:12648] [client 104.23.199.89] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:SERVER[REQUEST_METHOD]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [REQUEST_METHOD] found within ARGS_NAMES:SERVER[REQUEST_METHOD]: SERVER[REQUEST_METHOD]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfrz6aChfbWW0CZ_hqJ7wAAAMc"]
[Tue Jul 28 01:37:53.022425 2026] [:error] [pid 12380:tid 140706911823616] [client 172.70.216.82:9835] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfr0aaChfbWW0CZ_hqJ-QAAAM4"]
[Tue Jul 28 01:37:53.023289 2026] [:error] [pid 12380:tid 140706911823616] [client 172.70.216.82:9835] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfr0aaChfbWW0CZ_hqJ-QAAAM4"]
[Tue Jul 28 01:37:53.023585 2026] [:error] [pid 12380:tid 140706911823616] [client 172.70.216.82:9835] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/x-www-form-urlencoded|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfr0aaChfbWW0CZ_hqJ-QAAAM4"]
[Tue Jul 28 01:37:53.023931 2026] [:error] [pid 12380:tid 140706911823616] [client 172.70.216.82:9835] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:filter[] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:filter[]=filter[]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfr0aaChfbWW0CZ_hqJ-QAAAM4"]
[Tue Jul 28 01:37:53.023969 2026] [:error] [pid 12380:tid 140706911823616] [client 172.70.216.82:9835] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in ARGS_NAMES:SERVER[REQUEST_METHOD] outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS_NAMES:SERVER[REQUEST_METHOD]=SERVER[REQUEST_METHOD]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfr0aaChfbWW0CZ_hqJ-QAAAM4"]
[Tue Jul 28 01:37:53.024000 2026] [:error] [pid 12380:tid 140706911823616] [client 172.70.216.82:9835] [client 172.70.216.82] ModSecurity: Warning. Found 4 byte(s) in REQUEST_BODY outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "REQUEST_BODY=_method=__construct&filter[]=phpinfo&method=get&SERVER[REQUEST_METHOD]=pwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfr0aaChfbWW0CZ_hqJ-QAAAM4"]
[Tue Jul 28 01:37:53.024065 2026] [:error] [pid 12380:tid 140706911823616] [client 172.70.216.82:9835] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfr0aaChfbWW0CZ_hqJ-QAAAM4"]
[Tue Jul 28 01:37:53.025772 2026] [:error] [pid 12380:tid 140706911823616] [client 172.70.216.82:9835] [client 172.70.216.82] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:filter[]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [] found within ARGS_NAMES:filter[]: filter[]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfr0aaChfbWW0CZ_hqJ-QAAAM4"]
[Tue Jul 28 01:37:53.025889 2026] [:error] [pid 12380:tid 140706911823616] [client 172.70.216.82:9835] [client 172.70.216.82] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS_NAMES:SERVER[REQUEST_METHOD]. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [REQUEST_METHOD] found within ARGS_NAMES:SERVER[REQUEST_METHOD]: SERVER[REQUEST_METHOD]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/index.php"] [unique_id "amfr0aaChfbWW0CZ_hqJ-QAAAM4"]
[Tue Jul 28 01:42:38.781572 2026] [:error] [pid 24106:tid 140707004143360] [client 104.23.243.19:9587] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amfs7js8oMu6f6EYbxTczgAAAUM"]
[Tue Jul 28 01:42:38.782829 2026] [:error] [pid 24106:tid 140707004143360] [client 104.23.243.19:9587] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amfs7js8oMu6f6EYbxTczgAAAUM"]
[Tue Jul 28 01:42:38.783349 2026] [:error] [pid 24106:tid 140707004143360] [client 104.23.243.19:9587] [client 104.23.243.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amfs7js8oMu6f6EYbxTczgAAAUM"]
[Tue Jul 28 01:55:48.614822 2026] [:error] [pid 21545:tid 140706962179840] [client 172.70.242.202:13275] [client 172.70.242.202] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfwBJhXfYDIcpslIWMH0wAAAYg"]
[Tue Jul 28 01:55:48.615765 2026] [:error] [pid 21545:tid 140706962179840] [client 172.70.242.202:13275] [client 172.70.242.202] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfwBJhXfYDIcpslIWMH0wAAAYg"]
[Tue Jul 28 01:55:48.616206 2026] [:error] [pid 21545:tid 140706962179840] [client 172.70.242.202:13275] [client 172.70.242.202] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amfwBJhXfYDIcpslIWMH0wAAAYg"]
[Tue Jul 28 02:28:45.680472 2026] [:error] [pid 21545:tid 140706903430912] [client 104.23.166.83:12404] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amf3vZhXfYDIcpslIWMujgAAAY8"]
[Tue Jul 28 02:28:45.681372 2026] [:error] [pid 21545:tid 140706903430912] [client 104.23.166.83:12404] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amf3vZhXfYDIcpslIWMujgAAAY8"]
[Tue Jul 28 02:28:45.681841 2026] [:error] [pid 21545:tid 140706903430912] [client 104.23.166.83:12404] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amf3vZhXfYDIcpslIWMujgAAAY8"]
[Tue Jul 28 02:50:17.609638 2026] [:error] [pid 24106:tid 140707004143360] [client 104.23.243.19:10668] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amf8yTs8oMu6f6EYbxTomgAAAUM"]
[Tue Jul 28 02:50:17.616288 2026] [:error] [pid 24106:tid 140707004143360] [client 104.23.243.19:10668] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amf8yTs8oMu6f6EYbxTomgAAAUM"]
[Tue Jul 28 02:50:17.616766 2026] [:error] [pid 24106:tid 140707004143360] [client 104.23.243.19:10668] [client 104.23.243.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amf8yTs8oMu6f6EYbxTomgAAAUM"]
[Tue Jul 28 02:50:18.055527 2026] [:error] [pid 21545:tid 140706945394432] [client 104.23.243.181:11126] [client 104.23.243.181] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amf8yphXfYDIcpslIWNEbwAAAYo"]
[Tue Jul 28 02:50:18.056398 2026] [:error] [pid 21545:tid 140706945394432] [client 104.23.243.181:11126] [client 104.23.243.181] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amf8yphXfYDIcpslIWNEbwAAAYo"]
[Tue Jul 28 02:50:18.056937 2026] [:error] [pid 21545:tid 140706945394432] [client 104.23.243.181:11126] [client 104.23.243.181] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amf8yphXfYDIcpslIWNEbwAAAYo"]
[Tue Jul 28 02:55:14.025726 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amf98hwjcb8HQE21kA4QeAAAAIc"]
[Tue Jul 28 02:55:14.026745 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amf98hwjcb8HQE21kA4QeAAAAIc"]
[Tue Jul 28 02:55:14.027277 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amf98hwjcb8HQE21kA4QeAAAAIc"]
[Tue Jul 28 02:55:14.219986 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amf98hwjcb8HQE21kA4QegAAAIo"]
[Tue Jul 28 02:55:14.220699 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amf98hwjcb8HQE21kA4QegAAAIo"]
[Tue Jul 28 02:55:14.222407 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amf98hwjcb8HQE21kA4QegAAAIo"]
[Tue Jul 28 02:55:14.222620 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amf98hwjcb8HQE21kA4QegAAAIo"]
[Tue Jul 28 02:55:14.467709 2026] [:error] [pid 12277:tid 140706886645504] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amf98hwjcb8HQE21kA4QfAAAAJE"]
[Tue Jul 28 02:55:14.468615 2026] [:error] [pid 12277:tid 140706886645504] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amf98hwjcb8HQE21kA4QfAAAAJE"]
[Tue Jul 28 02:55:14.468937 2026] [:error] [pid 12277:tid 140706886645504] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/x-www-form-urlencoded|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amf98hwjcb8HQE21kA4QfAAAAJE"]
[Tue Jul 28 02:55:14.469268 2026] [:error] [pid 12277:tid 140706886645504] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amf98hwjcb8HQE21kA4QfAAAAJE"]
[Tue Jul 28 02:55:14.640251 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amf98hwjcb8HQE21kA4QfQAAAIw"]
[Tue Jul 28 02:55:14.641087 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amf98hwjcb8HQE21kA4QfQAAAIw"]
[Tue Jul 28 02:55:14.641647 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amf98hwjcb8HQE21kA4QfQAAAIw"]
[Tue Jul 28 02:55:14.641882 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amf98hwjcb8HQE21kA4QfQAAAIw"]
[Tue Jul 28 02:55:14.850274 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amf98hwjcb8HQE21kA4QgAAAAJY"]
[Tue Jul 28 02:55:14.851007 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amf98hwjcb8HQE21kA4QgAAAAJY"]
[Tue Jul 28 02:55:14.851452 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amf98hwjcb8HQE21kA4QgAAAAJY"]
[Tue Jul 28 02:55:14.851612 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amf98hwjcb8HQE21kA4QgAAAAJY"]
[Tue Jul 28 02:55:15.035090 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amf98xwjcb8HQE21kA4QggAAAI8"]
[Tue Jul 28 02:55:15.035820 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amf98xwjcb8HQE21kA4QggAAAI8"]
[Tue Jul 28 02:55:15.036214 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amf98xwjcb8HQE21kA4QggAAAI8"]
[Tue Jul 28 02:55:15.036376 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amf98xwjcb8HQE21kA4QggAAAI8"]
[Tue Jul 28 02:55:15.226601 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amf98xwjcb8HQE21kA4QhAAAAIA"]
[Tue Jul 28 02:55:15.228011 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amf98xwjcb8HQE21kA4QhAAAAIA"]
[Tue Jul 28 02:55:15.228488 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amf98xwjcb8HQE21kA4QhAAAAIA"]
[Tue Jul 28 02:55:15.228718 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amf98xwjcb8HQE21kA4QhAAAAIA"]
[Tue Jul 28 02:55:15.413784 2026] [:error] [pid 12277:tid 140706978965248] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amf98xwjcb8HQE21kA4QhQAAAIY"]
[Tue Jul 28 02:55:15.414645 2026] [:error] [pid 12277:tid 140706978965248] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amf98xwjcb8HQE21kA4QhQAAAIY"]
[Tue Jul 28 02:55:15.415174 2026] [:error] [pid 12277:tid 140706978965248] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amf98xwjcb8HQE21kA4QhQAAAIY"]
[Tue Jul 28 02:55:15.415441 2026] [:error] [pid 12277:tid 140706978965248] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amf98xwjcb8HQE21kA4QhQAAAIY"]
[Tue Jul 28 02:55:15.602400 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amf98xwjcb8HQE21kA4QiAAAAIk"]
[Tue Jul 28 02:55:15.603015 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amf98xwjcb8HQE21kA4QiAAAAIk"]
[Tue Jul 28 02:55:15.603457 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amf98xwjcb8HQE21kA4QiAAAAIk"]
[Tue Jul 28 02:55:15.603671 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amf98xwjcb8HQE21kA4QiAAAAIk"]
[Tue Jul 28 02:55:15.790766 2026] [:error] [pid 12277:tid 140706987357952] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "amf98xwjcb8HQE21kA4QiQAAAIU"]
[Tue Jul 28 02:55:15.791587 2026] [:error] [pid 12277:tid 140706987357952] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "amf98xwjcb8HQE21kA4QiQAAAIU"]
[Tue Jul 28 02:55:15.792105 2026] [:error] [pid 12277:tid 140706987357952] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "amf98xwjcb8HQE21kA4QiQAAAIU"]
[Tue Jul 28 02:55:15.792339 2026] [:error] [pid 12277:tid 140706987357952] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "amf98xwjcb8HQE21kA4QiQAAAIU"]
[Tue Jul 28 02:55:15.978884 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amf98xwjcb8HQE21kA4QiwAAAJg"]
[Tue Jul 28 02:55:15.979502 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amf98xwjcb8HQE21kA4QiwAAAJg"]
[Tue Jul 28 02:55:15.979890 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amf98xwjcb8HQE21kA4QiwAAAJg"]
[Tue Jul 28 02:55:15.980044 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amf98xwjcb8HQE21kA4QiwAAAJg"]
[Tue Jul 28 02:55:16.187929 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amf99Bwjcb8HQE21kA4QjQAAAIc"]
[Tue Jul 28 02:55:16.188838 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amf99Bwjcb8HQE21kA4QjQAAAIc"]
[Tue Jul 28 02:55:16.189393 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amf99Bwjcb8HQE21kA4QjQAAAIc"]
[Tue Jul 28 02:55:16.189665 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amf99Bwjcb8HQE21kA4QjQAAAIc"]
[Tue Jul 28 02:55:16.388201 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amf99Bwjcb8HQE21kA4QjwAAAIo"]
[Tue Jul 28 02:55:16.388912 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amf99Bwjcb8HQE21kA4QjwAAAIo"]
[Tue Jul 28 02:55:16.389324 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amf99Bwjcb8HQE21kA4QjwAAAIo"]
[Tue Jul 28 02:55:16.389481 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amf99Bwjcb8HQE21kA4QjwAAAIo"]
[Tue Jul 28 02:55:16.574516 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amf99Bwjcb8HQE21kA4QkAAAAIg"]
[Tue Jul 28 02:55:16.575336 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amf99Bwjcb8HQE21kA4QkAAAAIg"]
[Tue Jul 28 02:55:16.575897 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amf99Bwjcb8HQE21kA4QkAAAAIg"]
[Tue Jul 28 02:55:16.576141 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amf99Bwjcb8HQE21kA4QkAAAAIg"]
[Tue Jul 28 02:55:16.765826 2026] [:error] [pid 12277:tid 140706836289280] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amf99Bwjcb8HQE21kA4QkgAAAJc"]
[Tue Jul 28 02:55:16.766856 2026] [:error] [pid 12277:tid 140706836289280] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amf99Bwjcb8HQE21kA4QkgAAAJc"]
[Tue Jul 28 02:55:16.767429 2026] [:error] [pid 12277:tid 140706836289280] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amf99Bwjcb8HQE21kA4QkgAAAJc"]
[Tue Jul 28 02:55:16.767709 2026] [:error] [pid 12277:tid 140706836289280] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amf99Bwjcb8HQE21kA4QkgAAAJc"]
[Tue Jul 28 02:55:16.959885 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amf99Bwjcb8HQE21kA4QlAAAAJA"]
[Tue Jul 28 02:55:16.960837 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amf99Bwjcb8HQE21kA4QlAAAAJA"]
[Tue Jul 28 02:55:16.961409 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amf99Bwjcb8HQE21kA4QlAAAAJA"]
[Tue Jul 28 02:55:16.961683 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amf99Bwjcb8HQE21kA4QlAAAAJA"]
[Tue Jul 28 02:55:17.141247 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amf99Rwjcb8HQE21kA4QlQAAAIM"]
[Tue Jul 28 02:55:17.141860 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amf99Rwjcb8HQE21kA4QlQAAAIM"]
[Tue Jul 28 02:55:17.142223 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amf99Rwjcb8HQE21kA4QlQAAAIM"]
[Tue Jul 28 02:55:17.142394 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amf99Rwjcb8HQE21kA4QlQAAAIM"]
[Tue Jul 28 02:55:17.339423 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amf99Rwjcb8HQE21kA4QlgAAAJY"]
[Tue Jul 28 02:55:17.340246 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amf99Rwjcb8HQE21kA4QlgAAAJY"]
[Tue Jul 28 02:55:17.340789 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amf99Rwjcb8HQE21kA4QlgAAAJY"]
[Tue Jul 28 02:55:17.341024 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amf99Rwjcb8HQE21kA4QlgAAAJY"]
[Tue Jul 28 02:55:17.524846 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amf99Rwjcb8HQE21kA4QmAAAAIQ"]
[Tue Jul 28 02:55:17.525794 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amf99Rwjcb8HQE21kA4QmAAAAIQ"]
[Tue Jul 28 02:55:17.526381 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amf99Rwjcb8HQE21kA4QmAAAAIQ"]
[Tue Jul 28 02:55:17.526649 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amf99Rwjcb8HQE21kA4QmAAAAIQ"]
[Tue Jul 28 02:55:17.708369 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "amf99Rwjcb8HQE21kA4QmgAAAIs"]
[Tue Jul 28 02:55:17.708965 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "amf99Rwjcb8HQE21kA4QmgAAAIs"]
[Tue Jul 28 02:55:17.709343 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "amf99Rwjcb8HQE21kA4QmgAAAIs"]
[Tue Jul 28 02:55:17.709501 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.ci"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "amf99Rwjcb8HQE21kA4QmgAAAIs"]
[Tue Jul 28 02:55:17.892282 2026] [:error] [pid 12277:tid 140706869860096] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "amf99Rwjcb8HQE21kA4QmwAAAJM"]
[Tue Jul 28 02:55:17.892880 2026] [:error] [pid 12277:tid 140706869860096] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "amf99Rwjcb8HQE21kA4QmwAAAJM"]
[Tue Jul 28 02:55:17.893239 2026] [:error] [pid 12277:tid 140706869860096] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "amf99Rwjcb8HQE21kA4QmwAAAJM"]
[Tue Jul 28 02:55:17.893396 2026] [:error] [pid 12277:tid 140706869860096] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.docker"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "amf99Rwjcb8HQE21kA4QmwAAAJM"]
[Tue Jul 28 02:55:18.080296 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amf99hwjcb8HQE21kA4QnAAAAI0"]
[Tue Jul 28 02:55:18.081167 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amf99hwjcb8HQE21kA4QnAAAAI0"]
[Tue Jul 28 02:55:18.081664 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amf99hwjcb8HQE21kA4QnAAAAI0"]
[Tue Jul 28 02:55:18.081918 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.live"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amf99hwjcb8HQE21kA4QnAAAAI0"]
[Tue Jul 28 02:55:18.344705 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "amf99hwjcb8HQE21kA4QoQAAAJg"]
[Tue Jul 28 02:55:18.345666 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "amf99hwjcb8HQE21kA4QoQAAAJg"]
[Tue Jul 28 02:55:18.346236 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "amf99hwjcb8HQE21kA4QoQAAAJg"]
[Tue Jul 28 02:55:18.346512 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.preprod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "amf99hwjcb8HQE21kA4QoQAAAJg"]
[Tue Jul 28 02:55:18.532595 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "amf99hwjcb8HQE21kA4QogAAAIE"]
[Tue Jul 28 02:55:18.533428 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "amf99hwjcb8HQE21kA4QogAAAIE"]
[Tue Jul 28 02:55:18.533981 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "amf99hwjcb8HQE21kA4QogAAAIE"]
[Tue Jul 28 02:55:18.534221 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.uat"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "amf99hwjcb8HQE21kA4QogAAAIE"]
[Tue Jul 28 02:55:18.717635 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amf99hwjcb8HQE21kA4QowAAAIc"]
[Tue Jul 28 02:55:18.718695 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amf99hwjcb8HQE21kA4QowAAAIc"]
[Tue Jul 28 02:55:18.719231 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amf99hwjcb8HQE21kA4QowAAAIc"]
[Tue Jul 28 02:55:18.719487 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amf99hwjcb8HQE21kA4QowAAAIc"]
[Tue Jul 28 02:55:18.901588 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amf99hwjcb8HQE21kA4QpAAAAII"]
[Tue Jul 28 02:55:18.902417 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amf99hwjcb8HQE21kA4QpAAAAII"]
[Tue Jul 28 02:55:18.902957 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amf99hwjcb8HQE21kA4QpAAAAII"]
[Tue Jul 28 02:55:18.903196 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amf99hwjcb8HQE21kA4QpAAAAII"]
[Tue Jul 28 02:55:19.093507 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "amf99xwjcb8HQE21kA4QpgAAAIg"]
[Tue Jul 28 02:55:19.094093 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "amf99xwjcb8HQE21kA4QpgAAAIg"]
[Tue Jul 28 02:55:19.094314 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Pattern match "\\\\.[^.~]+~(?:/.*|)$" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1060"] [id "920500"] [msg "Attempt to access a backup or working file"] [data ".env~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "amf99xwjcb8HQE21kA4QpgAAAIg"]
[Tue Jul 28 02:55:19.094572 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "amf99xwjcb8HQE21kA4QpgAAAIg"]
[Tue Jul 28 02:55:19.094721 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "amf99xwjcb8HQE21kA4QpgAAAIg"]
[Tue Jul 28 02:55:19.279567 2026] [:error] [pid 12277:tid 140706836289280] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env1"] [unique_id "amf99xwjcb8HQE21kA4QqAAAAJc"]
[Tue Jul 28 02:55:19.280083 2026] [:error] [pid 12277:tid 140706836289280] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env1"] [unique_id "amf99xwjcb8HQE21kA4QqAAAAJc"]
[Tue Jul 28 02:55:19.280429 2026] [:error] [pid 12277:tid 140706836289280] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env1"] [unique_id "amf99xwjcb8HQE21kA4QqAAAAJc"]
[Tue Jul 28 02:55:19.280601 2026] [:error] [pid 12277:tid 140706836289280] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env1"] [unique_id "amf99xwjcb8HQE21kA4QqAAAAJc"]
[Tue Jul 28 02:55:19.465542 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env2"] [unique_id "amf99xwjcb8HQE21kA4QqQAAAJA"]
[Tue Jul 28 02:55:19.466389 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env2"] [unique_id "amf99xwjcb8HQE21kA4QqQAAAJA"]
[Tue Jul 28 02:55:19.466930 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env2"] [unique_id "amf99xwjcb8HQE21kA4QqQAAAJA"]
[Tue Jul 28 02:55:19.467173 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env2"] [unique_id "amf99xwjcb8HQE21kA4QqQAAAJA"]
[Tue Jul 28 02:55:19.653399 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amf99xwjcb8HQE21kA4QqwAAAIM"]
[Tue Jul 28 02:55:19.654336 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amf99xwjcb8HQE21kA4QqwAAAIM"]
[Tue Jul 28 02:55:19.654909 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amf99xwjcb8HQE21kA4QqwAAAIM"]
[Tue Jul 28 02:55:19.655119 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_copy"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amf99xwjcb8HQE21kA4QqwAAAIM"]
[Tue Jul 28 02:55:19.838240 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amf99xwjcb8HQE21kA4QrQAAAJY"]
[Tue Jul 28 02:55:19.839169 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amf99xwjcb8HQE21kA4QrQAAAJY"]
[Tue Jul 28 02:55:19.839788 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amf99xwjcb8HQE21kA4QrQAAAJY"]
[Tue Jul 28 02:55:19.840028 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.txt"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amf99xwjcb8HQE21kA4QrQAAAJY"]
[Tue Jul 28 02:55:20.039660 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.json"] [unique_id "amf9-Bwjcb8HQE21kA4QrgAAAIw"]
[Tue Jul 28 02:55:20.040538 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.json"] [unique_id "amf9-Bwjcb8HQE21kA4QrgAAAIw"]
[Tue Jul 28 02:55:20.041151 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.json"] [unique_id "amf9-Bwjcb8HQE21kA4QrgAAAIw"]
[Tue Jul 28 02:55:20.041404 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.json"] [unique_id "amf9-Bwjcb8HQE21kA4QrgAAAIw"]
[Tue Jul 28 02:55:20.225610 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "amf9-Bwjcb8HQE21kA4QsAAAAIs"]
[Tue Jul 28 02:55:20.226495 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "amf9-Bwjcb8HQE21kA4QsAAAAIs"]
[Tue Jul 28 02:55:20.227012 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "amf9-Bwjcb8HQE21kA4QsAAAAIs"]
[Tue Jul 28 02:55:20.227240 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yaml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "amf9-Bwjcb8HQE21kA4QsAAAAIs"]
[Tue Jul 28 02:55:20.410540 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "amf9-Bwjcb8HQE21kA4QsgAAAI4"]
[Tue Jul 28 02:55:20.411420 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "amf9-Bwjcb8HQE21kA4QsgAAAI4"]
[Tue Jul 28 02:55:20.411852 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "amf9-Bwjcb8HQE21kA4QsgAAAI4"]
[Tue Jul 28 02:55:20.412001 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "amf9-Bwjcb8HQE21kA4QsgAAAI4"]
[Tue Jul 28 02:55:20.660055 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amf9-Bwjcb8HQE21kA4QtAAAAI8"]
[Tue Jul 28 02:55:20.660910 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amf9-Bwjcb8HQE21kA4QtAAAAI8"]
[Tue Jul 28 02:55:20.661529 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amf9-Bwjcb8HQE21kA4QtAAAAI8"]
[Tue Jul 28 02:55:20.661823 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amf9-Bwjcb8HQE21kA4QtAAAAI8"]
[Tue Jul 28 02:55:20.845258 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "amf9-Bwjcb8HQE21kA4QtQAAAI0"]
[Tue Jul 28 02:55:20.846037 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "amf9-Bwjcb8HQE21kA4QtQAAAI0"]
[Tue Jul 28 02:55:20.846450 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "amf9-Bwjcb8HQE21kA4QtQAAAI0"]
[Tue Jul 28 02:55:20.846679 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "amf9-Bwjcb8HQE21kA4QtQAAAI0"]
[Tue Jul 28 02:55:21.032488 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QtgAAAJg"]
[Tue Jul 28 02:55:21.033283 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QtgAAAJg"]
[Tue Jul 28 02:55:21.033791 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QtgAAAJg"]
[Tue Jul 28 02:55:21.034019 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QtgAAAJg"]
[Tue Jul 28 02:55:21.215840 2026] [:error] [pid 12277:tid 140706978965248] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QuAAAAIY"]
[Tue Jul 28 02:55:21.216826 2026] [:error] [pid 12277:tid 140706978965248] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QuAAAAIY"]
[Tue Jul 28 02:55:21.217414 2026] [:error] [pid 12277:tid 140706978965248] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QuAAAAIY"]
[Tue Jul 28 02:55:21.217684 2026] [:error] [pid 12277:tid 140706978965248] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QuAAAAIY"]
[Tue Jul 28 02:55:21.398611 2026] [:error] [pid 12277:tid 140706861467392] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/site/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QuwAAAJQ"]
[Tue Jul 28 02:55:21.399452 2026] [:error] [pid 12277:tid 140706861467392] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/site/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QuwAAAJQ"]
[Tue Jul 28 02:55:21.400007 2026] [:error] [pid 12277:tid 140706861467392] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/site/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QuwAAAJQ"]
[Tue Jul 28 02:55:21.400253 2026] [:error] [pid 12277:tid 140706861467392] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/site/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QuwAAAJQ"]
[Tue Jul 28 02:55:21.580445 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QvAAAAII"]
[Tue Jul 28 02:55:21.581111 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QvAAAAII"]
[Tue Jul 28 02:55:21.581570 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QvAAAAII"]
[Tue Jul 28 02:55:21.581814 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QvAAAAII"]
[Tue Jul 28 02:55:21.780124 2026] [:error] [pid 12277:tid 140706836289280] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QvgAAAJc"]
[Tue Jul 28 02:55:21.781027 2026] [:error] [pid 12277:tid 140706836289280] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QvgAAAJc"]
[Tue Jul 28 02:55:21.781470 2026] [:error] [pid 12277:tid 140706836289280] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QvgAAAJc"]
[Tue Jul 28 02:55:21.781643 2026] [:error] [pid 12277:tid 140706836289280] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QvgAAAJc"]
[Tue Jul 28 02:55:21.963442 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QwAAAAIo"]
[Tue Jul 28 02:55:21.964187 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QwAAAAIo"]
[Tue Jul 28 02:55:21.964715 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QwAAAAIo"]
[Tue Jul 28 02:55:21.964959 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amf9-Rwjcb8HQE21kA4QwAAAAIo"]
[Tue Jul 28 02:55:22.146211 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amf9-hwjcb8HQE21kA4QwQAAAIM"]
[Tue Jul 28 02:55:22.146791 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amf9-hwjcb8HQE21kA4QwQAAAIM"]
[Tue Jul 28 02:55:22.147227 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amf9-hwjcb8HQE21kA4QwQAAAIM"]
[Tue Jul 28 02:55:22.147450 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amf9-hwjcb8HQE21kA4QwQAAAIM"]
[Tue Jul 28 02:55:22.336266 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amf9-hwjcb8HQE21kA4QwwAAAJY"]
[Tue Jul 28 02:55:22.336898 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amf9-hwjcb8HQE21kA4QwwAAAJY"]
[Tue Jul 28 02:55:22.337292 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amf9-hwjcb8HQE21kA4QwwAAAJY"]
[Tue Jul 28 02:55:22.337467 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /frontend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amf9-hwjcb8HQE21kA4QwwAAAJY"]
[Tue Jul 28 02:55:22.518149 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amf9-hwjcb8HQE21kA4QxQAAAIw"]
[Tue Jul 28 02:55:22.518780 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amf9-hwjcb8HQE21kA4QxQAAAIw"]
[Tue Jul 28 02:55:22.519094 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amf9-hwjcb8HQE21kA4QxQAAAIw"]
[Tue Jul 28 02:55:22.519265 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amf9-hwjcb8HQE21kA4QxQAAAIw"]
[Tue Jul 28 02:55:22.712415 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amf9-hwjcb8HQE21kA4QxwAAAIs"]
[Tue Jul 28 02:55:22.713245 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amf9-hwjcb8HQE21kA4QxwAAAIs"]
[Tue Jul 28 02:55:22.713810 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amf9-hwjcb8HQE21kA4QxwAAAIs"]
[Tue Jul 28 02:55:22.714065 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amf9-hwjcb8HQE21kA4QxwAAAIs"]
[Tue Jul 28 02:55:22.909588 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "amf9-hwjcb8HQE21kA4QyQAAAI4"]
[Tue Jul 28 02:55:22.910487 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "amf9-hwjcb8HQE21kA4QyQAAAI4"]
[Tue Jul 28 02:55:22.911099 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "amf9-hwjcb8HQE21kA4QyQAAAI4"]
[Tue Jul 28 02:55:22.911337 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "amf9-hwjcb8HQE21kA4QyQAAAI4"]
[Tue Jul 28 02:55:23.100374 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amf9-xwjcb8HQE21kA4QygAAAI8"]
[Tue Jul 28 02:55:23.100982 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amf9-xwjcb8HQE21kA4QygAAAI8"]
[Tue Jul 28 02:55:23.101409 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amf9-xwjcb8HQE21kA4QygAAAI8"]
[Tue Jul 28 02:55:23.101604 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amf9-xwjcb8HQE21kA4QygAAAI8"]
[Tue Jul 28 02:55:23.289248 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amf9-xwjcb8HQE21kA4QzAAAAI0"]
[Tue Jul 28 02:55:23.290303 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amf9-xwjcb8HQE21kA4QzAAAAI0"]
[Tue Jul 28 02:55:23.290909 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amf9-xwjcb8HQE21kA4QzAAAAI0"]
[Tue Jul 28 02:55:23.291304 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /private/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amf9-xwjcb8HQE21kA4QzAAAAI0"]
[Tue Jul 28 02:55:23.475642 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amf9-xwjcb8HQE21kA4QzQAAAJg"]
[Tue Jul 28 02:55:23.476521 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amf9-xwjcb8HQE21kA4QzQAAAJg"]
[Tue Jul 28 02:55:23.477410 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amf9-xwjcb8HQE21kA4QzQAAAJg"]
[Tue Jul 28 02:55:23.477673 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amf9-xwjcb8HQE21kA4QzQAAAJg"]
[Tue Jul 28 02:55:23.661032 2026] [:error] [pid 12277:tid 140706861467392] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "amf9-xwjcb8HQE21kA4QzwAAAJQ"]
[Tue Jul 28 02:55:23.662306 2026] [:error] [pid 12277:tid 140706861467392] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "amf9-xwjcb8HQE21kA4QzwAAAJQ"]
[Tue Jul 28 02:55:23.662984 2026] [:error] [pid 12277:tid 140706861467392] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "amf9-xwjcb8HQE21kA4QzwAAAJQ"]
[Tue Jul 28 02:55:23.663258 2026] [:error] [pid 12277:tid 140706861467392] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /bootstrap/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "amf9-xwjcb8HQE21kA4QzwAAAJQ"]
[Tue Jul 28 02:55:23.845863 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/database/.env"] [unique_id "amf9-xwjcb8HQE21kA4Q0gAAAIE"]
[Tue Jul 28 02:55:23.846800 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/database/.env"] [unique_id "amf9-xwjcb8HQE21kA4Q0gAAAIE"]
[Tue Jul 28 02:55:23.847359 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/database/.env"] [unique_id "amf9-xwjcb8HQE21kA4Q0gAAAIE"]
[Tue Jul 28 02:55:23.847661 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/database/.env"] [unique_id "amf9-xwjcb8HQE21kA4Q0gAAAIE"]
[Tue Jul 28 02:55:24.039535 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q0wAAAIc"]
[Tue Jul 28 02:55:24.040401 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q0wAAAIc"]
[Tue Jul 28 02:55:24.040930 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q0wAAAIc"]
[Tue Jul 28 02:55:24.041171 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q0wAAAIc"]
[Tue Jul 28 02:55:24.227783 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q1gAAAIo"]
[Tue Jul 28 02:55:24.228732 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q1gAAAIo"]
[Tue Jul 28 02:55:24.229286 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q1gAAAIo"]
[Tue Jul 28 02:55:24.229570 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /var/www/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q1gAAAIo"]
[Tue Jul 28 02:55:24.413181 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q2QAAAIg"]
[Tue Jul 28 02:55:24.413728 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q2QAAAIg"]
[Tue Jul 28 02:55:24.414185 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q2QAAAIg"]
[Tue Jul 28 02:55:24.414420 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /var/www/html/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q2QAAAIg"]
[Tue Jul 28 02:55:24.620444 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/current/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q2gAAAIw"]
[Tue Jul 28 02:55:24.621227 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/current/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q2gAAAIw"]
[Tue Jul 28 02:55:24.621633 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/current/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q2gAAAIw"]
[Tue Jul 28 02:55:24.621807 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /current/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/current/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q2gAAAIw"]
[Tue Jul 28 02:55:24.805085 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/release/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q3AAAAI4"]
[Tue Jul 28 02:55:24.806144 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/release/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q3AAAAI4"]
[Tue Jul 28 02:55:24.806756 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/release/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q3AAAAI4"]
[Tue Jul 28 02:55:24.807014 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /release/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/release/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q3AAAAI4"]
[Tue Jul 28 02:55:24.989593 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q3QAAAIk"]
[Tue Jul 28 02:55:24.990455 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q3QAAAIk"]
[Tue Jul 28 02:55:24.991023 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q3QAAAIk"]
[Tue Jul 28 02:55:24.991267 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /releases/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "amf9_Bwjcb8HQE21kA4Q3QAAAIk"]
[Tue Jul 28 02:55:25.173683 2026] [:error] [pid 12277:tid 140706878252800] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q3wAAAJI"]
[Tue Jul 28 02:55:25.174438 2026] [:error] [pid 12277:tid 140706878252800] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q3wAAAJI"]
[Tue Jul 28 02:55:25.174970 2026] [:error] [pid 12277:tid 140706878252800] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q3wAAAJI"]
[Tue Jul 28 02:55:25.175208 2026] [:error] [pid 12277:tid 140706878252800] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /shared/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q3wAAAJI"]
[Tue Jul 28 02:55:25.366084 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q4QAAAJg"]
[Tue Jul 28 02:55:25.367022 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q4QAAAJg"]
[Tue Jul 28 02:55:25.367633 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q4QAAAJg"]
[Tue Jul 28 02:55:25.367901 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /deploy/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q4QAAAJg"]
[Tue Jul 28 02:55:25.551574 2026] [:error] [pid 12277:tid 140706886645504] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/build/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q4gAAAJE"]
[Tue Jul 28 02:55:25.552381 2026] [:error] [pid 12277:tid 140706886645504] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/build/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q4gAAAJE"]
[Tue Jul 28 02:55:25.552919 2026] [:error] [pid 12277:tid 140706886645504] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/build/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q4gAAAJE"]
[Tue Jul 28 02:55:25.553163 2026] [:error] [pid 12277:tid 140706886645504] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /build/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/build/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q4gAAAJE"]
[Tue Jul 28 02:55:25.746679 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q5AAAAIE"]
[Tue Jul 28 02:55:25.747318 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q5AAAAIE"]
[Tue Jul 28 02:55:25.747739 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q5AAAAIE"]
[Tue Jul 28 02:55:25.747909 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /dist/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q5AAAAIE"]
[Tue Jul 28 02:55:25.935298 2026] [:error] [pid 12277:tid 140706869860096] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q5QAAAJM"]
[Tue Jul 28 02:55:25.936122 2026] [:error] [pid 12277:tid 140706869860096] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q5QAAAJM"]
[Tue Jul 28 02:55:25.936683 2026] [:error] [pid 12277:tid 140706869860096] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q5QAAAJM"]
[Tue Jul 28 02:55:25.936927 2026] [:error] [pid 12277:tid 140706869860096] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public_html/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "amf9_Rwjcb8HQE21kA4Q5QAAAJM"]
[Tue Jul 28 02:55:26.117944 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q5gAAAIA"]
[Tue Jul 28 02:55:26.118741 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q5gAAAIA"]
[Tue Jul 28 02:55:26.119247 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q5gAAAIA"]
[Tue Jul 28 02:55:26.119508 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /htdocs/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q5gAAAIA"]
[Tue Jul 28 02:55:26.303217 2026] [:error] [pid 12277:tid 140706853074688] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/www/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q5wAAAJU"]
[Tue Jul 28 02:55:26.303886 2026] [:error] [pid 12277:tid 140706853074688] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/www/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q5wAAAJU"]
[Tue Jul 28 02:55:26.304279 2026] [:error] [pid 12277:tid 140706853074688] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/www/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q5wAAAJU"]
[Tue Jul 28 02:55:26.304463 2026] [:error] [pid 12277:tid 140706853074688] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /www/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/www/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q5wAAAJU"]
[Tue Jul 28 02:55:26.485428 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/html/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q6AAAAIQ"]
[Tue Jul 28 02:55:26.486188 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/html/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q6AAAAIQ"]
[Tue Jul 28 02:55:26.486733 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/html/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q6AAAAIQ"]
[Tue Jul 28 02:55:26.486964 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /html/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/html/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q6AAAAIQ"]
[Tue Jul 28 02:55:26.667751 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/live/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q6wAAAIo"]
[Tue Jul 28 02:55:26.668536 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/live/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q6wAAAIo"]
[Tue Jul 28 02:55:26.669023 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/live/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q6wAAAIo"]
[Tue Jul 28 02:55:26.669263 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /live/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/live/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q6wAAAIo"]
[Tue Jul 28 02:55:26.853242 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q7AAAAII"]
[Tue Jul 28 02:55:26.854018 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q7AAAAII"]
[Tue Jul 28 02:55:26.854574 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q7AAAAII"]
[Tue Jul 28 02:55:26.854742 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prod/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "amf9_hwjcb8HQE21kA4Q7AAAAII"]
[Tue Jul 28 02:55:27.039676 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q7QAAAJA"]
[Tue Jul 28 02:55:27.040487 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q7QAAAJA"]
[Tue Jul 28 02:55:27.041023 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q7QAAAJA"]
[Tue Jul 28 02:55:27.041264 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /dev/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q7QAAAJA"]
[Tue Jul 28 02:55:27.225601 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q7gAAAIg"]
[Tue Jul 28 02:55:27.226439 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q7gAAAIg"]
[Tue Jul 28 02:55:27.226965 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q7gAAAIg"]
[Tue Jul 28 02:55:27.227215 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /staging/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q7gAAAIg"]
[Tue Jul 28 02:55:27.412573 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8AAAAI4"]
[Tue Jul 28 02:55:27.413363 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8AAAAI4"]
[Tue Jul 28 02:55:27.413881 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8AAAAI4"]
[Tue Jul 28 02:55:27.414093 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /opt/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8AAAAI4"]
[Tue Jul 28 02:55:27.603325 2026] [:error] [pid 12277:tid 140706987357952] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8QAAAIU"]
[Tue Jul 28 02:55:27.604229 2026] [:error] [pid 12277:tid 140706987357952] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8QAAAIU"]
[Tue Jul 28 02:55:27.604783 2026] [:error] [pid 12277:tid 140706987357952] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8QAAAIU"]
[Tue Jul 28 02:55:27.605042 2026] [:error] [pid 12277:tid 140706987357952] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8QAAAIU"]
[Tue Jul 28 02:55:27.788491 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8gAAAJY"]
[Tue Jul 28 02:55:27.789285 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8gAAAJY"]
[Tue Jul 28 02:55:27.789829 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8gAAAJY"]
[Tue Jul 28 02:55:27.790061 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /symfony/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8gAAAJY"]
[Tue Jul 28 02:55:27.987465 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8wAAAIk"]
[Tue Jul 28 02:55:27.988229 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8wAAAIk"]
[Tue Jul 28 02:55:27.988745 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8wAAAIk"]
[Tue Jul 28 02:55:27.988957 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wordpress/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "amf9_xwjcb8HQE21kA4Q8wAAAIk"]
[Tue Jul 28 02:55:28.170672 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q9QAAAIs"]
[Tue Jul 28 02:55:28.171499 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q9QAAAIs"]
[Tue Jul 28 02:55:28.172041 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q9QAAAIs"]
[Tue Jul 28 02:55:28.172282 2026] [:error] [pid 12277:tid 140706937001728] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q9QAAAIs"]
[Tue Jul 28 02:55:28.354328 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q9gAAAJg"]
[Tue Jul 28 02:55:28.354929 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q9gAAAJg"]
[Tue Jul 28 02:55:28.355294 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q9gAAAJg"]
[Tue Jul 28 02:55:28.355475 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cms/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q9gAAAJg"]
[Tue Jul 28 02:55:28.535953 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q-AAAAI8"]
[Tue Jul 28 02:55:28.536810 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q-AAAAI8"]
[Tue Jul 28 02:55:28.537360 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q-AAAAI8"]
[Tue Jul 28 02:55:28.537620 2026] [:error] [pid 12277:tid 140706903430912] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /drupal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q-AAAAI8"]
[Tue Jul 28 02:55:28.717750 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q-QAAAIE"]
[Tue Jul 28 02:55:28.718635 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q-QAAAIE"]
[Tue Jul 28 02:55:28.719181 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q-QAAAIE"]
[Tue Jul 28 02:55:28.719472 2026] [:error] [pid 12277:tid 140707020928768] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /joomla/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q-QAAAIE"]
[Tue Jul 28 02:55:28.900363 2026] [:error] [pid 12277:tid 140706869860096] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q-wAAAJM"]
[Tue Jul 28 02:55:28.901022 2026] [:error] [pid 12277:tid 140706869860096] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q-wAAAJM"]
[Tue Jul 28 02:55:28.901473 2026] [:error] [pid 12277:tid 140706869860096] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q-wAAAJM"]
[Tue Jul 28 02:55:28.901651 2026] [:error] [pid 12277:tid 140706869860096] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /magento/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "amf-ABwjcb8HQE21kA4Q-wAAAJM"]
[Tue Jul 28 02:55:29.083669 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "amf-ARwjcb8HQE21kA4Q_AAAAIA"]
[Tue Jul 28 02:55:29.084514 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "amf-ARwjcb8HQE21kA4Q_AAAAIA"]
[Tue Jul 28 02:55:29.085081 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "amf-ARwjcb8HQE21kA4Q_AAAAIA"]
[Tue Jul 28 02:55:29.085367 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /shopify/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "amf-ARwjcb8HQE21kA4Q_AAAAIA"]
[Tue Jul 28 02:55:29.267401 2026] [:error] [pid 12277:tid 140706861467392] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "amf-ARwjcb8HQE21kA4Q_QAAAJQ"]
[Tue Jul 28 02:55:29.268283 2026] [:error] [pid 12277:tid 140706861467392] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "amf-ARwjcb8HQE21kA4Q_QAAAJQ"]
[Tue Jul 28 02:55:29.268828 2026] [:error] [pid 12277:tid 140706861467392] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "amf-ARwjcb8HQE21kA4Q_QAAAJQ"]
[Tue Jul 28 02:55:29.269069 2026] [:error] [pid 12277:tid 140706861467392] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prestashop/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "amf-ARwjcb8HQE21kA4Q_QAAAJQ"]
[Tue Jul 28 02:55:29.456620 2026] [:error] [pid 12277:tid 140706853074688] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "amf-ARwjcb8HQE21kA4Q_wAAAJU"]
[Tue Jul 28 02:55:29.457331 2026] [:error] [pid 12277:tid 140706853074688] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "amf-ARwjcb8HQE21kA4Q_wAAAJU"]
[Tue Jul 28 02:55:29.457787 2026] [:error] [pid 12277:tid 140706853074688] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "amf-ARwjcb8HQE21kA4Q_wAAAJU"]
[Tue Jul 28 02:55:29.457970 2026] [:error] [pid 12277:tid 140706853074688] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /codeigniter/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "amf-ARwjcb8HQE21kA4Q_wAAAJU"]
[Tue Jul 28 02:55:29.642788 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "amf-ARwjcb8HQE21kA4RAQAAAIQ"]
[Tue Jul 28 02:55:29.643879 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "amf-ARwjcb8HQE21kA4RAQAAAIQ"]
[Tue Jul 28 02:55:29.644576 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "amf-ARwjcb8HQE21kA4RAQAAAIQ"]
[Tue Jul 28 02:55:29.644824 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cakephp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "amf-ARwjcb8HQE21kA4RAQAAAIQ"]
[Tue Jul 28 02:55:29.825693 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "amf-ARwjcb8HQE21kA4RAgAAAIo"]
[Tue Jul 28 02:55:29.826525 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "amf-ARwjcb8HQE21kA4RAgAAAIo"]
[Tue Jul 28 02:55:29.827062 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "amf-ARwjcb8HQE21kA4RAgAAAIo"]
[Tue Jul 28 02:55:29.827306 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /zend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "amf-ARwjcb8HQE21kA4RAgAAAIo"]
[Tue Jul 28 02:55:30.006862 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RAwAAAII"]
[Tue Jul 28 02:55:30.007694 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RAwAAAII"]
[Tue Jul 28 02:55:30.008081 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RAwAAAII"]
[Tue Jul 28 02:55:30.008231 2026] [:error] [pid 12277:tid 140707012536064] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /yii/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RAwAAAII"]
[Tue Jul 28 02:55:30.187705 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RBAAAAJA"]
[Tue Jul 28 02:55:30.188346 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RBAAAAJA"]
[Tue Jul 28 02:55:30.188746 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RBAAAAJA"]
[Tue Jul 28 02:55:30.188909 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel5/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RBAAAAJA"]
[Tue Jul 28 02:55:30.370699 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RBgAAAIg"]
[Tue Jul 28 02:55:30.371352 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RBgAAAIg"]
[Tue Jul 28 02:55:30.371755 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RBgAAAIg"]
[Tue Jul 28 02:55:30.371910 2026] [:error] [pid 12277:tid 140706962179840] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RBgAAAIg"]
[Tue Jul 28 02:55:30.556741 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RBwAAAI4"]
[Tue Jul 28 02:55:30.557538 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RBwAAAI4"]
[Tue Jul 28 02:55:30.558035 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RBwAAAI4"]
[Tue Jul 28 02:55:30.558264 2026] [:error] [pid 12277:tid 140706911823616] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RBwAAAI4"]
[Tue Jul 28 02:55:30.739988 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RCQAAAIw"]
[Tue Jul 28 02:55:30.740649 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RCQAAAIw"]
[Tue Jul 28 02:55:30.741159 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RCQAAAIw"]
[Tue Jul 28 02:55:30.741412 2026] [:error] [pid 12277:tid 140706928609024] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v3/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RCQAAAIw"]
[Tue Jul 28 02:55:30.927025 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RCwAAAJg"]
[Tue Jul 28 02:55:30.928003 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RCwAAAJg"]
[Tue Jul 28 02:55:30.928607 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RCwAAAJg"]
[Tue Jul 28 02:55:30.928862 2026] [:error] [pid 12277:tid 140706827896576] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "amf-Ahwjcb8HQE21kA4RCwAAAJg"]
[Tue Jul 28 02:55:31.111396 2026] [:error] [pid 12277:tid 140706878252800] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDAAAAJI"]
[Tue Jul 28 02:55:31.112122 2026] [:error] [pid 12277:tid 140706878252800] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDAAAAJI"]
[Tue Jul 28 02:55:31.112643 2026] [:error] [pid 12277:tid 140706878252800] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDAAAAJI"]
[Tue Jul 28 02:55:31.112883 2026] [:error] [pid 12277:tid 140706878252800] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDAAAAJI"]
[Tue Jul 28 02:55:31.294829 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDQAAAIA"]
[Tue Jul 28 02:55:31.295478 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDQAAAIA"]
[Tue Jul 28 02:55:31.295888 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDQAAAIA"]
[Tue Jul 28 02:55:31.296065 2026] [:error] [pid 12277:tid 140707103270656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /rest/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDQAAAIA"]
[Tue Jul 28 02:55:31.490278 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDgAAAI0"]
[Tue Jul 28 02:55:31.491120 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDgAAAI0"]
[Tue Jul 28 02:55:31.491651 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDgAAAI0"]
[Tue Jul 28 02:55:31.491849 2026] [:error] [pid 12277:tid 140706920216320] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /graphql/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDgAAAI0"]
[Tue Jul 28 02:55:31.680052 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDwAAAIQ"]
[Tue Jul 28 02:55:31.680770 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDwAAAIQ"]
[Tue Jul 28 02:55:31.681160 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDwAAAIQ"]
[Tue Jul 28 02:55:31.681327 2026] [:error] [pid 12277:tid 140706995750656] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /gateway/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "amf-Axwjcb8HQE21kA4RDwAAAIQ"]
[Tue Jul 28 02:55:31.862306 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "amf-Axwjcb8HQE21kA4REAAAAIo"]
[Tue Jul 28 02:55:31.862871 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "amf-Axwjcb8HQE21kA4REAAAAIo"]
[Tue Jul 28 02:55:31.863148 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "amf-Axwjcb8HQE21kA4REAAAAIo"]
[Tue Jul 28 02:55:31.863285 2026] [:error] [pid 12277:tid 140706945394432] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /microservice/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "amf-Axwjcb8HQE21kA4REAAAAIo"]
[Tue Jul 28 02:55:32.048712 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/service/.env"] [unique_id "amf-BBwjcb8HQE21kA4REQAAAIM"]
[Tue Jul 28 02:55:32.049453 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/service/.env"] [unique_id "amf-BBwjcb8HQE21kA4REQAAAIM"]
[Tue Jul 28 02:55:32.049874 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/service/.env"] [unique_id "amf-BBwjcb8HQE21kA4REQAAAIM"]
[Tue Jul 28 02:55:32.050037 2026] [:error] [pid 12277:tid 140707004143360] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /service/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/service/.env"] [unique_id "amf-BBwjcb8HQE21kA4REQAAAIM"]
[Tue Jul 28 02:55:32.236753 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "amf-BBwjcb8HQE21kA4REwAAAIc"]
[Tue Jul 28 02:55:32.237660 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "amf-BBwjcb8HQE21kA4REwAAAIc"]
[Tue Jul 28 02:55:32.238182 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "amf-BBwjcb8HQE21kA4REwAAAIc"]
[Tue Jul 28 02:55:32.238448 2026] [:error] [pid 12277:tid 140706970572544] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/v3/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "amf-BBwjcb8HQE21kA4REwAAAIc"]
[Tue Jul 28 02:55:32.418652 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "amf-BBwjcb8HQE21kA4RFAAAAJA"]
[Tue Jul 28 02:55:32.419491 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "amf-BBwjcb8HQE21kA4RFAAAAJA"]
[Tue Jul 28 02:55:32.420049 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "amf-BBwjcb8HQE21kA4RFAAAAJA"]
[Tue Jul 28 02:55:32.420275 2026] [:error] [pid 12277:tid 140706895038208] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/dev/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "amf-BBwjcb8HQE21kA4RFAAAAJA"]
[Tue Jul 28 02:55:32.604181 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "amf-BBwjcb8HQE21kA4RFwAAAJY"]
[Tue Jul 28 02:55:32.605033 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "amf-BBwjcb8HQE21kA4RFwAAAJY"]
[Tue Jul 28 02:55:32.605599 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "amf-BBwjcb8HQE21kA4RFwAAAJY"]
[Tue Jul 28 02:55:32.605869 2026] [:error] [pid 12277:tid 140706844681984] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/staging/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "amf-BBwjcb8HQE21kA4RFwAAAJY"]
[Tue Jul 28 02:55:32.790316 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "amf-BBwjcb8HQE21kA4RGgAAAIk"]
[Tue Jul 28 02:55:32.791046 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "amf-BBwjcb8HQE21kA4RGgAAAIk"]
[Tue Jul 28 02:55:32.791493 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "amf-BBwjcb8HQE21kA4RGgAAAIk"]
[Tue Jul 28 02:55:32.791670 2026] [:error] [pid 12277:tid 140706953787136] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /vendor/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "amf-BBwjcb8HQE21kA4RGgAAAIk"]
[Tue Jul 28 02:55:32.976483 2026] [:error] [pid 12277:tid 140706978965248] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "amf-BBwjcb8HQE21kA4RGwAAAIY"]
[Tue Jul 28 02:55:32.977307 2026] [:error] [pid 12277:tid 140706978965248] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "amf-BBwjcb8HQE21kA4RGwAAAIY"]
[Tue Jul 28 02:55:32.977863 2026] [:error] [pid 12277:tid 140706978965248] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "amf-BBwjcb8HQE21kA4RGwAAAIY"]
[Tue Jul 28 02:55:32.978095 2026] [:error] [pid 12277:tid 140706978965248] [client 162.158.106.236:12123] [client 162.158.106.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lib/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "amf-BBwjcb8HQE21kA4RGwAAAIY"]
[Tue Jul 28 02:55:33.683999 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "amf-BecsEMuHmMYmk65UeAAAAFE"]
[Tue Jul 28 02:55:33.684872 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "amf-BecsEMuHmMYmk65UeAAAAFE"]
[Tue Jul 28 02:55:33.685419 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "amf-BecsEMuHmMYmk65UeAAAAFE"]
[Tue Jul 28 02:55:33.685709 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /resources/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "amf-BecsEMuHmMYmk65UeAAAAFE"]
[Tue Jul 28 02:55:33.879932 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "amf-BecsEMuHmMYmk65UeQAAAEA"]
[Tue Jul 28 02:55:33.880658 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "amf-BecsEMuHmMYmk65UeQAAAEA"]
[Tue Jul 28 02:55:33.881106 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "amf-BecsEMuHmMYmk65UeQAAAEA"]
[Tue Jul 28 02:55:33.881325 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "amf-BecsEMuHmMYmk65UeQAAAEA"]
[Tue Jul 28 02:55:34.080641 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "amf-BucsEMuHmMYmk65UegAAAEU"]
[Tue Jul 28 02:55:34.081517 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "amf-BucsEMuHmMYmk65UegAAAEU"]
[Tue Jul 28 02:55:34.082036 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "amf-BucsEMuHmMYmk65UegAAAEU"]
[Tue Jul 28 02:55:34.082284 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "amf-BucsEMuHmMYmk65UegAAAEU"]
[Tue Jul 28 02:55:34.279655 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "amf-BucsEMuHmMYmk65UewAAAEk"]
[Tue Jul 28 02:55:34.280618 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "amf-BucsEMuHmMYmk65UewAAAEk"]
[Tue Jul 28 02:55:34.281209 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "amf-BucsEMuHmMYmk65UewAAAEk"]
[Tue Jul 28 02:55:34.281453 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /internal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "amf-BucsEMuHmMYmk65UewAAAEk"]
[Tue Jul 28 02:55:34.478486 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "amf-BucsEMuHmMYmk65UfAAAAE0"]
[Tue Jul 28 02:55:34.479279 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "amf-BucsEMuHmMYmk65UfAAAAE0"]
[Tue Jul 28 02:55:34.479843 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "amf-BucsEMuHmMYmk65UfAAAAE0"]
[Tue Jul 28 02:55:34.480092 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "amf-BucsEMuHmMYmk65UfAAAAE0"]
[Tue Jul 28 02:55:34.679498 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "amf-BucsEMuHmMYmk65UfQAAAEw"]
[Tue Jul 28 02:55:34.680361 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "amf-BucsEMuHmMYmk65UfQAAAEw"]
[Tue Jul 28 02:55:34.680922 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "amf-BucsEMuHmMYmk65UfQAAAEw"]
[Tue Jul 28 02:55:34.681162 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /scripts/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "amf-BucsEMuHmMYmk65UfQAAAEw"]
[Tue Jul 28 02:55:34.884672 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "amf-BucsEMuHmMYmk65UfgAAAEE"]
[Tue Jul 28 02:55:34.885513 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "amf-BucsEMuHmMYmk65UfgAAAEE"]
[Tue Jul 28 02:55:34.886043 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "amf-BucsEMuHmMYmk65UfgAAAEE"]
[Tue Jul 28 02:55:34.886299 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /bin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "amf-BucsEMuHmMYmk65UfgAAAEE"]
[Tue Jul 28 02:55:35.086264 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "amf-B-csEMuHmMYmk65UfwAAAFg"]
[Tue Jul 28 02:55:35.086863 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "amf-B-csEMuHmMYmk65UfwAAAFg"]
[Tue Jul 28 02:55:35.087271 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "amf-B-csEMuHmMYmk65UfwAAAFg"]
[Tue Jul 28 02:55:35.087439 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sbin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "amf-B-csEMuHmMYmk65UfwAAAFg"]
[Tue Jul 28 02:55:35.284628 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/local/.env"] [unique_id "amf-B-csEMuHmMYmk65UgAAAAEg"]
[Tue Jul 28 02:55:35.285421 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/local/.env"] [unique_id "amf-B-csEMuHmMYmk65UgAAAAEg"]
[Tue Jul 28 02:55:35.286042 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/local/.env"] [unique_id "amf-B-csEMuHmMYmk65UgAAAAEg"]
[Tue Jul 28 02:55:35.286281 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/local/.env"] [unique_id "amf-B-csEMuHmMYmk65UgAAAAEg"]
[Tue Jul 28 02:55:35.482529 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "amf-B-csEMuHmMYmk65UgQAAAFU"]
[Tue Jul 28 02:55:35.483463 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "amf-B-csEMuHmMYmk65UgQAAAFU"]
[Tue Jul 28 02:55:35.484029 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "amf-B-csEMuHmMYmk65UgQAAAFU"]
[Tue Jul 28 02:55:35.484295 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /portal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "amf-B-csEMuHmMYmk65UgQAAAFU"]
[Tue Jul 28 02:55:35.678672 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "amf-B-csEMuHmMYmk65UggAAAEo"]
[Tue Jul 28 02:55:35.679492 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "amf-B-csEMuHmMYmk65UggAAAEo"]
[Tue Jul 28 02:55:35.679973 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "amf-B-csEMuHmMYmk65UggAAAEo"]
[Tue Jul 28 02:55:35.680199 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /dashboard/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "amf-B-csEMuHmMYmk65UggAAAEo"]
[Tue Jul 28 02:55:35.873631 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "amf-B-csEMuHmMYmk65UgwAAAE8"]
[Tue Jul 28 02:55:35.874430 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "amf-B-csEMuHmMYmk65UgwAAAE8"]
[Tue Jul 28 02:55:35.874912 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "amf-B-csEMuHmMYmk65UgwAAAE8"]
[Tue Jul 28 02:55:35.875116 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "amf-B-csEMuHmMYmk65UgwAAAE8"]
[Tue Jul 28 02:55:36.070520 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "amf-COcsEMuHmMYmk65UhAAAAFc"]
[Tue Jul 28 02:55:36.071360 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "amf-COcsEMuHmMYmk65UhAAAAFc"]
[Tue Jul 28 02:55:36.071791 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "amf-COcsEMuHmMYmk65UhAAAAFc"]
[Tue Jul 28 02:55:36.071953 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /crm/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "amf-COcsEMuHmMYmk65UhAAAAFc"]
[Tue Jul 28 02:55:36.268320 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "amf-COcsEMuHmMYmk65UhQAAAFQ"]
[Tue Jul 28 02:55:36.268993 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "amf-COcsEMuHmMYmk65UhQAAAFQ"]
[Tue Jul 28 02:55:36.269393 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "amf-COcsEMuHmMYmk65UhQAAAFQ"]
[Tue Jul 28 02:55:36.269572 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /erp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "amf-COcsEMuHmMYmk65UhQAAAFQ"]
[Tue Jul 28 02:55:36.462753 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "amf-COcsEMuHmMYmk65UhgAAAEM"]
[Tue Jul 28 02:55:36.463588 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "amf-COcsEMuHmMYmk65UhgAAAEM"]
[Tue Jul 28 02:55:36.464049 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "amf-COcsEMuHmMYmk65UhgAAAEM"]
[Tue Jul 28 02:55:36.464279 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /shop/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "amf-COcsEMuHmMYmk65UhgAAAEM"]
[Tue Jul 28 02:55:36.660537 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/store/.env"] [unique_id "amf-COcsEMuHmMYmk65UhwAAAFM"]
[Tue Jul 28 02:55:36.661093 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/store/.env"] [unique_id "amf-COcsEMuHmMYmk65UhwAAAFM"]
[Tue Jul 28 02:55:36.661755 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/store/.env"] [unique_id "amf-COcsEMuHmMYmk65UhwAAAFM"]
[Tue Jul 28 02:55:36.661964 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /store/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/store/.env"] [unique_id "amf-COcsEMuHmMYmk65UhwAAAFM"]
[Tue Jul 28 02:55:36.858528 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "amf-COcsEMuHmMYmk65UiAAAAFY"]
[Tue Jul 28 02:55:36.859278 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "amf-COcsEMuHmMYmk65UiAAAAFY"]
[Tue Jul 28 02:55:36.859867 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "amf-COcsEMuHmMYmk65UiAAAAFY"]
[Tue Jul 28 02:55:36.860095 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "amf-COcsEMuHmMYmk65UiAAAAFY"]
[Tue Jul 28 02:55:37.062209 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amf-CecsEMuHmMYmk65UiQAAAFA"]
[Tue Jul 28 02:55:37.063011 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amf-CecsEMuHmMYmk65UiQAAAFA"]
[Tue Jul 28 02:55:37.063488 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amf-CecsEMuHmMYmk65UiQAAAFA"]
[Tue Jul 28 02:55:37.063705 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /client/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amf-CecsEMuHmMYmk65UiQAAAFA"]
[Tue Jul 28 02:55:37.257233 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/project/.env"] [unique_id "amf-CecsEMuHmMYmk65UigAAAEQ"]
[Tue Jul 28 02:55:37.258002 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/project/.env"] [unique_id "amf-CecsEMuHmMYmk65UigAAAEQ"]
[Tue Jul 28 02:55:37.258459 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/project/.env"] [unique_id "amf-CecsEMuHmMYmk65UigAAAEQ"]
[Tue Jul 28 02:55:37.258728 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /project/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/project/.env"] [unique_id "amf-CecsEMuHmMYmk65UigAAAEQ"]
[Tue Jul 28 02:55:37.451720 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "amf-CecsEMuHmMYmk65UiwAAAFI"]
[Tue Jul 28 02:55:37.452389 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "amf-CecsEMuHmMYmk65UiwAAAFI"]
[Tue Jul 28 02:55:37.453081 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "amf-CecsEMuHmMYmk65UiwAAAFI"]
[Tue Jul 28 02:55:37.453287 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin-panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "amf-CecsEMuHmMYmk65UiwAAAFI"]
[Tue Jul 28 02:55:37.646994 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "amf-CecsEMuHmMYmk65UjAAAAEc"]
[Tue Jul 28 02:55:37.647792 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "amf-CecsEMuHmMYmk65UjAAAAEc"]
[Tue Jul 28 02:55:37.648288 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "amf-CecsEMuHmMYmk65UjAAAAEc"]
[Tue Jul 28 02:55:37.648567 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /control-panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "amf-CecsEMuHmMYmk65UjAAAAEc"]
[Tue Jul 28 02:55:37.844435 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "amf-CecsEMuHmMYmk65UjQAAAE4"]
[Tue Jul 28 02:55:37.845164 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "amf-CecsEMuHmMYmk65UjQAAAE4"]
[Tue Jul 28 02:55:37.845684 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "amf-CecsEMuHmMYmk65UjQAAAE4"]
[Tue Jul 28 02:55:37.845911 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /user-panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "amf-CecsEMuHmMYmk65UjQAAAE4"]
[Tue Jul 28 02:55:38.041507 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/node/.env"] [unique_id "amf-CucsEMuHmMYmk65UjgAAAEY"]
[Tue Jul 28 02:55:38.042266 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/node/.env"] [unique_id "amf-CucsEMuHmMYmk65UjgAAAEY"]
[Tue Jul 28 02:55:38.042800 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/node/.env"] [unique_id "amf-CucsEMuHmMYmk65UjgAAAEY"]
[Tue Jul 28 02:55:38.043040 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/node/.env"] [unique_id "amf-CucsEMuHmMYmk65UjgAAAEY"]
[Tue Jul 28 02:55:38.238179 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/express/.env"] [unique_id "amf-CucsEMuHmMYmk65UjwAAAEI"]
[Tue Jul 28 02:55:38.238944 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/express/.env"] [unique_id "amf-CucsEMuHmMYmk65UjwAAAEI"]
[Tue Jul 28 02:55:38.239434 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/express/.env"] [unique_id "amf-CucsEMuHmMYmk65UjwAAAEI"]
[Tue Jul 28 02:55:38.239676 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /express/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/express/.env"] [unique_id "amf-CucsEMuHmMYmk65UjwAAAEI"]
[Tue Jul 28 02:55:38.434304 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/next/.env"] [unique_id "amf-CucsEMuHmMYmk65UkAAAAEs"]
[Tue Jul 28 02:55:38.434937 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/next/.env"] [unique_id "amf-CucsEMuHmMYmk65UkAAAAEs"]
[Tue Jul 28 02:55:38.435277 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/next/.env"] [unique_id "amf-CucsEMuHmMYmk65UkAAAAEs"]
[Tue Jul 28 02:55:38.435456 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /next/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/next/.env"] [unique_id "amf-CucsEMuHmMYmk65UkAAAAEs"]
[Tue Jul 28 02:55:38.629381 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "amf-CucsEMuHmMYmk65UkQAAAFE"]
[Tue Jul 28 02:55:38.630005 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "amf-CucsEMuHmMYmk65UkQAAAFE"]
[Tue Jul 28 02:55:38.630422 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "amf-CucsEMuHmMYmk65UkQAAAFE"]
[Tue Jul 28 02:55:38.630644 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nuxt/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "amf-CucsEMuHmMYmk65UkQAAAFE"]
[Tue Jul 28 02:55:38.826379 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "amf-CucsEMuHmMYmk65UkgAAAEA"]
[Tue Jul 28 02:55:38.827154 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "amf-CucsEMuHmMYmk65UkgAAAEA"]
[Tue Jul 28 02:55:38.827657 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "amf-CucsEMuHmMYmk65UkgAAAEA"]
[Tue Jul 28 02:55:38.827917 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nest/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "amf-CucsEMuHmMYmk65UkgAAAEA"]
[Tue Jul 28 02:55:39.021716 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/react/.env"] [unique_id "amf-C-csEMuHmMYmk65UkwAAAEU"]
[Tue Jul 28 02:55:39.022402 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/react/.env"] [unique_id "amf-C-csEMuHmMYmk65UkwAAAEU"]
[Tue Jul 28 02:55:39.022840 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/react/.env"] [unique_id "amf-C-csEMuHmMYmk65UkwAAAEU"]
[Tue Jul 28 02:55:39.023061 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/react/.env"] [unique_id "amf-C-csEMuHmMYmk65UkwAAAEU"]
[Tue Jul 28 02:55:39.219508 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "amf-C-csEMuHmMYmk65UlAAAAEk"]
[Tue Jul 28 02:55:39.220174 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "amf-C-csEMuHmMYmk65UlAAAAEk"]
[Tue Jul 28 02:55:39.220670 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "amf-C-csEMuHmMYmk65UlAAAAEk"]
[Tue Jul 28 02:55:39.220869 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /vue/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "amf-C-csEMuHmMYmk65UlAAAAEk"]
[Tue Jul 28 02:55:39.415269 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "amf-C-csEMuHmMYmk65UlQAAAE0"]
[Tue Jul 28 02:55:39.415962 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "amf-C-csEMuHmMYmk65UlQAAAE0"]
[Tue Jul 28 02:55:39.416357 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "amf-C-csEMuHmMYmk65UlQAAAE0"]
[Tue Jul 28 02:55:39.416545 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /angular/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "amf-C-csEMuHmMYmk65UlQAAAE0"]
[Tue Jul 28 02:55:39.612720 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "amf-C-csEMuHmMYmk65UlgAAAEw"]
[Tue Jul 28 02:55:39.613493 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "amf-C-csEMuHmMYmk65UlgAAAEw"]
[Tue Jul 28 02:55:39.614004 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "amf-C-csEMuHmMYmk65UlgAAAEw"]
[Tue Jul 28 02:55:39.614245 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /svelte/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "amf-C-csEMuHmMYmk65UlgAAAEw"]
[Tue Jul 28 02:55:39.809790 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "amf-C-csEMuHmMYmk65UlwAAAEE"]
[Tue Jul 28 02:55:39.810491 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "amf-C-csEMuHmMYmk65UlwAAAEE"]
[Tue Jul 28 02:55:39.810961 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "amf-C-csEMuHmMYmk65UlwAAAEE"]
[Tue Jul 28 02:55:39.811172 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /vite/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "amf-C-csEMuHmMYmk65UlwAAAEE"]
[Tue Jul 28 02:55:40.004931 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmAAAAFg"]
[Tue Jul 28 02:55:40.005735 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmAAAAFg"]
[Tue Jul 28 02:55:40.006235 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmAAAAFg"]
[Tue Jul 28 02:55:40.006494 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backup/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmAAAAFg"]
[Tue Jul 28 02:55:40.200256 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmQAAAEg"]
[Tue Jul 28 02:55:40.201118 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmQAAAEg"]
[Tue Jul 28 02:55:40.201637 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmQAAAEg"]
[Tue Jul 28 02:55:40.201908 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backups/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmQAAAEg"]
[Tue Jul 28 02:55:40.396082 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmgAAAFU"]
[Tue Jul 28 02:55:40.396714 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmgAAAFU"]
[Tue Jul 28 02:55:40.397108 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmgAAAFU"]
[Tue Jul 28 02:55:40.397416 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /old/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmgAAAFU"]
[Tue Jul 28 02:55:40.590869 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmwAAAEo"]
[Tue Jul 28 02:55:40.591622 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmwAAAEo"]
[Tue Jul 28 02:55:40.592069 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmwAAAEo"]
[Tue Jul 28 02:55:40.592219 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tmp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amf-DOcsEMuHmMYmk65UmwAAAEo"]
[Tue Jul 28 02:55:40.787440 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amf-DOcsEMuHmMYmk65UnAAAAE8"]
[Tue Jul 28 02:55:40.788189 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amf-DOcsEMuHmMYmk65UnAAAAE8"]
[Tue Jul 28 02:55:40.788601 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amf-DOcsEMuHmMYmk65UnAAAAE8"]
[Tue Jul 28 02:55:40.788850 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /temp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amf-DOcsEMuHmMYmk65UnAAAAE8"]
[Tue Jul 28 02:55:40.980940 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "amf-DOcsEMuHmMYmk65UnQAAAFc"]
[Tue Jul 28 02:55:40.981718 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "amf-DOcsEMuHmMYmk65UnQAAAFc"]
[Tue Jul 28 02:55:40.982209 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "amf-DOcsEMuHmMYmk65UnQAAAFc"]
[Tue Jul 28 02:55:40.982477 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "amf-DOcsEMuHmMYmk65UnQAAAFc"]
[Tue Jul 28 02:55:41.177110 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "amf-DecsEMuHmMYmk65UngAAAFQ"]
[Tue Jul 28 02:55:41.177925 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "amf-DecsEMuHmMYmk65UngAAAFQ"]
[Tue Jul 28 02:55:41.178341 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "amf-DecsEMuHmMYmk65UngAAAFQ"]
[Tue Jul 28 02:55:41.178505 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "amf-DecsEMuHmMYmk65UngAAAFQ"]
[Tue Jul 28 02:55:41.373447 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "amf-DecsEMuHmMYmk65UnwAAAEM"]
[Tue Jul 28 02:55:41.374355 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "amf-DecsEMuHmMYmk65UnwAAAEM"]
[Tue Jul 28 02:55:41.374816 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "amf-DecsEMuHmMYmk65UnwAAAEM"]
[Tue Jul 28 02:55:41.375028 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "amf-DecsEMuHmMYmk65UnwAAAEM"]
[Tue Jul 28 02:55:41.569159 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/en/.env"] [unique_id "amf-DecsEMuHmMYmk65UoAAAAFM"]
[Tue Jul 28 02:55:41.569828 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/en/.env"] [unique_id "amf-DecsEMuHmMYmk65UoAAAAFM"]
[Tue Jul 28 02:55:41.570163 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/en/.env"] [unique_id "amf-DecsEMuHmMYmk65UoAAAAFM"]
[Tue Jul 28 02:55:41.570360 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/en/.env"] [unique_id "amf-DecsEMuHmMYmk65UoAAAAFM"]
[Tue Jul 28 02:55:41.763098 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "amf-DecsEMuHmMYmk65UoQAAAFY"]
[Tue Jul 28 02:55:41.763810 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "amf-DecsEMuHmMYmk65UoQAAAFY"]
[Tue Jul 28 02:55:41.764352 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "amf-DecsEMuHmMYmk65UoQAAAFY"]
[Tue Jul 28 02:55:41.764607 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "amf-DecsEMuHmMYmk65UoQAAAFY"]
[Tue Jul 28 02:55:41.956200 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "amf-DecsEMuHmMYmk65UogAAAFA"]
[Tue Jul 28 02:55:41.957008 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "amf-DecsEMuHmMYmk65UogAAAFA"]
[Tue Jul 28 02:55:41.957521 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "amf-DecsEMuHmMYmk65UogAAAFA"]
[Tue Jul 28 02:55:41.957779 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "amf-DecsEMuHmMYmk65UogAAAFA"]
[Tue Jul 28 02:55:42.152544 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "amf-DucsEMuHmMYmk65UowAAAEQ"]
[Tue Jul 28 02:55:42.153341 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "amf-DucsEMuHmMYmk65UowAAAEQ"]
[Tue Jul 28 02:55:42.153872 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "amf-DucsEMuHmMYmk65UowAAAEQ"]
[Tue Jul 28 02:55:42.154105 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "amf-DucsEMuHmMYmk65UowAAAEQ"]
[Tue Jul 28 02:55:42.347142 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "amf-DucsEMuHmMYmk65UpAAAAFI"]
[Tue Jul 28 02:55:42.347810 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "amf-DucsEMuHmMYmk65UpAAAAFI"]
[Tue Jul 28 02:55:42.348206 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "amf-DucsEMuHmMYmk65UpAAAAFI"]
[Tue Jul 28 02:55:42.348373 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "amf-DucsEMuHmMYmk65UpAAAAFI"]
[Tue Jul 28 02:55:42.543670 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "amf-DucsEMuHmMYmk65UpQAAAEc"]
[Tue Jul 28 02:55:42.544224 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "amf-DucsEMuHmMYmk65UpQAAAEc"]
[Tue Jul 28 02:55:42.544612 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "amf-DucsEMuHmMYmk65UpQAAAEc"]
[Tue Jul 28 02:55:42.544768 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "amf-DucsEMuHmMYmk65UpQAAAEc"]
[Tue Jul 28 02:55:42.738165 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "amf-DucsEMuHmMYmk65UpgAAAE4"]
[Tue Jul 28 02:55:42.738986 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "amf-DucsEMuHmMYmk65UpgAAAE4"]
[Tue Jul 28 02:55:42.739573 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "amf-DucsEMuHmMYmk65UpgAAAE4"]
[Tue Jul 28 02:55:42.739821 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "amf-DucsEMuHmMYmk65UpgAAAE4"]
[Tue Jul 28 02:55:42.934192 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "amf-DucsEMuHmMYmk65UpwAAAEY"]
[Tue Jul 28 02:55:42.934958 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "amf-DucsEMuHmMYmk65UpwAAAEY"]
[Tue Jul 28 02:55:42.935424 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "amf-DucsEMuHmMYmk65UpwAAAEY"]
[Tue Jul 28 02:55:42.935670 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /logs/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "amf-DucsEMuHmMYmk65UpwAAAEY"]
[Tue Jul 28 02:55:43.135234 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "amf-D-csEMuHmMYmk65UqAAAAEI"]
[Tue Jul 28 02:55:43.135834 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "amf-D-csEMuHmMYmk65UqAAAAEI"]
[Tue Jul 28 02:55:43.136300 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "amf-D-csEMuHmMYmk65UqAAAAEI"]
[Tue Jul 28 02:55:43.136544 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cache/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "amf-D-csEMuHmMYmk65UqAAAAEI"]
[Tue Jul 28 02:55:43.331931 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "amf-D-csEMuHmMYmk65UqQAAAEs"]
[Tue Jul 28 02:55:43.332493 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "amf-D-csEMuHmMYmk65UqQAAAEs"]
[Tue Jul 28 02:55:43.332838 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "amf-D-csEMuHmMYmk65UqQAAAEs"]
[Tue Jul 28 02:55:43.332984 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailer/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "amf-D-csEMuHmMYmk65UqQAAAEs"]
[Tue Jul 28 02:55:43.529382 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "amf-D-csEMuHmMYmk65UqgAAAFE"]
[Tue Jul 28 02:55:43.530016 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "amf-D-csEMuHmMYmk65UqgAAAFE"]
[Tue Jul 28 02:55:43.530527 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "amf-D-csEMuHmMYmk65UqgAAAFE"]
[Tue Jul 28 02:55:43.530788 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mail/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "amf-D-csEMuHmMYmk65UqgAAAFE"]
[Tue Jul 28 02:55:43.722721 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/email/.env"] [unique_id "amf-D-csEMuHmMYmk65UqwAAAEA"]
[Tue Jul 28 02:55:43.723176 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/email/.env"] [unique_id "amf-D-csEMuHmMYmk65UqwAAAEA"]
[Tue Jul 28 02:55:43.723586 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/email/.env"] [unique_id "amf-D-csEMuHmMYmk65UqwAAAEA"]
[Tue Jul 28 02:55:43.723804 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /email/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/email/.env"] [unique_id "amf-D-csEMuHmMYmk65UqwAAAEA"]
[Tue Jul 28 02:55:43.917933 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "amf-D-csEMuHmMYmk65UrAAAAEU"]
[Tue Jul 28 02:55:43.918731 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "amf-D-csEMuHmMYmk65UrAAAAEU"]
[Tue Jul 28 02:55:43.919239 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "amf-D-csEMuHmMYmk65UrAAAAEU"]
[Tue Jul 28 02:55:43.919488 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /smtp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "amf-D-csEMuHmMYmk65UrAAAAEU"]
[Tue Jul 28 02:55:44.113948 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "amf-EOcsEMuHmMYmk65UrQAAAEk"]
[Tue Jul 28 02:55:44.114584 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "amf-EOcsEMuHmMYmk65UrQAAAEk"]
[Tue Jul 28 02:55:44.114932 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "amf-EOcsEMuHmMYmk65UrQAAAEk"]
[Tue Jul 28 02:55:44.115079 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailing/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "amf-EOcsEMuHmMYmk65UrQAAAEk"]
[Tue Jul 28 02:55:44.307448 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "amf-EOcsEMuHmMYmk65UrgAAAE0"]
[Tue Jul 28 02:55:44.308006 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "amf-EOcsEMuHmMYmk65UrgAAAE0"]
[Tue Jul 28 02:55:44.308399 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "amf-EOcsEMuHmMYmk65UrgAAAE0"]
[Tue Jul 28 02:55:44.308587 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /notifications/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "amf-EOcsEMuHmMYmk65UrgAAAE0"]
[Tue Jul 28 02:55:44.501286 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "amf-EOcsEMuHmMYmk65UrwAAAEw"]
[Tue Jul 28 02:55:44.501982 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "amf-EOcsEMuHmMYmk65UrwAAAEw"]
[Tue Jul 28 02:55:44.502482 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "amf-EOcsEMuHmMYmk65UrwAAAEw"]
[Tue Jul 28 02:55:44.502733 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /notify/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "amf-EOcsEMuHmMYmk65UrwAAAEw"]
[Tue Jul 28 02:55:44.696720 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "amf-EOcsEMuHmMYmk65UsAAAAEE"]
[Tue Jul 28 02:55:44.697477 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "amf-EOcsEMuHmMYmk65UsAAAAEE"]
[Tue Jul 28 02:55:44.697938 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "amf-EOcsEMuHmMYmk65UsAAAAEE"]
[Tue Jul 28 02:55:44.698161 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sender/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "amf-EOcsEMuHmMYmk65UsAAAAEE"]
[Tue Jul 28 02:55:44.899605 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "amf-EOcsEMuHmMYmk65UsQAAAFg"]
[Tue Jul 28 02:55:44.900061 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "amf-EOcsEMuHmMYmk65UsQAAAFg"]
[Tue Jul 28 02:55:44.900441 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "amf-EOcsEMuHmMYmk65UsQAAAFg"]
[Tue Jul 28 02:55:44.900650 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /campaign/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "amf-EOcsEMuHmMYmk65UsQAAAFg"]
[Tue Jul 28 02:55:45.091919 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "amf-EecsEMuHmMYmk65UsgAAAEg"]
[Tue Jul 28 02:55:45.092442 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "amf-EecsEMuHmMYmk65UsgAAAEg"]
[Tue Jul 28 02:55:45.092878 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "amf-EecsEMuHmMYmk65UsgAAAEg"]
[Tue Jul 28 02:55:45.093106 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /newsletter/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "amf-EecsEMuHmMYmk65UsgAAAEg"]
[Tue Jul 28 02:55:45.287037 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "amf-EecsEMuHmMYmk65UswAAAFU"]
[Tue Jul 28 02:55:45.287822 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "amf-EecsEMuHmMYmk65UswAAAFU"]
[Tue Jul 28 02:55:45.288306 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "amf-EecsEMuHmMYmk65UswAAAFU"]
[Tue Jul 28 02:55:45.288578 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /ses/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "amf-EecsEMuHmMYmk65UswAAAFU"]
[Tue Jul 28 02:55:45.484637 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "amf-EecsEMuHmMYmk65UtAAAAEo"]
[Tue Jul 28 02:55:45.485428 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "amf-EecsEMuHmMYmk65UtAAAAEo"]
[Tue Jul 28 02:55:45.485954 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "amf-EecsEMuHmMYmk65UtAAAAEo"]
[Tue Jul 28 02:55:45.486209 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sendgrid/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "amf-EecsEMuHmMYmk65UtAAAAEo"]
[Tue Jul 28 02:55:45.681778 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "amf-EecsEMuHmMYmk65UtQAAAE8"]
[Tue Jul 28 02:55:45.682741 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "amf-EecsEMuHmMYmk65UtQAAAE8"]
[Tue Jul 28 02:55:45.683299 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "amf-EecsEMuHmMYmk65UtQAAAE8"]
[Tue Jul 28 02:55:45.683608 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sparkpost/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "amf-EecsEMuHmMYmk65UtQAAAE8"]
[Tue Jul 28 02:55:45.877209 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "amf-EecsEMuHmMYmk65UtgAAAFc"]
[Tue Jul 28 02:55:45.877792 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "amf-EecsEMuHmMYmk65UtgAAAFc"]
[Tue Jul 28 02:55:45.878254 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "amf-EecsEMuHmMYmk65UtgAAAFc"]
[Tue Jul 28 02:55:45.878457 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /postmark/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "amf-EecsEMuHmMYmk65UtgAAAFc"]
[Tue Jul 28 02:55:46.070770 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "amf-EucsEMuHmMYmk65UtwAAAFQ"]
[Tue Jul 28 02:55:46.071501 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "amf-EucsEMuHmMYmk65UtwAAAFQ"]
[Tue Jul 28 02:55:46.071995 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "amf-EucsEMuHmMYmk65UtwAAAFQ"]
[Tue Jul 28 02:55:46.072249 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailgun/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "amf-EucsEMuHmMYmk65UtwAAAFQ"]
[Tue Jul 28 02:55:46.265217 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "amf-EucsEMuHmMYmk65UuAAAAEM"]
[Tue Jul 28 02:55:46.266055 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "amf-EucsEMuHmMYmk65UuAAAAEM"]
[Tue Jul 28 02:55:46.266574 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "amf-EucsEMuHmMYmk65UuAAAAEM"]
[Tue Jul 28 02:55:46.266819 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mandrill/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "amf-EucsEMuHmMYmk65UuAAAAEM"]
[Tue Jul 28 02:55:46.463605 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "amf-EucsEMuHmMYmk65UuQAAAFM"]
[Tue Jul 28 02:55:46.464509 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "amf-EucsEMuHmMYmk65UuQAAAFM"]
[Tue Jul 28 02:55:46.465145 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "amf-EucsEMuHmMYmk65UuQAAAFM"]
[Tue Jul 28 02:55:46.465439 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailjet/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "amf-EucsEMuHmMYmk65UuQAAAFM"]
[Tue Jul 28 02:55:46.661866 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "amf-EucsEMuHmMYmk65UugAAAFY"]
[Tue Jul 28 02:55:46.662690 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "amf-EucsEMuHmMYmk65UugAAAFY"]
[Tue Jul 28 02:55:46.663253 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "amf-EucsEMuHmMYmk65UugAAAFY"]
[Tue Jul 28 02:55:46.663505 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /brevo/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "amf-EucsEMuHmMYmk65UugAAAFY"]
[Tue Jul 28 02:55:46.860116 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "amf-EucsEMuHmMYmk65UuwAAAFA"]
[Tue Jul 28 02:55:46.860843 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "amf-EucsEMuHmMYmk65UuwAAAFA"]
[Tue Jul 28 02:55:46.861297 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "amf-EucsEMuHmMYmk65UuwAAAFA"]
[Tue Jul 28 02:55:46.861570 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /transactional/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "amf-EucsEMuHmMYmk65UuwAAAFA"]
[Tue Jul 28 02:55:47.058467 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "amf-E-csEMuHmMYmk65UvAAAAEQ"]
[Tue Jul 28 02:55:47.059238 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "amf-E-csEMuHmMYmk65UvAAAAEQ"]
[Tue Jul 28 02:55:47.059761 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "amf-E-csEMuHmMYmk65UvAAAAEQ"]
[Tue Jul 28 02:55:47.059993 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /bulk/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "amf-E-csEMuHmMYmk65UvAAAAEQ"]
[Tue Jul 28 02:55:47.253421 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "amf-E-csEMuHmMYmk65UvQAAAFI"]
[Tue Jul 28 02:55:47.254163 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "amf-E-csEMuHmMYmk65UvQAAAFI"]
[Tue Jul 28 02:55:47.254626 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "amf-E-csEMuHmMYmk65UvQAAAFI"]
[Tue Jul 28 02:55:47.254828 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /aws/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "amf-E-csEMuHmMYmk65UvQAAAFI"]
[Tue Jul 28 02:55:47.449257 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "amf-E-csEMuHmMYmk65UvgAAAEc"]
[Tue Jul 28 02:55:47.449809 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "amf-E-csEMuHmMYmk65UvgAAAEc"]
[Tue Jul 28 02:55:47.450157 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "amf-E-csEMuHmMYmk65UvgAAAEc"]
[Tue Jul 28 02:55:47.450303 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /azure/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "amf-E-csEMuHmMYmk65UvgAAAEc"]
[Tue Jul 28 02:55:47.651198 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "amf-E-csEMuHmMYmk65UvwAAAE4"]
[Tue Jul 28 02:55:47.651793 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "amf-E-csEMuHmMYmk65UvwAAAE4"]
[Tue Jul 28 02:55:47.652142 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "amf-E-csEMuHmMYmk65UvwAAAE4"]
[Tue Jul 28 02:55:47.652308 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /gcp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "amf-E-csEMuHmMYmk65UvwAAAE4"]
[Tue Jul 28 02:55:47.856374 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "amf-E-csEMuHmMYmk65UwAAAAEY"]
[Tue Jul 28 02:55:47.856970 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "amf-E-csEMuHmMYmk65UwAAAAEY"]
[Tue Jul 28 02:55:47.857410 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "amf-E-csEMuHmMYmk65UwAAAAEY"]
[Tue Jul 28 02:55:47.857647 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cloud/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "amf-E-csEMuHmMYmk65UwAAAAEY"]
[Tue Jul 28 02:55:48.058447 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "amf-FOcsEMuHmMYmk65UwQAAAEI"]
[Tue Jul 28 02:55:48.059211 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "amf-FOcsEMuHmMYmk65UwQAAAEI"]
[Tue Jul 28 02:55:48.059687 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "amf-FOcsEMuHmMYmk65UwQAAAEI"]
[Tue Jul 28 02:55:48.059901 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /infrastructure/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "amf-FOcsEMuHmMYmk65UwQAAAEI"]
[Tue Jul 28 02:55:48.261910 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "amf-FOcsEMuHmMYmk65UwgAAAEs"]
[Tue Jul 28 02:55:48.262694 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "amf-FOcsEMuHmMYmk65UwgAAAEs"]
[Tue Jul 28 02:55:48.263154 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "amf-FOcsEMuHmMYmk65UwgAAAEs"]
[Tue Jul 28 02:55:48.263385 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "amf-FOcsEMuHmMYmk65UwgAAAEs"]
[Tue Jul 28 02:55:48.459454 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "amf-FOcsEMuHmMYmk65UwwAAAFE"]
[Tue Jul 28 02:55:48.460241 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "amf-FOcsEMuHmMYmk65UwwAAAFE"]
[Tue Jul 28 02:55:48.460763 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "amf-FOcsEMuHmMYmk65UwwAAAFE"]
[Tue Jul 28 02:55:48.461021 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /k8s/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "amf-FOcsEMuHmMYmk65UwwAAAFE"]
[Tue Jul 28 02:55:48.658547 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "amf-FOcsEMuHmMYmk65UxAAAAEA"]
[Tue Jul 28 02:55:48.659261 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "amf-FOcsEMuHmMYmk65UxAAAAEA"]
[Tue Jul 28 02:55:48.659755 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "amf-FOcsEMuHmMYmk65UxAAAAEA"]
[Tue Jul 28 02:55:48.659994 2026] [:error] [pid 12276:tid 140707103270656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kubernetes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "amf-FOcsEMuHmMYmk65UxAAAAEA"]
[Tue Jul 28 02:55:48.855222 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "amf-FOcsEMuHmMYmk65UxQAAAEU"]
[Tue Jul 28 02:55:48.856012 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "amf-FOcsEMuHmMYmk65UxQAAAEU"]
[Tue Jul 28 02:55:48.856490 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "amf-FOcsEMuHmMYmk65UxQAAAEU"]
[Tue Jul 28 02:55:48.856687 2026] [:error] [pid 12276:tid 140706987357952] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /terraform/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "amf-FOcsEMuHmMYmk65UxQAAAEU"]
[Tue Jul 28 02:55:49.052507 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "amf-FecsEMuHmMYmk65UxgAAAEk"]
[Tue Jul 28 02:55:49.053273 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "amf-FecsEMuHmMYmk65UxgAAAEk"]
[Tue Jul 28 02:55:49.053789 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "amf-FecsEMuHmMYmk65UxgAAAEk"]
[Tue Jul 28 02:55:49.054027 2026] [:error] [pid 12276:tid 140706953787136] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /ansible/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "amf-FecsEMuHmMYmk65UxgAAAEk"]
[Tue Jul 28 02:55:49.250000 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "amf-FecsEMuHmMYmk65UxwAAAE0"]
[Tue Jul 28 02:55:49.250708 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "amf-FecsEMuHmMYmk65UxwAAAE0"]
[Tue Jul 28 02:55:49.251123 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "amf-FecsEMuHmMYmk65UxwAAAE0"]
[Tue Jul 28 02:55:49.251364 2026] [:error] [pid 12276:tid 140706920216320] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "amf-FecsEMuHmMYmk65UxwAAAE0"]
[Tue Jul 28 02:55:49.446481 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "amf-FecsEMuHmMYmk65UyAAAAEw"]
[Tue Jul 28 02:55:49.447243 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "amf-FecsEMuHmMYmk65UyAAAAEw"]
[Tue Jul 28 02:55:49.447795 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "amf-FecsEMuHmMYmk65UyAAAAEw"]
[Tue Jul 28 02:55:49.448077 2026] [:error] [pid 12276:tid 140706928609024] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /ci/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "amf-FecsEMuHmMYmk65UyAAAAEw"]
[Tue Jul 28 02:55:49.644519 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "amf-FecsEMuHmMYmk65UyQAAAEE"]
[Tue Jul 28 02:55:49.645348 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "amf-FecsEMuHmMYmk65UyQAAAEE"]
[Tue Jul 28 02:55:49.645910 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "amf-FecsEMuHmMYmk65UyQAAAEE"]
[Tue Jul 28 02:55:49.646239 2026] [:error] [pid 12276:tid 140707020928768] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cd/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "amf-FecsEMuHmMYmk65UyQAAAEE"]
[Tue Jul 28 02:55:49.850504 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "amf-FecsEMuHmMYmk65UygAAAFg"]
[Tue Jul 28 02:55:49.851268 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "amf-FecsEMuHmMYmk65UygAAAFg"]
[Tue Jul 28 02:55:49.851803 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "amf-FecsEMuHmMYmk65UygAAAFg"]
[Tue Jul 28 02:55:49.852043 2026] [:error] [pid 12276:tid 140706827896576] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /jenkins/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "amf-FecsEMuHmMYmk65UygAAAFg"]
[Tue Jul 28 02:55:50.045691 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "amf-FucsEMuHmMYmk65UywAAAEg"]
[Tue Jul 28 02:55:50.046439 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "amf-FucsEMuHmMYmk65UywAAAEg"]
[Tue Jul 28 02:55:50.046964 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "amf-FucsEMuHmMYmk65UywAAAEg"]
[Tue Jul 28 02:55:50.047225 2026] [:error] [pid 12276:tid 140706962179840] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /gitlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "amf-FucsEMuHmMYmk65UywAAAEg"]
[Tue Jul 28 02:55:50.240879 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/github/.env"] [unique_id "amf-FucsEMuHmMYmk65UzAAAAFU"]
[Tue Jul 28 02:55:50.241727 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/github/.env"] [unique_id "amf-FucsEMuHmMYmk65UzAAAAFU"]
[Tue Jul 28 02:55:50.242255 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/github/.env"] [unique_id "amf-FucsEMuHmMYmk65UzAAAAFU"]
[Tue Jul 28 02:55:50.242532 2026] [:error] [pid 12276:tid 140706853074688] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /github/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/github/.env"] [unique_id "amf-FucsEMuHmMYmk65UzAAAAFU"]
[Tue Jul 28 02:55:50.439685 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "amf-FucsEMuHmMYmk65UzQAAAEo"]
[Tue Jul 28 02:55:50.440527 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "amf-FucsEMuHmMYmk65UzQAAAEo"]
[Tue Jul 28 02:55:50.441027 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "amf-FucsEMuHmMYmk65UzQAAAEo"]
[Tue Jul 28 02:55:50.441262 2026] [:error] [pid 12276:tid 140706945394432] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /actions/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "amf-FucsEMuHmMYmk65UzQAAAEo"]
[Tue Jul 28 02:55:50.635539 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "amf-FucsEMuHmMYmk65UzgAAAE8"]
[Tue Jul 28 02:55:50.636357 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "amf-FucsEMuHmMYmk65UzgAAAE8"]
[Tue Jul 28 02:55:50.636915 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "amf-FucsEMuHmMYmk65UzgAAAE8"]
[Tue Jul 28 02:55:50.637154 2026] [:error] [pid 12276:tid 140706903430912] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /circleci/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "amf-FucsEMuHmMYmk65UzgAAAE8"]
[Tue Jul 28 02:55:50.831594 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "amf-FucsEMuHmMYmk65UzwAAAFc"]
[Tue Jul 28 02:55:50.832126 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "amf-FucsEMuHmMYmk65UzwAAAFc"]
[Tue Jul 28 02:55:50.832513 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "amf-FucsEMuHmMYmk65UzwAAAFc"]
[Tue Jul 28 02:55:50.832780 2026] [:error] [pid 12276:tid 140706836289280] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /travis/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "amf-FucsEMuHmMYmk65UzwAAAFc"]
[Tue Jul 28 02:55:51.026857 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "amf-F-csEMuHmMYmk65U0AAAAFQ"]
[Tue Jul 28 02:55:51.027402 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "amf-F-csEMuHmMYmk65U0AAAAFQ"]
[Tue Jul 28 02:55:51.027773 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "amf-F-csEMuHmMYmk65U0AAAAFQ"]
[Tue Jul 28 02:55:51.027992 2026] [:error] [pid 12276:tid 140706861467392] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /buildkite/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "amf-F-csEMuHmMYmk65U0AAAAFQ"]
[Tue Jul 28 02:55:51.232090 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "amf-F-csEMuHmMYmk65U0QAAAEM"]
[Tue Jul 28 02:55:51.232950 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "amf-F-csEMuHmMYmk65U0QAAAEM"]
[Tue Jul 28 02:55:51.233479 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "amf-F-csEMuHmMYmk65U0QAAAEM"]
[Tue Jul 28 02:55:51.233745 2026] [:error] [pid 12276:tid 140707004143360] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mysql/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "amf-F-csEMuHmMYmk65U0QAAAEM"]
[Tue Jul 28 02:55:51.427987 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "amf-F-csEMuHmMYmk65U0gAAAFM"]
[Tue Jul 28 02:55:51.428753 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "amf-F-csEMuHmMYmk65U0gAAAFM"]
[Tue Jul 28 02:55:51.429234 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "amf-F-csEMuHmMYmk65U0gAAAFM"]
[Tue Jul 28 02:55:51.429471 2026] [:error] [pid 12276:tid 140706869860096] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /postgres/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "amf-F-csEMuHmMYmk65U0gAAAFM"]
[Tue Jul 28 02:55:51.625685 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "amf-F-csEMuHmMYmk65U0wAAAFY"]
[Tue Jul 28 02:55:51.626215 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "amf-F-csEMuHmMYmk65U0wAAAFY"]
[Tue Jul 28 02:55:51.626652 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "amf-F-csEMuHmMYmk65U0wAAAFY"]
[Tue Jul 28 02:55:51.626849 2026] [:error] [pid 12276:tid 140706844681984] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mongodb/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "amf-F-csEMuHmMYmk65U0wAAAFY"]
[Tue Jul 28 02:55:51.821427 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "amf-F-csEMuHmMYmk65U1AAAAFA"]
[Tue Jul 28 02:55:51.821916 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "amf-F-csEMuHmMYmk65U1AAAAFA"]
[Tue Jul 28 02:55:51.822300 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "amf-F-csEMuHmMYmk65U1AAAAFA"]
[Tue Jul 28 02:55:51.822537 2026] [:error] [pid 12276:tid 140706895038208] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /redis/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "amf-F-csEMuHmMYmk65U1AAAAFA"]
[Tue Jul 28 02:55:52.015517 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "amf-GOcsEMuHmMYmk65U1QAAAEQ"]
[Tue Jul 28 02:55:52.016169 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "amf-GOcsEMuHmMYmk65U1QAAAEQ"]
[Tue Jul 28 02:55:52.016613 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "amf-GOcsEMuHmMYmk65U1QAAAEQ"]
[Tue Jul 28 02:55:52.016775 2026] [:error] [pid 12276:tid 140706995750656] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /elasticsearch/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "amf-GOcsEMuHmMYmk65U1QAAAEQ"]
[Tue Jul 28 02:55:52.210906 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "amf-GOcsEMuHmMYmk65U1gAAAFI"]
[Tue Jul 28 02:55:52.211731 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "amf-GOcsEMuHmMYmk65U1gAAAFI"]
[Tue Jul 28 02:55:52.212227 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "amf-GOcsEMuHmMYmk65U1gAAAFI"]
[Tue Jul 28 02:55:52.212470 2026] [:error] [pid 12276:tid 140706878252800] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /rabbitmq/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "amf-GOcsEMuHmMYmk65U1gAAAFI"]
[Tue Jul 28 02:55:52.408680 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "amf-GOcsEMuHmMYmk65U1wAAAEc"]
[Tue Jul 28 02:55:52.409438 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "amf-GOcsEMuHmMYmk65U1wAAAEc"]
[Tue Jul 28 02:55:52.409947 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "amf-GOcsEMuHmMYmk65U1wAAAEc"]
[Tue Jul 28 02:55:52.410212 2026] [:error] [pid 12276:tid 140706970572544] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kafka/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "amf-GOcsEMuHmMYmk65U1wAAAEc"]
[Tue Jul 28 02:55:52.602766 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "amf-GOcsEMuHmMYmk65U2AAAAE4"]
[Tue Jul 28 02:55:52.603542 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "amf-GOcsEMuHmMYmk65U2AAAAE4"]
[Tue Jul 28 02:55:52.604091 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "amf-GOcsEMuHmMYmk65U2AAAAE4"]
[Tue Jul 28 02:55:52.604345 2026] [:error] [pid 12276:tid 140706911823616] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /queue/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "amf-GOcsEMuHmMYmk65U2AAAAE4"]
[Tue Jul 28 02:55:52.800268 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "amf-GOcsEMuHmMYmk65U2QAAAEY"]
[Tue Jul 28 02:55:52.801027 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "amf-GOcsEMuHmMYmk65U2QAAAEY"]
[Tue Jul 28 02:55:52.801517 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "amf-GOcsEMuHmMYmk65U2QAAAEY"]
[Tue Jul 28 02:55:52.801770 2026] [:error] [pid 12276:tid 140706978965248] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /worker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "amf-GOcsEMuHmMYmk65U2QAAAEY"]
[Tue Jul 28 02:55:52.998530 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/job/.env"] [unique_id "amf-GOcsEMuHmMYmk65U2gAAAEI"]
[Tue Jul 28 02:55:52.999298 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/job/.env"] [unique_id "amf-GOcsEMuHmMYmk65U2gAAAEI"]
[Tue Jul 28 02:55:52.999772 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/job/.env"] [unique_id "amf-GOcsEMuHmMYmk65U2gAAAEI"]
[Tue Jul 28 02:55:52.999999 2026] [:error] [pid 12276:tid 140707012536064] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /job/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/job/.env"] [unique_id "amf-GOcsEMuHmMYmk65U2gAAAEI"]
[Tue Jul 28 02:55:53.204280 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/test/.env"] [unique_id "amf-GecsEMuHmMYmk65U2wAAAEs"]
[Tue Jul 28 02:55:53.205080 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/test/.env"] [unique_id "amf-GecsEMuHmMYmk65U2wAAAEs"]
[Tue Jul 28 02:55:53.205605 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/test/.env"] [unique_id "amf-GecsEMuHmMYmk65U2wAAAEs"]
[Tue Jul 28 02:55:53.205871 2026] [:error] [pid 12276:tid 140706937001728] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /test/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/test/.env"] [unique_id "amf-GecsEMuHmMYmk65U2wAAAEs"]
[Tue Jul 28 02:55:53.400378 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "amf-GecsEMuHmMYmk65U3AAAAFE"]
[Tue Jul 28 02:55:53.401195 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "amf-GecsEMuHmMYmk65U3AAAAFE"]
[Tue Jul 28 02:55:53.401738 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "amf-GecsEMuHmMYmk65U3AAAAFE"]
[Tue Jul 28 02:55:53.401977 2026] [:error] [pid 12276:tid 140706886645504] [client 162.158.106.237:11700] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /qa/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "amf-GecsEMuHmMYmk65U3AAAAFE"]
[Tue Jul 28 02:55:54.087771 2026] [:error] [pid 12275:tid 140706945394432] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqWAAAAAo"]
[Tue Jul 28 02:55:54.088409 2026] [:error] [pid 12275:tid 140706945394432] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqWAAAAAo"]
[Tue Jul 28 02:55:54.088818 2026] [:error] [pid 12275:tid 140706945394432] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqWAAAAAo"]
[Tue Jul 28 02:55:54.088973 2026] [:error] [pid 12275:tid 140706945394432] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /preview/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqWAAAAAo"]
[Tue Jul 28 02:55:54.280992 2026] [:error] [pid 12275:tid 140706878252800] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqWgAAABI"]
[Tue Jul 28 02:55:54.281767 2026] [:error] [pid 12275:tid 140706878252800] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqWgAAABI"]
[Tue Jul 28 02:55:54.282236 2026] [:error] [pid 12275:tid 140706878252800] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqWgAAABI"]
[Tue Jul 28 02:55:54.282418 2026] [:error] [pid 12275:tid 140706878252800] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /beta/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqWgAAABI"]
[Tue Jul 28 02:55:54.475542 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqWwAAABM"]
[Tue Jul 28 02:55:54.476382 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqWwAAABM"]
[Tue Jul 28 02:55:54.476900 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqWwAAABM"]
[Tue Jul 28 02:55:54.477158 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uat/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqWwAAABM"]
[Tue Jul 28 02:55:54.668273 2026] [:error] [pid 12275:tid 140706827896576] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqXAAAABg"]
[Tue Jul 28 02:55:54.669050 2026] [:error] [pid 12275:tid 140706827896576] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqXAAAABg"]
[Tue Jul 28 02:55:54.669593 2026] [:error] [pid 12275:tid 140706827896576] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqXAAAABg"]
[Tue Jul 28 02:55:54.669817 2026] [:error] [pid 12275:tid 140706827896576] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /stage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqXAAAABg"]
[Tue Jul 28 02:55:54.860709 2026] [:error] [pid 12275:tid 140706920216320] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/development/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqXQAAAA0"]
[Tue Jul 28 02:55:54.861631 2026] [:error] [pid 12275:tid 140706920216320] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/development/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqXQAAAA0"]
[Tue Jul 28 02:55:54.862166 2026] [:error] [pid 12275:tid 140706920216320] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/development/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqXQAAAA0"]
[Tue Jul 28 02:55:54.862428 2026] [:error] [pid 12275:tid 140706920216320] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /development/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/development/.env"] [unique_id "amf-GnFwI8r7BFXGkAsqXQAAAA0"]
[Tue Jul 28 02:55:55.055687 2026] [:error] [pid 12275:tid 140706886645504] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/production/.env"] [unique_id "amf-G3FwI8r7BFXGkAsqXwAAABE"]
[Tue Jul 28 02:55:55.056512 2026] [:error] [pid 12275:tid 140706886645504] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/production/.env"] [unique_id "amf-G3FwI8r7BFXGkAsqXwAAABE"]
[Tue Jul 28 02:55:55.057077 2026] [:error] [pid 12275:tid 140706886645504] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/production/.env"] [unique_id "amf-G3FwI8r7BFXGkAsqXwAAABE"]
[Tue Jul 28 02:55:55.057335 2026] [:error] [pid 12275:tid 140706886645504] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /production/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/production/.env"] [unique_id "amf-G3FwI8r7BFXGkAsqXwAAABE"]
[Tue Jul 28 02:55:55.249074 2026] [:error] [pid 12275:tid 140706836289280] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "amf-G3FwI8r7BFXGkAsqYAAAABc"]
[Tue Jul 28 02:55:55.249727 2026] [:error] [pid 12275:tid 140706836289280] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "amf-G3FwI8r7BFXGkAsqYAAAABc"]
[Tue Jul 28 02:55:55.250229 2026] [:error] [pid 12275:tid 140706836289280] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "amf-G3FwI8r7BFXGkAsqYAAAABc"]
[Tue Jul 28 02:55:55.250488 2026] [:error] [pid 12275:tid 140706836289280] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "amf-G3FwI8r7BFXGkAsqYAAAABc"]
[Tue Jul 28 02:55:55.439530 2026] [:error] [pid 12275:tid 140706962179840] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.vault"] [unique_id "amf-G3FwI8r7BFXGkAsqYQAAAAg"]
[Tue Jul 28 02:55:55.440373 2026] [:error] [pid 12275:tid 140706962179840] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.vault"] [unique_id "amf-G3FwI8r7BFXGkAsqYQAAAAg"]
[Tue Jul 28 02:55:55.440904 2026] [:error] [pid 12275:tid 140706962179840] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.vault"] [unique_id "amf-G3FwI8r7BFXGkAsqYQAAAAg"]
[Tue Jul 28 02:55:55.441158 2026] [:error] [pid 12275:tid 140706962179840] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.vault"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.vault"] [unique_id "amf-G3FwI8r7BFXGkAsqYQAAAAg"]
[Tue Jul 28 02:55:55.633904 2026] [:error] [pid 12275:tid 140706953787136] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.fly"] [unique_id "amf-G3FwI8r7BFXGkAsqYgAAAAk"]
[Tue Jul 28 02:55:55.634730 2026] [:error] [pid 12275:tid 140706953787136] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.fly"] [unique_id "amf-G3FwI8r7BFXGkAsqYgAAAAk"]
[Tue Jul 28 02:55:55.635208 2026] [:error] [pid 12275:tid 140706953787136] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.fly"] [unique_id "amf-G3FwI8r7BFXGkAsqYgAAAAk"]
[Tue Jul 28 02:55:55.635441 2026] [:error] [pid 12275:tid 140706953787136] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.fly"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.fly"] [unique_id "amf-G3FwI8r7BFXGkAsqYgAAAAk"]
[Tue Jul 28 02:55:55.826634 2026] [:error] [pid 12275:tid 140706903430912] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.railway"] [unique_id "amf-G3FwI8r7BFXGkAsqZAAAAA8"]
[Tue Jul 28 02:55:55.827453 2026] [:error] [pid 12275:tid 140706903430912] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.railway"] [unique_id "amf-G3FwI8r7BFXGkAsqZAAAAA8"]
[Tue Jul 28 02:55:55.828020 2026] [:error] [pid 12275:tid 140706903430912] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.railway"] [unique_id "amf-G3FwI8r7BFXGkAsqZAAAAA8"]
[Tue Jul 28 02:55:55.828401 2026] [:error] [pid 12275:tid 140706903430912] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.railway"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.railway"] [unique_id "amf-G3FwI8r7BFXGkAsqZAAAAA8"]
[Tue Jul 28 02:55:56.021969 2026] [:error] [pid 12275:tid 140707012536064] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.render"] [unique_id "amf-HHFwI8r7BFXGkAsqZQAAAAI"]
[Tue Jul 28 02:55:56.022791 2026] [:error] [pid 12275:tid 140707012536064] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.render"] [unique_id "amf-HHFwI8r7BFXGkAsqZQAAAAI"]
[Tue Jul 28 02:55:56.023320 2026] [:error] [pid 12275:tid 140707012536064] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.render"] [unique_id "amf-HHFwI8r7BFXGkAsqZQAAAAI"]
[Tue Jul 28 02:55:56.023578 2026] [:error] [pid 12275:tid 140707012536064] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.render"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.render"] [unique_id "amf-HHFwI8r7BFXGkAsqZQAAAAI"]
[Tue Jul 28 02:55:56.215228 2026] [:error] [pid 12275:tid 140706844681984] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.vercel"] [unique_id "amf-HHFwI8r7BFXGkAsqZgAAABY"]
[Tue Jul 28 02:55:56.216800 2026] [:error] [pid 12275:tid 140706844681984] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.vercel"] [unique_id "amf-HHFwI8r7BFXGkAsqZgAAABY"]
[Tue Jul 28 02:55:56.217325 2026] [:error] [pid 12275:tid 140706844681984] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.vercel"] [unique_id "amf-HHFwI8r7BFXGkAsqZgAAABY"]
[Tue Jul 28 02:55:56.217540 2026] [:error] [pid 12275:tid 140706844681984] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.vercel"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.vercel"] [unique_id "amf-HHFwI8r7BFXGkAsqZgAAABY"]
[Tue Jul 28 02:55:56.413916 2026] [:error] [pid 12275:tid 140706861467392] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.supabase"] [unique_id "amf-HHFwI8r7BFXGkAsqaAAAABQ"]
[Tue Jul 28 02:55:56.414938 2026] [:error] [pid 12275:tid 140706861467392] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.supabase"] [unique_id "amf-HHFwI8r7BFXGkAsqaAAAABQ"]
[Tue Jul 28 02:55:56.415520 2026] [:error] [pid 12275:tid 140706861467392] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.supabase"] [unique_id "amf-HHFwI8r7BFXGkAsqaAAAABQ"]
[Tue Jul 28 02:55:56.415766 2026] [:error] [pid 12275:tid 140706861467392] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.supabase"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.supabase"] [unique_id "amf-HHFwI8r7BFXGkAsqaAAAABQ"]
[Tue Jul 28 02:55:56.609675 2026] [:error] [pid 12275:tid 140706987357952] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.neon"] [unique_id "amf-HHFwI8r7BFXGkAsqagAAAAU"]
[Tue Jul 28 02:55:56.610572 2026] [:error] [pid 12275:tid 140706987357952] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.neon"] [unique_id "amf-HHFwI8r7BFXGkAsqagAAAAU"]
[Tue Jul 28 02:55:56.611101 2026] [:error] [pid 12275:tid 140706987357952] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.neon"] [unique_id "amf-HHFwI8r7BFXGkAsqagAAAAU"]
[Tue Jul 28 02:55:56.611343 2026] [:error] [pid 12275:tid 140706987357952] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.neon"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.neon"] [unique_id "amf-HHFwI8r7BFXGkAsqagAAAAU"]
[Tue Jul 28 02:55:56.802405 2026] [:error] [pid 12275:tid 140707020928768] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amf-HHFwI8r7BFXGkAsqawAAAAE"]
[Tue Jul 28 02:55:56.803188 2026] [:error] [pid 12275:tid 140707020928768] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amf-HHFwI8r7BFXGkAsqawAAAAE"]
[Tue Jul 28 02:55:56.803761 2026] [:error] [pid 12275:tid 140707020928768] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amf-HHFwI8r7BFXGkAsqawAAAAE"]
[Tue Jul 28 02:55:56.992364 2026] [:error] [pid 12275:tid 140706945394432] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amf-HHFwI8r7BFXGkAsqbAAAAAo"]
[Tue Jul 28 02:55:56.992850 2026] [:error] [pid 12275:tid 140706945394432] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amf-HHFwI8r7BFXGkAsqbAAAAAo"]
[Tue Jul 28 02:55:56.993203 2026] [:error] [pid 12275:tid 140706945394432] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amf-HHFwI8r7BFXGkAsqbAAAAAo"]
[Tue Jul 28 02:55:57.181816 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/php.php"] [unique_id "amf-HXFwI8r7BFXGkAsqbQAAAAQ"]
[Tue Jul 28 02:55:57.182496 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/php.php"] [unique_id "amf-HXFwI8r7BFXGkAsqbQAAAAQ"]
[Tue Jul 28 02:55:57.182956 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/php.php"] [unique_id "amf-HXFwI8r7BFXGkAsqbQAAAAQ"]
[Tue Jul 28 02:55:57.374394 2026] [:error] [pid 12275:tid 140706878252800] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/i.php"] [unique_id "amf-HXFwI8r7BFXGkAsqbwAAABI"]
[Tue Jul 28 02:55:57.375212 2026] [:error] [pid 12275:tid 140706878252800] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/i.php"] [unique_id "amf-HXFwI8r7BFXGkAsqbwAAABI"]
[Tue Jul 28 02:55:57.375768 2026] [:error] [pid 12275:tid 140706878252800] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/i.php"] [unique_id "amf-HXFwI8r7BFXGkAsqbwAAABI"]
[Tue Jul 28 02:55:57.564629 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/pi.php"] [unique_id "amf-HXFwI8r7BFXGkAsqcAAAABM"]
[Tue Jul 28 02:55:57.565400 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/pi.php"] [unique_id "amf-HXFwI8r7BFXGkAsqcAAAABM"]
[Tue Jul 28 02:55:57.565958 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/pi.php"] [unique_id "amf-HXFwI8r7BFXGkAsqcAAAABM"]
[Tue Jul 28 02:55:57.762580 2026] [:error] [pid 12275:tid 140706827896576] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/pinfo.php"] [unique_id "amf-HXFwI8r7BFXGkAsqcQAAABg"]
[Tue Jul 28 02:55:57.769496 2026] [:error] [pid 12275:tid 140706827896576] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/pinfo.php"] [unique_id "amf-HXFwI8r7BFXGkAsqcQAAABg"]
[Tue Jul 28 02:55:57.769910 2026] [:error] [pid 12275:tid 140706827896576] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/pinfo.php"] [unique_id "amf-HXFwI8r7BFXGkAsqcQAAABg"]
[Tue Jul 28 02:55:57.957806 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/test.php"] [unique_id "amf-HXFwI8r7BFXGkAsqcgAAABU"]
[Tue Jul 28 02:55:57.958439 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/test.php"] [unique_id "amf-HXFwI8r7BFXGkAsqcgAAABU"]
[Tue Jul 28 02:55:57.958823 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/test.php"] [unique_id "amf-HXFwI8r7BFXGkAsqcgAAABU"]
[Tue Jul 28 02:55:58.164330 2026] [:error] [pid 12275:tid 140706886645504] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo"] [unique_id "amf-HnFwI8r7BFXGkAsqdAAAABE"]
[Tue Jul 28 02:55:58.165061 2026] [:error] [pid 12275:tid 140706886645504] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo"] [unique_id "amf-HnFwI8r7BFXGkAsqdAAAABE"]
[Tue Jul 28 02:55:58.165619 2026] [:error] [pid 12275:tid 140706886645504] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo"] [unique_id "amf-HnFwI8r7BFXGkAsqdAAAABE"]
[Tue Jul 28 02:55:58.354466 2026] [:error] [pid 12275:tid 140706836289280] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/p.php"] [unique_id "amf-HnFwI8r7BFXGkAsqdQAAABc"]
[Tue Jul 28 02:55:58.355336 2026] [:error] [pid 12275:tid 140706836289280] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/p.php"] [unique_id "amf-HnFwI8r7BFXGkAsqdQAAABc"]
[Tue Jul 28 02:55:58.355861 2026] [:error] [pid 12275:tid 140706836289280] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/p.php"] [unique_id "amf-HnFwI8r7BFXGkAsqdQAAABc"]
[Tue Jul 28 02:55:58.544425 2026] [:error] [pid 12275:tid 140706962179840] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/debug.php"] [unique_id "amf-HnFwI8r7BFXGkAsqdgAAAAg"]
[Tue Jul 28 02:55:58.545206 2026] [:error] [pid 12275:tid 140706962179840] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/debug.php"] [unique_id "amf-HnFwI8r7BFXGkAsqdgAAAAg"]
[Tue Jul 28 02:55:58.545672 2026] [:error] [pid 12275:tid 140706962179840] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/debug.php"] [unique_id "amf-HnFwI8r7BFXGkAsqdgAAAAg"]
[Tue Jul 28 02:55:58.736210 2026] [:error] [pid 12275:tid 140706911823616] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin/phpinfo.php"] [unique_id "amf-HnFwI8r7BFXGkAsqdwAAAA4"]
[Tue Jul 28 02:55:58.736777 2026] [:error] [pid 12275:tid 140706911823616] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin/phpinfo.php"] [unique_id "amf-HnFwI8r7BFXGkAsqdwAAAA4"]
[Tue Jul 28 02:55:58.737127 2026] [:error] [pid 12275:tid 140706911823616] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin/phpinfo.php"] [unique_id "amf-HnFwI8r7BFXGkAsqdwAAAA4"]
[Tue Jul 28 02:55:58.930874 2026] [:error] [pid 12275:tid 140706953787136] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/test/phpinfo.php"] [unique_id "amf-HnFwI8r7BFXGkAsqeAAAAAk"]
[Tue Jul 28 02:55:58.931623 2026] [:error] [pid 12275:tid 140706953787136] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/test/phpinfo.php"] [unique_id "amf-HnFwI8r7BFXGkAsqeAAAAAk"]
[Tue Jul 28 02:55:58.932103 2026] [:error] [pid 12275:tid 140706953787136] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/test/phpinfo.php"] [unique_id "amf-HnFwI8r7BFXGkAsqeAAAAAk"]
[Tue Jul 28 02:55:59.121124 2026] [:error] [pid 12275:tid 140706903430912] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dev/phpinfo.php"] [unique_id "amf-H3FwI8r7BFXGkAsqeQAAAA8"]
[Tue Jul 28 02:55:59.121662 2026] [:error] [pid 12275:tid 140706903430912] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dev/phpinfo.php"] [unique_id "amf-H3FwI8r7BFXGkAsqeQAAAA8"]
[Tue Jul 28 02:55:59.122173 2026] [:error] [pid 12275:tid 140706903430912] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dev/phpinfo.php"] [unique_id "amf-H3FwI8r7BFXGkAsqeQAAAA8"]
[Tue Jul 28 02:55:59.313189 2026] [:error] [pid 12275:tid 140706978965248] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/old/phpinfo.php"] [unique_id "amf-H3FwI8r7BFXGkAsqewAAAAY"]
[Tue Jul 28 02:55:59.314113 2026] [:error] [pid 12275:tid 140706978965248] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/old/phpinfo.php"] [unique_id "amf-H3FwI8r7BFXGkAsqewAAAAY"]
[Tue Jul 28 02:55:59.314669 2026] [:error] [pid 12275:tid 140706978965248] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/old/phpinfo.php"] [unique_id "amf-H3FwI8r7BFXGkAsqewAAAAY"]
[Tue Jul 28 02:55:59.506721 2026] [:error] [pid 12275:tid 140706844681984] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/tmp/phpinfo.php"] [unique_id "amf-H3FwI8r7BFXGkAsqfAAAABY"]
[Tue Jul 28 02:55:59.507596 2026] [:error] [pid 12275:tid 140706844681984] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/tmp/phpinfo.php"] [unique_id "amf-H3FwI8r7BFXGkAsqfAAAABY"]
[Tue Jul 28 02:55:59.508148 2026] [:error] [pid 12275:tid 140706844681984] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/tmp/phpinfo.php"] [unique_id "amf-H3FwI8r7BFXGkAsqfAAAABY"]
[Tue Jul 28 02:55:59.699709 2026] [:error] [pid 12275:tid 140706861467392] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/public/phpinfo.php"] [unique_id "amf-H3FwI8r7BFXGkAsqfQAAABQ"]
[Tue Jul 28 02:55:59.700444 2026] [:error] [pid 12275:tid 140706861467392] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/public/phpinfo.php"] [unique_id "amf-H3FwI8r7BFXGkAsqfQAAABQ"]
[Tue Jul 28 02:55:59.700894 2026] [:error] [pid 12275:tid 140706861467392] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/public/phpinfo.php"] [unique_id "amf-H3FwI8r7BFXGkAsqfQAAABQ"]
[Tue Jul 28 02:55:59.891483 2026] [:error] [pid 12275:tid 140707004143360] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/info"] [unique_id "amf-H3FwI8r7BFXGkAsqfgAAAAM"]
[Tue Jul 28 02:55:59.892035 2026] [:error] [pid 12275:tid 140707004143360] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/info"] [unique_id "amf-H3FwI8r7BFXGkAsqfgAAAAM"]
[Tue Jul 28 02:55:59.892408 2026] [:error] [pid 12275:tid 140707004143360] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/info"] [unique_id "amf-H3FwI8r7BFXGkAsqfgAAAAM"]
[Tue Jul 28 02:56:00.094372 2026] [:error] [pid 12275:tid 140706937001728] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amf-IHFwI8r7BFXGkAsqgAAAAAs"]
[Tue Jul 28 02:56:00.095485 2026] [:error] [pid 12275:tid 140706937001728] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amf-IHFwI8r7BFXGkAsqgAAAAAs"]
[Tue Jul 28 02:56:00.096091 2026] [:error] [pid 12275:tid 140706937001728] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amf-IHFwI8r7BFXGkAsqgAAAAAs"]
[Tue Jul 28 02:56:00.286545 2026] [:error] [pid 12275:tid 140707020928768] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpversion.php"] [unique_id "amf-IHFwI8r7BFXGkAsqgQAAAAE"]
[Tue Jul 28 02:56:00.287429 2026] [:error] [pid 12275:tid 140707020928768] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpversion.php"] [unique_id "amf-IHFwI8r7BFXGkAsqgQAAAAE"]
[Tue Jul 28 02:56:00.287857 2026] [:error] [pid 12275:tid 140707020928768] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpversion.php"] [unique_id "amf-IHFwI8r7BFXGkAsqgQAAAAE"]
[Tue Jul 28 02:56:00.481067 2026] [:error] [pid 12275:tid 140706895038208] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_phpinfo.php"] [unique_id "amf-IHFwI8r7BFXGkAsqggAAABA"]
[Tue Jul 28 02:56:00.481700 2026] [:error] [pid 12275:tid 140706895038208] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_phpinfo.php"] [unique_id "amf-IHFwI8r7BFXGkAsqggAAABA"]
[Tue Jul 28 02:56:00.482052 2026] [:error] [pid 12275:tid 140706895038208] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_phpinfo.php"] [unique_id "amf-IHFwI8r7BFXGkAsqggAAABA"]
[Tue Jul 28 02:56:00.673042 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/old_phpinfo.php"] [unique_id "amf-IHFwI8r7BFXGkAsqgwAAAAQ"]
[Tue Jul 28 02:56:00.673788 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/old_phpinfo.php"] [unique_id "amf-IHFwI8r7BFXGkAsqgwAAAAQ"]
[Tue Jul 28 02:56:00.674219 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/old_phpinfo.php"] [unique_id "amf-IHFwI8r7BFXGkAsqgwAAAAQ"]
[Tue Jul 28 02:56:00.864785 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server-info.php"] [unique_id "amf-IHFwI8r7BFXGkAsqhQAAABM"]
[Tue Jul 28 02:56:00.865562 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/server-info.php"] [unique_id "amf-IHFwI8r7BFXGkAsqhQAAABM"]
[Tue Jul 28 02:56:00.866067 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/server-info.php"] [unique_id "amf-IHFwI8r7BFXGkAsqhQAAABM"]
[Tue Jul 28 02:56:01.057203 2026] [:error] [pid 12275:tid 140706928609024] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server-status.php"] [unique_id "amf-IXFwI8r7BFXGkAsqhwAAAAw"]
[Tue Jul 28 02:56:01.058055 2026] [:error] [pid 12275:tid 140706928609024] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/server-status.php"] [unique_id "amf-IXFwI8r7BFXGkAsqhwAAAAw"]
[Tue Jul 28 02:56:01.058583 2026] [:error] [pid 12275:tid 140706928609024] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/server-status.php"] [unique_id "amf-IXFwI8r7BFXGkAsqhwAAAAw"]
[Tue Jul 28 02:56:01.247396 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_profiler/phpinfo"] [unique_id "amf-IXFwI8r7BFXGkAsqiAAAABU"]
[Tue Jul 28 02:56:01.248177 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_profiler/phpinfo"] [unique_id "amf-IXFwI8r7BFXGkAsqiAAAABU"]
[Tue Jul 28 02:56:01.248707 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_profiler/phpinfo"] [unique_id "amf-IXFwI8r7BFXGkAsqiAAAABU"]
[Tue Jul 28 02:56:01.440585 2026] [:error] [pid 12275:tid 140706886645504] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_environment"] [unique_id "amf-IXFwI8r7BFXGkAsqiQAAABE"]
[Tue Jul 28 02:56:01.441408 2026] [:error] [pid 12275:tid 140706886645504] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_environment"] [unique_id "amf-IXFwI8r7BFXGkAsqiQAAABE"]
[Tue Jul 28 02:56:01.441929 2026] [:error] [pid 12275:tid 140706886645504] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_environment"] [unique_id "amf-IXFwI8r7BFXGkAsqiQAAABE"]
[Tue Jul 28 02:56:01.632694 2026] [:error] [pid 12275:tid 140706962179840] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/webroot/index.php/_environment"] [unique_id "amf-IXFwI8r7BFXGkAsqiwAAAAg"]
[Tue Jul 28 02:56:01.633683 2026] [:error] [pid 12275:tid 140706962179840] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/webroot/index.php/_environment"] [unique_id "amf-IXFwI8r7BFXGkAsqiwAAAAg"]
[Tue Jul 28 02:56:01.634243 2026] [:error] [pid 12275:tid 140706962179840] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/webroot/index.php/_environment"] [unique_id "amf-IXFwI8r7BFXGkAsqiwAAAAg"]
[Tue Jul 28 02:56:01.825440 2026] [:error] [pid 12275:tid 140706920216320] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mail/phpinfo.php"] [unique_id "amf-IXFwI8r7BFXGkAsqjAAAAA0"]
[Tue Jul 28 02:56:01.826400 2026] [:error] [pid 12275:tid 140706920216320] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mail/phpinfo.php"] [unique_id "amf-IXFwI8r7BFXGkAsqjAAAAA0"]
[Tue Jul 28 02:56:01.826962 2026] [:error] [pid 12275:tid 140706920216320] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mail/phpinfo.php"] [unique_id "amf-IXFwI8r7BFXGkAsqjAAAAA0"]
[Tue Jul 28 02:56:02.022603 2026] [:error] [pid 12275:tid 140706911823616] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cpanel/phpinfo.php"] [unique_id "amf-InFwI8r7BFXGkAsqjQAAAA4"]
[Tue Jul 28 02:56:03.160824 2026] [:error] [pid 12275:tid 140707012536064] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/hosting/phpinfo.php"] [unique_id "amf-I3FwI8r7BFXGkAsqkgAAAAI"]
[Tue Jul 28 02:56:03.161483 2026] [:error] [pid 12275:tid 140707012536064] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/hosting/phpinfo.php"] [unique_id "amf-I3FwI8r7BFXGkAsqkgAAAAI"]
[Tue Jul 28 02:56:03.161874 2026] [:error] [pid 12275:tid 140707012536064] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/hosting/phpinfo.php"] [unique_id "amf-I3FwI8r7BFXGkAsqkgAAAAI"]
[Tue Jul 28 02:56:03.356610 2026] [:error] [pid 12275:tid 140707004143360] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/webmail/phpinfo.php"] [unique_id "amf-I3FwI8r7BFXGkAsqkwAAAAM"]
[Tue Jul 28 02:56:03.357321 2026] [:error] [pid 12275:tid 140707004143360] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/webmail/phpinfo.php"] [unique_id "amf-I3FwI8r7BFXGkAsqkwAAAAM"]
[Tue Jul 28 02:56:03.357888 2026] [:error] [pid 12275:tid 140707004143360] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/webmail/phpinfo.php"] [unique_id "amf-I3FwI8r7BFXGkAsqkwAAAAM"]
[Tue Jul 28 02:56:03.546727 2026] [:error] [pid 12275:tid 140706937001728] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/smtp/phpinfo.php"] [unique_id "amf-I3FwI8r7BFXGkAsqlAAAAAs"]
[Tue Jul 28 02:56:03.547473 2026] [:error] [pid 12275:tid 140706937001728] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/smtp/phpinfo.php"] [unique_id "amf-I3FwI8r7BFXGkAsqlAAAAAs"]
[Tue Jul 28 02:56:03.547862 2026] [:error] [pid 12275:tid 140706937001728] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/smtp/phpinfo.php"] [unique_id "amf-I3FwI8r7BFXGkAsqlAAAAAs"]
[Tue Jul 28 02:56:03.750211 2026] [:error] [pid 12275:tid 140706895038208] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amf-I3FwI8r7BFXGkAsqlgAAABA"]
[Tue Jul 28 02:56:03.751296 2026] [:error] [pid 12275:tid 140706895038208] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amf-I3FwI8r7BFXGkAsqlgAAABA"]
[Tue Jul 28 02:56:03.751945 2026] [:error] [pid 12275:tid 140706895038208] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amf-I3FwI8r7BFXGkAsqlgAAABA"]
[Tue Jul 28 02:56:03.945528 2026] [:error] [pid 12275:tid 140706987357952] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.old"] [unique_id "amf-I3FwI8r7BFXGkAsqlwAAAAU"]
[Tue Jul 28 02:56:03.946393 2026] [:error] [pid 12275:tid 140706987357952] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.old"] [unique_id "amf-I3FwI8r7BFXGkAsqlwAAAAU"]
[Tue Jul 28 02:56:03.946770 2026] [:error] [pid 12275:tid 140706987357952] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.old"] [unique_id "amf-I3FwI8r7BFXGkAsqlwAAAAU"]
[Tue Jul 28 02:56:04.136196 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "amf-JHFwI8r7BFXGkAsqmAAAAAQ"]
[Tue Jul 28 02:56:04.137061 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "amf-JHFwI8r7BFXGkAsqmAAAAAQ"]
[Tue Jul 28 02:56:04.137373 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Pattern match "\\\\.[^.~]+~(?:/.*|)$" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1060"] [id "920500"] [msg "Attempt to access a backup or working file"] [data ".php~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "amf-JHFwI8r7BFXGkAsqmAAAAAQ"]
[Tue Jul 28 02:56:04.137654 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "amf-JHFwI8r7BFXGkAsqmAAAAAQ"]
[Tue Jul 28 02:56:04.334408 2026] [:error] [pid 12275:tid 140706945394432] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amf-JHFwI8r7BFXGkAsqmQAAAAo"]
[Tue Jul 28 02:56:04.335184 2026] [:error] [pid 12275:tid 140706945394432] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amf-JHFwI8r7BFXGkAsqmQAAAAo"]
[Tue Jul 28 02:56:04.335844 2026] [:error] [pid 12275:tid 140706945394432] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amf-JHFwI8r7BFXGkAsqmQAAAAo"]
[Tue Jul 28 02:56:04.530744 2026] [:error] [pid 12275:tid 140706928609024] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.save"] [unique_id "amf-JHFwI8r7BFXGkAsqmwAAAAw"]
[Tue Jul 28 02:56:04.531325 2026] [:error] [pid 12275:tid 140706928609024] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.save"] [unique_id "amf-JHFwI8r7BFXGkAsqmwAAAAw"]
[Tue Jul 28 02:56:04.531697 2026] [:error] [pid 12275:tid 140706928609024] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.save"] [unique_id "amf-JHFwI8r7BFXGkAsqmwAAAAw"]
[Tue Jul 28 02:56:04.720335 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/staging/phpinfo.php"] [unique_id "amf-JHFwI8r7BFXGkAsqnAAAABU"]
[Tue Jul 28 02:56:04.721175 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/staging/phpinfo.php"] [unique_id "amf-JHFwI8r7BFXGkAsqnAAAABU"]
[Tue Jul 28 02:56:04.721751 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/staging/phpinfo.php"] [unique_id "amf-JHFwI8r7BFXGkAsqnAAAABU"]
[Tue Jul 28 02:56:04.911703 2026] [:error] [pid 12275:tid 140706962179840] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/beta/phpinfo.php"] [unique_id "amf-JHFwI8r7BFXGkAsqnQAAAAg"]
[Tue Jul 28 02:56:04.912450 2026] [:error] [pid 12275:tid 140706962179840] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/beta/phpinfo.php"] [unique_id "amf-JHFwI8r7BFXGkAsqnQAAAAg"]
[Tue Jul 28 02:56:04.912886 2026] [:error] [pid 12275:tid 140706962179840] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/beta/phpinfo.php"] [unique_id "amf-JHFwI8r7BFXGkAsqnQAAAAg"]
[Tue Jul 28 02:56:05.103366 2026] [:error] [pid 12275:tid 140706911823616] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/uat/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqnwAAAA4"]
[Tue Jul 28 02:56:05.104203 2026] [:error] [pid 12275:tid 140706911823616] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/uat/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqnwAAAA4"]
[Tue Jul 28 02:56:05.104706 2026] [:error] [pid 12275:tid 140706911823616] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/uat/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqnwAAAA4"]
[Tue Jul 28 02:56:05.294526 2026] [:error] [pid 12275:tid 140706836289280] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/qa/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqoAAAABc"]
[Tue Jul 28 02:56:05.295172 2026] [:error] [pid 12275:tid 140706836289280] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/qa/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqoAAAABc"]
[Tue Jul 28 02:56:05.295661 2026] [:error] [pid 12275:tid 140706836289280] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/qa/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqoAAAABc"]
[Tue Jul 28 02:56:05.484494 2026] [:error] [pid 12275:tid 140706903430912] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/preview/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqoQAAAA8"]
[Tue Jul 28 02:56:05.485106 2026] [:error] [pid 12275:tid 140706903430912] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/preview/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqoQAAAA8"]
[Tue Jul 28 02:56:05.485486 2026] [:error] [pid 12275:tid 140706903430912] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/preview/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqoQAAAA8"]
[Tue Jul 28 02:56:05.675442 2026] [:error] [pid 12275:tid 140706978965248] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/www/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqogAAAAY"]
[Tue Jul 28 02:56:05.676315 2026] [:error] [pid 12275:tid 140706978965248] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/www/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqogAAAAY"]
[Tue Jul 28 02:56:05.676851 2026] [:error] [pid 12275:tid 140706978965248] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/www/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqogAAAAY"]
[Tue Jul 28 02:56:05.872629 2026] [:error] [pid 12275:tid 140707012536064] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqpAAAAAI"]
[Tue Jul 28 02:56:05.873455 2026] [:error] [pid 12275:tid 140707012536064] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqpAAAAAI"]
[Tue Jul 28 02:56:05.873993 2026] [:error] [pid 12275:tid 140707012536064] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "amf-JXFwI8r7BFXGkAsqpAAAAAI"]
[Tue Jul 28 02:56:06.066637 2026] [:error] [pid 12275:tid 140706937001728] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/public_html/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqpgAAAAs"]
[Tue Jul 28 02:56:06.067705 2026] [:error] [pid 12275:tid 140706937001728] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/public_html/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqpgAAAAs"]
[Tue Jul 28 02:56:06.068326 2026] [:error] [pid 12275:tid 140706937001728] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/public_html/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqpgAAAAs"]
[Tue Jul 28 02:56:06.275154 2026] [:error] [pid 12275:tid 140706987357952] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/site/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqqQAAAAU"]
[Tue Jul 28 02:56:06.275954 2026] [:error] [pid 12275:tid 140706987357952] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/site/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqqQAAAAU"]
[Tue Jul 28 02:56:06.276501 2026] [:error] [pid 12275:tid 140706987357952] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/site/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqqQAAAAU"]
[Tue Jul 28 02:56:06.467860 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/docs/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqqgAAAAQ"]
[Tue Jul 28 02:56:06.468833 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/docs/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqqgAAAAQ"]
[Tue Jul 28 02:56:06.469487 2026] [:error] [pid 12275:tid 140706995750656] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/docs/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqqgAAAAQ"]
[Tue Jul 28 02:56:06.666502 2026] [:error] [pid 12275:tid 140707020928768] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqqwAAAAE"]
[Tue Jul 28 02:56:06.667199 2026] [:error] [pid 12275:tid 140707020928768] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqqwAAAAE"]
[Tue Jul 28 02:56:06.667725 2026] [:error] [pid 12275:tid 140707020928768] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqqwAAAAE"]
[Tue Jul 28 02:56:06.859873 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/administrator/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqrQAAABM"]
[Tue Jul 28 02:56:06.860498 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/administrator/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqrQAAABM"]
[Tue Jul 28 02:56:06.860963 2026] [:error] [pid 12275:tid 140706869860096] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/administrator/phpinfo.php"] [unique_id "amf-JnFwI8r7BFXGkAsqrQAAABM"]
[Tue Jul 28 02:56:07.057193 2026] [:error] [pid 12275:tid 140706928609024] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/core/phpinfo.php"] [unique_id "amf-J3FwI8r7BFXGkAsqrgAAAAw"]
[Tue Jul 28 02:56:07.058019 2026] [:error] [pid 12275:tid 140706928609024] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/core/phpinfo.php"] [unique_id "amf-J3FwI8r7BFXGkAsqrgAAAAw"]
[Tue Jul 28 02:56:07.058731 2026] [:error] [pid 12275:tid 140706928609024] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/core/phpinfo.php"] [unique_id "amf-J3FwI8r7BFXGkAsqrgAAAAw"]
[Tue Jul 28 02:56:07.248014 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/includes/phpinfo.php"] [unique_id "amf-J3FwI8r7BFXGkAsqsAAAABU"]
[Tue Jul 28 02:56:07.249151 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/includes/phpinfo.php"] [unique_id "amf-J3FwI8r7BFXGkAsqsAAAABU"]
[Tue Jul 28 02:56:07.249955 2026] [:error] [pid 12275:tid 140706853074688] [client 162.158.106.237:13796] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/includes/phpinfo.php"] [unique_id "amf-J3FwI8r7BFXGkAsqsAAAABU"]
[Tue Jul 28 03:01:02.269571 2026] [:error] [pid 12275:tid 140706853074688] [client 172.70.248.40:13296] [client 172.70.248.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amf_TnFwI8r7BFXGkAstcwAAABU"]
[Tue Jul 28 03:01:02.270465 2026] [:error] [pid 12275:tid 140706853074688] [client 172.70.248.40:13296] [client 172.70.248.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amf_TnFwI8r7BFXGkAstcwAAABU"]
[Tue Jul 28 03:01:02.271097 2026] [:error] [pid 12275:tid 140706853074688] [client 172.70.248.40:13296] [client 172.70.248.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amf_TnFwI8r7BFXGkAstcwAAABU"]
[Tue Jul 28 03:17:20.404322 2026] [:error] [pid 21545:tid 140706886645504] [client 172.71.103.41:14155] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgDIJhXfYDIcpslIWNgOwAAAZE"]
[Tue Jul 28 03:17:20.405214 2026] [:error] [pid 21545:tid 140706886645504] [client 172.71.103.41:14155] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgDIJhXfYDIcpslIWNgOwAAAZE"]
[Tue Jul 28 03:17:20.405748 2026] [:error] [pid 21545:tid 140706886645504] [client 172.71.103.41:14155] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgDIJhXfYDIcpslIWNgOwAAAZE"]
[Tue Jul 28 03:17:20.478647 2026] [:error] [pid 12277:tid 140706903430912] [client 172.71.102.115:12110] [client 172.71.102.115] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgDIBwjcb8HQE21kA4bVQAAAI8"]
[Tue Jul 28 03:17:20.501642 2026] [:error] [pid 12277:tid 140706903430912] [client 172.71.102.115:12110] [client 172.71.102.115] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgDIBwjcb8HQE21kA4bVQAAAI8"]
[Tue Jul 28 03:17:20.504292 2026] [:error] [pid 12277:tid 140706903430912] [client 172.71.102.115:12110] [client 172.71.102.115] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|multipart/form-data|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgDIBwjcb8HQE21kA4bVQAAAI8"]
[Tue Jul 28 03:17:20.506609 2026] [:error] [pid 12277:tid 140706903430912] [client 172.71.102.115:12110] [client 172.71.102.115] ModSecurity: Warning. Found 2 byte(s) in ARGS:1 outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:1={}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgDIBwjcb8HQE21kA4bVQAAAI8"]
[Tue Jul 28 03:17:20.506673 2026] [:error] [pid 12277:tid 140706903430912] [client 172.71.102.115:12110] [client 172.71.102.115] ModSecurity: Warning. Found 5 byte(s) in ARGS:0 outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:0=[\\x22$1:a:a\\x22]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgDIBwjcb8HQE21kA4bVQAAAI8"]
[Tue Jul 28 03:17:20.506735 2026] [:error] [pid 12277:tid 140706903430912] [client 172.71.102.115:12110] [client 172.71.102.115] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgDIBwjcb8HQE21kA4bVQAAAI8"]
[Tue Jul 28 03:17:21.429946 2026] [:error] [pid 12277:tid 140706903430912] [client 172.71.102.115:12110] [client 172.71.102.115] ModSecurity: Warning. Pattern match "(?i:[\\"'`]\\\\s*?(?:(?:n(?:and|ot)|(?:x?x)?or|between|\\\\|\\\\||and|div|&&)\\\\s+[\\\\s\\\\w]+=\\\\s*?\\\\w+\\\\s*?having\\\\s+|like(?:\\\\s+[\\\\s\\\\w]+=\\\\s*?\\\\w+\\\\s*?having\\\\s+|\\\\W*?[\\"'`\\\\d])|[^?\\\\w\\\\s=.,;)(]++\\\\s*?[(@\\"'`]*?\\\\s*?\\\\w+\\\\W+\\\\w|\\\\*\\\\s*?\\\\w+\\\\W+[\\"'`])|(?:unio ..." at ARGS:0. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "750"] [id "942260"] [msg "Detects basic SQL authentication bypass attempts 2/3"] [data "Matched Data: \\x22$1:a found within ARGS:0: [\\x22$1:a:a\\x22]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgDIBwjcb8HQE21kA4bVQAAAI8"]
[Tue Jul 28 03:17:21.857233 2026] [:error] [pid 12277:tid 140706903430912] [client 172.71.102.115:12110] [client 172.71.102.115] ModSecurity: Warning. Pattern match "[\\"'`][\\\\s\\\\d]*?[^\\\\w\\\\s]\\\\W*?\\\\d\\\\W*?.*?[\\"'`\\\\d]" at ARGS:0. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1344"] [id "942490"] [msg "Detects classic SQL injection probings 3/3"] [data "Matched Data: \\x22$1:a:a\\x22 found within ARGS:0: [\\x22$1:a:a\\x22]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgDIBwjcb8HQE21kA4bVQAAAI8"]
[Tue Jul 28 03:17:21.857829 2026] [:error] [pid 12277:tid 140706903430912] [client 172.71.102.115:12110] [client 172.71.102.115] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){6})" at ARGS:0. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1413"] [id "942431"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6)"] [data "Matched Data: [\\x22$1:a:a\\x22 found within ARGS:0: [\\x22$1:a:a\\x22]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgDIBwjcb8HQE21kA4bVQAAAI8"]
[Tue Jul 28 03:17:21.859198 2026] [:error] [pid 12277:tid 140706903430912] [client 172.71.102.115:12110] [client 172.71.102.115] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS:1. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: {} found within ARGS:1: {}"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgDIBwjcb8HQE21kA4bVQAAAI8"]
[Tue Jul 28 03:17:21.859262 2026] [:error] [pid 12277:tid 140706903430912] [client 172.71.102.115:12110] [client 172.71.102.115] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS:0. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [\\x22 found within ARGS:0: [\\x22$1:a:a\\x22]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgDIBwjcb8HQE21kA4bVQAAAI8"]
[Tue Jul 28 03:17:21.892595 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.103.41:14155] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/en"] [unique_id "amgDIZhXfYDIcpslIWNgQQAAAYA"]
[Tue Jul 28 03:17:21.914191 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.103.41:14155] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/en"] [unique_id "amgDIZhXfYDIcpslIWNgQQAAAYA"]
[Tue Jul 28 03:17:21.917426 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.103.41:14155] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|multipart/form-data|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/en"] [unique_id "amgDIZhXfYDIcpslIWNgQQAAAYA"]
[Tue Jul 28 03:17:21.919897 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.103.41:14155] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in ARGS:1 outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:1={}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/en"] [unique_id "amgDIZhXfYDIcpslIWNgQQAAAYA"]
[Tue Jul 28 03:17:21.919951 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.103.41:14155] [client 172.71.103.41] ModSecurity: Warning. Found 5 byte(s) in ARGS:0 outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:0=[\\x22$1:a:a\\x22]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/en"] [unique_id "amgDIZhXfYDIcpslIWNgQQAAAYA"]
[Tue Jul 28 03:17:21.920028 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.103.41:14155] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/en"] [unique_id "amgDIZhXfYDIcpslIWNgQQAAAYA"]
[Tue Jul 28 03:17:22.650916 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.103.41:14155] [client 172.71.103.41] ModSecurity: Warning. Pattern match "(?i:[\\"'`]\\\\s*?(?:(?:n(?:and|ot)|(?:x?x)?or|between|\\\\|\\\\||and|div|&&)\\\\s+[\\\\s\\\\w]+=\\\\s*?\\\\w+\\\\s*?having\\\\s+|like(?:\\\\s+[\\\\s\\\\w]+=\\\\s*?\\\\w+\\\\s*?having\\\\s+|\\\\W*?[\\"'`\\\\d])|[^?\\\\w\\\\s=.,;)(]++\\\\s*?[(@\\"'`]*?\\\\s*?\\\\w+\\\\W+\\\\w|\\\\*\\\\s*?\\\\w+\\\\W+[\\"'`])|(?:unio ..." at ARGS:0. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "750"] [id "942260"] [msg "Detects basic SQL authentication bypass attempts 2/3"] [data "Matched Data: \\x22$1:a found within ARGS:0: [\\x22$1:a:a\\x22]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/en"] [unique_id "amgDIZhXfYDIcpslIWNgQQAAAYA"]
[Tue Jul 28 03:17:23.016867 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.103.41:14155] [client 172.71.103.41] ModSecurity: Warning. Pattern match "[\\"'`][\\\\s\\\\d]*?[^\\\\w\\\\s]\\\\W*?\\\\d\\\\W*?.*?[\\"'`\\\\d]" at ARGS:0. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1344"] [id "942490"] [msg "Detects classic SQL injection probings 3/3"] [data "Matched Data: \\x22$1:a:a\\x22 found within ARGS:0: [\\x22$1:a:a\\x22]"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/en"] [unique_id "amgDIZhXfYDIcpslIWNgQQAAAYA"]
[Tue Jul 28 03:17:23.017595 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.103.41:14155] [client 172.71.103.41] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){6})" at ARGS:0. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1413"] [id "942431"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6)"] [data "Matched Data: [\\x22$1:a:a\\x22 found within ARGS:0: [\\x22$1:a:a\\x22]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "sbf-consultancy.com"] [uri "/en"] [unique_id "amgDIZhXfYDIcpslIWNgQQAAAYA"]
[Tue Jul 28 03:17:23.019181 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.103.41:14155] [client 172.71.103.41] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS:1. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: {} found within ARGS:1: {}"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/en"] [unique_id "amgDIZhXfYDIcpslIWNgQQAAAYA"]
[Tue Jul 28 03:17:23.019259 2026] [:error] [pid 21545:tid 140707103270656] [client 172.71.103.41:14155] [client 172.71.103.41] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){2})" at ARGS:0. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1589"] [id "942432"] [msg "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)"] [data "Matched Data: [\\x22 found within ARGS:0: [\\x22$1:a:a\\x22]"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/en"] [unique_id "amgDIZhXfYDIcpslIWNgQQAAAYA"]
[Tue Jul 28 03:26:52.466768 2026] [:error] [pid 12380:tid 140706920216320] [client 104.22.17.80:11526] [client 104.22.17.80] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amgFXKaChfbWW0CZ_hoy3AAAAM0"]
[Tue Jul 28 03:26:52.467762 2026] [:error] [pid 12380:tid 140706920216320] [client 104.22.17.80:11526] [client 104.22.17.80] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amgFXKaChfbWW0CZ_hoy3AAAAM0"]
[Tue Jul 28 03:26:52.468255 2026] [:error] [pid 12380:tid 140706920216320] [client 104.22.17.80:11526] [client 104.22.17.80] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amgFXKaChfbWW0CZ_hoy3AAAAM0"]
[Tue Jul 28 03:26:53.155368 2026] [:error] [pid 12380:tid 140706878252800] [client 162.158.167.47:11444] [client 162.158.167.47] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amgFXaaChfbWW0CZ_hoy4wAAANI"]
[Tue Jul 28 03:26:53.156382 2026] [:error] [pid 12380:tid 140706878252800] [client 162.158.167.47:11444] [client 162.158.167.47] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amgFXaaChfbWW0CZ_hoy4wAAANI"]
[Tue Jul 28 03:26:53.157020 2026] [:error] [pid 12380:tid 140706878252800] [client 162.158.167.47:11444] [client 162.158.167.47] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amgFXaaChfbWW0CZ_hoy4wAAANI"]
[Tue Jul 28 03:40:55.303670 2026] [:error] [pid 711:tid 139944538343168] [client 172.70.38.129:14253] [client 172.70.38.129] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgIp7b3Hg56MtJU4vy-ogAAARA"]
[Tue Jul 28 03:40:55.307408 2026] [:error] [pid 711:tid 139944538343168] [client 172.70.38.129:14253] [client 172.70.38.129] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgIp7b3Hg56MtJU4vy-ogAAARA"]
[Tue Jul 28 03:40:55.308060 2026] [:error] [pid 711:tid 139944538343168] [client 172.70.38.129:14253] [client 172.70.38.129] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgIp7b3Hg56MtJU4vy-ogAAARA"]
[Tue Jul 28 03:41:27.178519 2026] [:error] [pid 27697:tid 139944529950464] [client 162.158.106.237:10956] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgIxxkR7MhnM6j340ZhrQAAAFE"]
[Tue Jul 28 03:41:27.179082 2026] [:error] [pid 27697:tid 139944529950464] [client 162.158.106.237:10956] [client 162.158.106.237] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgIxxkR7MhnM6j340ZhrQAAAFE"]
[Tue Jul 28 03:41:27.179502 2026] [:error] [pid 27697:tid 139944529950464] [client 162.158.106.237:10956] [client 162.158.106.237] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgIxxkR7MhnM6j340ZhrQAAAFE"]
[Tue Jul 28 04:00:52.046689 2026] [:error] [pid 27697:tid 139944538343168] [client 104.23.190.73:12005] [client 104.23.190.73] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amgNVBkR7MhnM6j340ZrQQAAAFA"]
[Tue Jul 28 04:00:52.047722 2026] [:error] [pid 27697:tid 139944538343168] [client 104.23.190.73:12005] [client 104.23.190.73] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amgNVBkR7MhnM6j340ZrQQAAAFA"]
[Tue Jul 28 04:00:52.048267 2026] [:error] [pid 27697:tid 139944538343168] [client 104.23.190.73:12005] [client 104.23.190.73] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amgNVBkR7MhnM6j340ZrQQAAAFA"]
[Tue Jul 28 04:00:52.457645 2026] [:error] [pid 28027:tid 139944471201536] [client 104.23.187.74:11382] [client 104.23.187.74] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amgNVGzzpr4cNKr4fkujzgAAANg"]
[Tue Jul 28 04:00:52.458349 2026] [:error] [pid 28027:tid 139944471201536] [client 104.23.187.74:11382] [client 104.23.187.74] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amgNVGzzpr4cNKr4fkujzgAAANg"]
[Tue Jul 28 04:00:52.458723 2026] [:error] [pid 28027:tid 139944471201536] [client 104.23.187.74:11382] [client 104.23.187.74] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amgNVGzzpr4cNKr4fkujzgAAANg"]
[Tue Jul 28 04:10:42.598120 2026] [:error] [pid 28027:tid 139944571913984] [client 104.23.168.4:9443] [client 104.23.168.4] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgPomzzpr4cNKr4fkuvMQAAAMw"]
[Tue Jul 28 04:10:42.599185 2026] [:error] [pid 28027:tid 139944571913984] [client 104.23.168.4:9443] [client 104.23.168.4] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgPomzzpr4cNKr4fkuvMQAAAMw"]
[Tue Jul 28 04:10:42.599689 2026] [:error] [pid 28027:tid 139944571913984] [client 104.23.168.4:9443] [client 104.23.168.4] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgPomzzpr4cNKr4fkuvMQAAAMw"]
[Tue Jul 28 04:25:25.317889 2026] [:error] [pid 711:tid 139944655841024] [client 172.70.188.63:13368] [client 172.70.188.63] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgTFbb3Hg56MtJU4vwTqQAAAQI"]
[Tue Jul 28 04:25:25.319088 2026] [:error] [pid 711:tid 139944655841024] [client 172.70.188.63:13368] [client 172.70.188.63] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgTFbb3Hg56MtJU4vwTqQAAAQI"]
[Tue Jul 28 04:25:25.319729 2026] [:error] [pid 711:tid 139944655841024] [client 172.70.188.63:13368] [client 172.70.188.63] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgTFbb3Hg56MtJU4vwTqQAAAQI"]
[Tue Jul 28 04:26:02.080969 2026] [:error] [pid 28027:tid 139944647448320] [client 172.71.158.55:10976] [client 172.71.158.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgTOmzzpr4cNKr4fku_MwAAAMM"]
[Tue Jul 28 04:26:02.081751 2026] [:error] [pid 28027:tid 139944647448320] [client 172.71.158.55:10976] [client 172.71.158.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgTOmzzpr4cNKr4fku_MwAAAMM"]
[Tue Jul 28 04:26:02.082182 2026] [:error] [pid 28027:tid 139944647448320] [client 172.71.158.55:10976] [client 172.71.158.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgTOmzzpr4cNKr4fku_MwAAAMM"]
[Tue Jul 28 04:26:02.117243 2026] [:error] [pid 27697:tid 139944597092096] [client 172.71.150.168:14001] [client 172.71.150.168] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgTOhkR7MhnM6j340ZzBAAAAEk"]
[Tue Jul 28 04:26:02.118086 2026] [:error] [pid 27697:tid 139944597092096] [client 172.71.150.168:14001] [client 172.71.150.168] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgTOhkR7MhnM6j340ZzBAAAAEk"]
[Tue Jul 28 04:26:02.118605 2026] [:error] [pid 27697:tid 139944597092096] [client 172.71.150.168:14001] [client 172.71.150.168] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgTOhkR7MhnM6j340ZzBAAAAEk"]
[Tue Jul 28 04:26:02.433770 2026] [:error] [pid 711:tid 139944496379648] [client 172.71.151.133:10973] [client 172.71.151.133] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgTOrb3Hg56MtJU4vwVtQAAARU"]
[Tue Jul 28 04:26:02.434794 2026] [:error] [pid 711:tid 139944496379648] [client 172.71.151.133:10973] [client 172.71.151.133] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgTOrb3Hg56MtJU4vwVtQAAARU"]
[Tue Jul 28 04:26:02.435336 2026] [:error] [pid 711:tid 139944496379648] [client 172.71.151.133:10973] [client 172.71.151.133] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgTOrb3Hg56MtJU4vwVtQAAARU"]
[Tue Jul 28 04:26:02.468413 2026] [:error] [pid 27697:tid 139944622270208] [client 172.71.150.168:10833] [client 172.71.150.168] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgTOhkR7MhnM6j340ZzCAAAAEY"]
[Tue Jul 28 04:26:02.469279 2026] [:error] [pid 27697:tid 139944622270208] [client 172.71.150.168:10833] [client 172.71.150.168] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgTOhkR7MhnM6j340ZzCAAAAEY"]
[Tue Jul 28 04:26:02.469778 2026] [:error] [pid 27697:tid 139944622270208] [client 172.71.150.168:10833] [client 172.71.150.168] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgTOhkR7MhnM6j340ZzCAAAAEY"]
[Tue Jul 28 04:29:29.447536 2026] [:error] [pid 27697:tid 139944546735872] [client 104.23.243.19:13775] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amgUCRkR7MhnM6j340Z0vgAAAE8"]
[Tue Jul 28 04:29:29.448468 2026] [:error] [pid 27697:tid 139944546735872] [client 104.23.243.19:13775] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amgUCRkR7MhnM6j340Z0vgAAAE8"]
[Tue Jul 28 04:29:29.448979 2026] [:error] [pid 27697:tid 139944546735872] [client 104.23.243.19:13775] [client 104.23.243.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amgUCRkR7MhnM6j340Z0vgAAAE8"]
[Tue Jul 28 04:40:01.685969 2026] [:error] [pid 27702:tid 139944588699392] [client 104.23.197.76:10677] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amgWgYm1AQFltHspB3lNegAAAIo"]
[Tue Jul 28 04:40:01.697478 2026] [:error] [pid 27702:tid 139944588699392] [client 104.23.197.76:10677] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amgWgYm1AQFltHspB3lNegAAAIo"]
[Tue Jul 28 04:40:01.698006 2026] [:error] [pid 27702:tid 139944588699392] [client 104.23.197.76:10677] [client 104.23.197.76] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amgWgYm1AQFltHspB3lNegAAAIo"]
[Tue Jul 28 04:44:37.844969 2026] [:error] [pid 711:tid 139944504772352] [client 162.158.183.11:9983] [client 162.158.183.11] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amgXlbb3Hg56MtJU4vw7rgAAARQ"]
[Tue Jul 28 04:44:37.846316 2026] [:error] [pid 711:tid 139944504772352] [client 162.158.183.11:9983] [client 162.158.183.11] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amgXlbb3Hg56MtJU4vw7rgAAARQ"]
[Tue Jul 28 04:44:37.847095 2026] [:error] [pid 711:tid 139944504772352] [client 162.158.183.11:9983] [client 162.158.183.11] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amgXlbb3Hg56MtJU4vw7rgAAARQ"]
[Tue Jul 28 04:56:35.352343 2026] [:error] [pid 711:tid 139944546735872] [client 108.162.246.83:9399] [client 108.162.246.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/ucp"] [unique_id "amgaY7b3Hg56MtJU4vxReQAAAQ8"]
[Tue Jul 28 04:56:35.352972 2026] [:error] [pid 711:tid 139944546735872] [client 108.162.246.83:9399] [client 108.162.246.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/ucp"] [unique_id "amgaY7b3Hg56MtJU4vxReQAAAQ8"]
[Tue Jul 28 04:56:35.353279 2026] [:error] [pid 711:tid 139944546735872] [client 108.162.246.83:9399] [client 108.162.246.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/ucp"] [unique_id "amgaY7b3Hg56MtJU4vxReQAAAQ8"]
[Tue Jul 28 05:19:31.417816 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgfw7b3Hg56MtJU4vyAEQAAAQM"]
[Tue Jul 28 05:19:31.418768 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgfw7b3Hg56MtJU4vyAEQAAAQM"]
[Tue Jul 28 05:19:31.419307 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgfw7b3Hg56MtJU4vyAEQAAAQM"]
[Tue Jul 28 05:19:32.465894 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amgfxLb3Hg56MtJU4vyAFgAAARc"]
[Tue Jul 28 05:19:32.467207 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amgfxLb3Hg56MtJU4vyAFgAAARc"]
[Tue Jul 28 05:19:32.467865 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amgfxLb3Hg56MtJU4vyAFgAAARc"]
[Tue Jul 28 05:19:32.468122 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amgfxLb3Hg56MtJU4vyAFgAAARc"]
[Tue Jul 28 05:19:33.036615 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgfxbb3Hg56MtJU4vyAGQAAAQc"]
[Tue Jul 28 05:19:33.037280 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgfxbb3Hg56MtJU4vyAGQAAAQc"]
[Tue Jul 28 05:19:33.037624 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/x-www-form-urlencoded|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgfxbb3Hg56MtJU4vyAGQAAAQc"]
[Tue Jul 28 05:19:33.037931 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amgfxbb3Hg56MtJU4vyAGQAAAQc"]
[Tue Jul 28 05:19:33.305477 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amgfxbb3Hg56MtJU4vyAGgAAARM"]
[Tue Jul 28 05:19:33.306158 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amgfxbb3Hg56MtJU4vyAGgAAARM"]
[Tue Jul 28 05:19:33.306680 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amgfxbb3Hg56MtJU4vyAGgAAARM"]
[Tue Jul 28 05:19:33.306906 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amgfxbb3Hg56MtJU4vyAGgAAARM"]
[Tue Jul 28 05:19:33.594059 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amgfxbb3Hg56MtJU4vyAHgAAAQE"]
[Tue Jul 28 05:19:33.594784 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amgfxbb3Hg56MtJU4vyAHgAAAQE"]
[Tue Jul 28 05:19:33.595175 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amgfxbb3Hg56MtJU4vyAHgAAAQE"]
[Tue Jul 28 05:19:33.595380 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amgfxbb3Hg56MtJU4vyAHgAAAQE"]
[Tue Jul 28 05:19:33.930737 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amgfxbb3Hg56MtJU4vyAHwAAAQ8"]
[Tue Jul 28 05:19:33.931608 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amgfxbb3Hg56MtJU4vyAHwAAAQ8"]
[Tue Jul 28 05:19:33.932137 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amgfxbb3Hg56MtJU4vyAHwAAAQ8"]
[Tue Jul 28 05:19:33.932393 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amgfxbb3Hg56MtJU4vyAHwAAAQ8"]
[Tue Jul 28 05:19:34.215725 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amgfxrb3Hg56MtJU4vyAIwAAARc"]
[Tue Jul 28 05:19:34.216673 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amgfxrb3Hg56MtJU4vyAIwAAARc"]
[Tue Jul 28 05:19:34.217200 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amgfxrb3Hg56MtJU4vyAIwAAARc"]
[Tue Jul 28 05:19:34.217387 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amgfxrb3Hg56MtJU4vyAIwAAARc"]
[Tue Jul 28 05:19:34.504438 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amgfxrb3Hg56MtJU4vyAJAAAARQ"]
[Tue Jul 28 05:19:34.505067 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amgfxrb3Hg56MtJU4vyAJAAAARQ"]
[Tue Jul 28 05:19:34.505437 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amgfxrb3Hg56MtJU4vyAJAAAARQ"]
[Tue Jul 28 05:19:34.505611 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amgfxrb3Hg56MtJU4vyAJAAAARQ"]
[Tue Jul 28 05:19:34.792394 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amgfxrb3Hg56MtJU4vyAJQAAARM"]
[Tue Jul 28 05:19:34.793068 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amgfxrb3Hg56MtJU4vyAJQAAARM"]
[Tue Jul 28 05:19:34.793499 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amgfxrb3Hg56MtJU4vyAJQAAARM"]
[Tue Jul 28 05:19:34.793679 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amgfxrb3Hg56MtJU4vyAJQAAARM"]
[Tue Jul 28 05:19:35.071651 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "amgfx7b3Hg56MtJU4vyAKAAAAQI"]
[Tue Jul 28 05:19:35.072399 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "amgfx7b3Hg56MtJU4vyAKAAAAQI"]
[Tue Jul 28 05:19:35.072851 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "amgfx7b3Hg56MtJU4vyAKAAAAQI"]
[Tue Jul 28 05:19:35.073083 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "amgfx7b3Hg56MtJU4vyAKAAAAQI"]
[Tue Jul 28 05:19:35.365775 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amgfx7b3Hg56MtJU4vyAKwAAAQg"]
[Tue Jul 28 05:19:35.366943 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amgfx7b3Hg56MtJU4vyAKwAAAQg"]
[Tue Jul 28 05:19:35.367650 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amgfx7b3Hg56MtJU4vyAKwAAAQg"]
[Tue Jul 28 05:19:35.367887 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.84.254:10068] [client 141.101.84.254] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amgfx7b3Hg56MtJU4vyAKwAAAQg"]
[Tue Jul 28 05:19:35.646435 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amgfx7b3Hg56MtJU4vyALAAAAQs"]
[Tue Jul 28 05:19:35.647075 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amgfx7b3Hg56MtJU4vyALAAAAQs"]
[Tue Jul 28 05:19:35.647457 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amgfx7b3Hg56MtJU4vyALAAAAQs"]
[Tue Jul 28 05:19:35.647630 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amgfx7b3Hg56MtJU4vyALAAAAQs"]
[Tue Jul 28 05:19:35.927776 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amgfx7b3Hg56MtJU4vyALgAAAQ8"]
[Tue Jul 28 05:19:35.928681 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amgfx7b3Hg56MtJU4vyALgAAAQ8"]
[Tue Jul 28 05:19:35.929203 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amgfx7b3Hg56MtJU4vyALgAAAQ8"]
[Tue Jul 28 05:19:35.929444 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amgfx7b3Hg56MtJU4vyALgAAAQ8"]
[Tue Jul 28 05:19:36.216679 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amgfyLb3Hg56MtJU4vyALwAAARc"]
[Tue Jul 28 05:19:36.217338 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amgfyLb3Hg56MtJU4vyALwAAARc"]
[Tue Jul 28 05:19:36.217733 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amgfyLb3Hg56MtJU4vyALwAAARc"]
[Tue Jul 28 05:19:36.217883 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amgfyLb3Hg56MtJU4vyALwAAARc"]
[Tue Jul 28 05:19:36.500030 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amgfyLb3Hg56MtJU4vyAMQAAAQY"]
[Tue Jul 28 05:19:36.500831 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amgfyLb3Hg56MtJU4vyAMQAAAQY"]
[Tue Jul 28 05:19:36.501302 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amgfyLb3Hg56MtJU4vyAMQAAAQY"]
[Tue Jul 28 05:19:36.501587 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amgfyLb3Hg56MtJU4vyAMQAAAQY"]
[Tue Jul 28 05:19:36.782805 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amgfyLb3Hg56MtJU4vyAMwAAAQk"]
[Tue Jul 28 05:19:36.783790 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amgfyLb3Hg56MtJU4vyAMwAAAQk"]
[Tue Jul 28 05:19:36.784338 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amgfyLb3Hg56MtJU4vyAMwAAAQk"]
[Tue Jul 28 05:19:36.784582 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amgfyLb3Hg56MtJU4vyAMwAAAQk"]
[Tue Jul 28 05:19:37.063911 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amgfybb3Hg56MtJU4vyANQAAAQM"]
[Tue Jul 28 05:19:37.064883 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amgfybb3Hg56MtJU4vyANQAAAQM"]
[Tue Jul 28 05:19:37.065509 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amgfybb3Hg56MtJU4vyANQAAAQM"]
[Tue Jul 28 05:19:37.065757 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amgfybb3Hg56MtJU4vyANQAAAQM"]
[Tue Jul 28 05:19:37.343206 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amgfybb3Hg56MtJU4vyANgAAAQ0"]
[Tue Jul 28 05:19:37.343917 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amgfybb3Hg56MtJU4vyANgAAAQ0"]
[Tue Jul 28 05:19:37.344284 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amgfybb3Hg56MtJU4vyANgAAAQ0"]
[Tue Jul 28 05:19:37.344445 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amgfybb3Hg56MtJU4vyANgAAAQ0"]
[Tue Jul 28 05:19:37.621353 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amgfybb3Hg56MtJU4vyAOQAAAQs"]
[Tue Jul 28 05:19:37.621730 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amgfybb3Hg56MtJU4vyAOQAAAQs"]
[Tue Jul 28 05:19:37.622054 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amgfybb3Hg56MtJU4vyAOQAAAQs"]
[Tue Jul 28 05:19:37.622185 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amgfybb3Hg56MtJU4vyAOQAAAQs"]
[Tue Jul 28 05:19:37.898868 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "amgfybb3Hg56MtJU4vyAOwAAAQQ"]
[Tue Jul 28 05:19:37.899723 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "amgfybb3Hg56MtJU4vyAOwAAAQQ"]
[Tue Jul 28 05:19:37.900161 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "amgfybb3Hg56MtJU4vyAOwAAAQQ"]
[Tue Jul 28 05:19:37.900346 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.ci"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "amgfybb3Hg56MtJU4vyAOwAAAQQ"]
[Tue Jul 28 05:19:38.176589 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "amgfyrb3Hg56MtJU4vyAPAAAARA"]
[Tue Jul 28 05:19:38.177454 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "amgfyrb3Hg56MtJU4vyAPAAAARA"]
[Tue Jul 28 05:19:38.178000 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "amgfyrb3Hg56MtJU4vyAPAAAARA"]
[Tue Jul 28 05:19:38.178242 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.docker"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "amgfyrb3Hg56MtJU4vyAPAAAARA"]
[Tue Jul 28 05:19:38.458278 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amgfyrb3Hg56MtJU4vyAPwAAARE"]
[Tue Jul 28 05:19:38.459041 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amgfyrb3Hg56MtJU4vyAPwAAARE"]
[Tue Jul 28 05:19:38.459462 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amgfyrb3Hg56MtJU4vyAPwAAARE"]
[Tue Jul 28 05:19:38.459649 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.live"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amgfyrb3Hg56MtJU4vyAPwAAARE"]
[Tue Jul 28 05:19:38.738710 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "amgfyrb3Hg56MtJU4vyAQAAAAQM"]
[Tue Jul 28 05:19:38.739391 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "amgfyrb3Hg56MtJU4vyAQAAAAQM"]
[Tue Jul 28 05:19:38.739885 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "amgfyrb3Hg56MtJU4vyAQAAAAQM"]
[Tue Jul 28 05:19:38.740142 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.preprod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "amgfyrb3Hg56MtJU4vyAQAAAAQM"]
[Tue Jul 28 05:19:39.018376 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "amgfy7b3Hg56MtJU4vyAQgAAAQI"]
[Tue Jul 28 05:19:39.019537 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "amgfy7b3Hg56MtJU4vyAQgAAAQI"]
[Tue Jul 28 05:19:39.020205 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "amgfy7b3Hg56MtJU4vyAQgAAAQI"]
[Tue Jul 28 05:19:39.020516 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.uat"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "amgfy7b3Hg56MtJU4vyAQgAAAQI"]
[Tue Jul 28 05:19:39.298652 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amgfy7b3Hg56MtJU4vyARAAAARM"]
[Tue Jul 28 05:19:39.299668 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amgfy7b3Hg56MtJU4vyARAAAARM"]
[Tue Jul 28 05:19:39.300342 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amgfy7b3Hg56MtJU4vyARAAAARM"]
[Tue Jul 28 05:19:39.300639 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amgfy7b3Hg56MtJU4vyARAAAARM"]
[Tue Jul 28 05:19:39.595085 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amgfy7b3Hg56MtJU4vyARgAAAQE"]
[Tue Jul 28 05:19:39.595878 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amgfy7b3Hg56MtJU4vyARgAAAQE"]
[Tue Jul 28 05:19:39.596366 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amgfy7b3Hg56MtJU4vyARgAAAQE"]
[Tue Jul 28 05:19:39.596513 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amgfy7b3Hg56MtJU4vyARgAAAQE"]
[Tue Jul 28 05:19:39.914071 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amgfy7b3Hg56MtJU4vyASAAAAQ8"]
[Tue Jul 28 05:19:39.914786 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amgfy7b3Hg56MtJU4vyASAAAAQ8"]
[Tue Jul 28 05:19:39.915043 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Pattern match "\\\\.[^.~]+~(?:/.*|)$" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1060"] [id "920500"] [msg "Attempt to access a backup or working file"] [data ".env~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amgfy7b3Hg56MtJU4vyASAAAAQ8"]
[Tue Jul 28 05:19:39.915230 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amgfy7b3Hg56MtJU4vyASAAAAQ8"]
[Tue Jul 28 05:19:39.915388 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amgfy7b3Hg56MtJU4vyASAAAAQ8"]
[Tue Jul 28 05:19:40.209279 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env1"] [unique_id "amgfzLb3Hg56MtJU4vyASwAAAQQ"]
[Tue Jul 28 05:19:40.209936 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env1"] [unique_id "amgfzLb3Hg56MtJU4vyASwAAAQQ"]
[Tue Jul 28 05:19:40.210341 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env1"] [unique_id "amgfzLb3Hg56MtJU4vyASwAAAQQ"]
[Tue Jul 28 05:19:40.210510 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env1"] [unique_id "amgfzLb3Hg56MtJU4vyASwAAAQQ"]
[Tue Jul 28 05:19:40.490631 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env2"] [unique_id "amgfzLb3Hg56MtJU4vyAUAAAAQM"]
[Tue Jul 28 05:19:40.491451 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env2"] [unique_id "amgfzLb3Hg56MtJU4vyAUAAAAQM"]
[Tue Jul 28 05:19:40.491985 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env2"] [unique_id "amgfzLb3Hg56MtJU4vyAUAAAAQM"]
[Tue Jul 28 05:19:40.492217 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env2"] [unique_id "amgfzLb3Hg56MtJU4vyAUAAAAQM"]
[Tue Jul 28 05:19:40.770987 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amgfzLb3Hg56MtJU4vyAUgAAARg"]
[Tue Jul 28 05:19:40.771759 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amgfzLb3Hg56MtJU4vyAUgAAARg"]
[Tue Jul 28 05:19:40.772337 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amgfzLb3Hg56MtJU4vyAUgAAARg"]
[Tue Jul 28 05:19:40.772604 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_copy"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amgfzLb3Hg56MtJU4vyAUgAAARg"]
[Tue Jul 28 05:19:41.053719 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amgfzbb3Hg56MtJU4vyAVAAAAQE"]
[Tue Jul 28 05:19:41.054737 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amgfzbb3Hg56MtJU4vyAVAAAAQE"]
[Tue Jul 28 05:19:41.055300 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amgfzbb3Hg56MtJU4vyAVAAAAQE"]
[Tue Jul 28 05:19:41.055596 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.txt"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amgfzbb3Hg56MtJU4vyAVAAAAQE"]
[Tue Jul 28 05:19:41.335746 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.json"] [unique_id "amgfzbb3Hg56MtJU4vyAVgAAARI"]
[Tue Jul 28 05:19:41.336653 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.json"] [unique_id "amgfzbb3Hg56MtJU4vyAVgAAARI"]
[Tue Jul 28 05:19:41.337182 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.json"] [unique_id "amgfzbb3Hg56MtJU4vyAVgAAARI"]
[Tue Jul 28 05:19:41.342273 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.json"] [unique_id "amgfzbb3Hg56MtJU4vyAVgAAARI"]
[Tue Jul 28 05:19:41.622002 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "amgfzbb3Hg56MtJU4vyAWAAAAQQ"]
[Tue Jul 28 05:19:41.622830 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "amgfzbb3Hg56MtJU4vyAWAAAAQQ"]
[Tue Jul 28 05:19:41.623306 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "amgfzbb3Hg56MtJU4vyAWAAAAQQ"]
[Tue Jul 28 05:19:41.623541 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yaml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "amgfzbb3Hg56MtJU4vyAWAAAAQQ"]
[Tue Jul 28 05:19:41.662510 2026] [:error] [pid 711:tid 139944546735872] [client 172.64.215.40:9569] [client 172.64.215.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgfzbb3Hg56MtJU4vyAWQAAAQ8"], referer: https://sbf-consultancy.com/
[Tue Jul 28 05:19:41.663386 2026] [:error] [pid 711:tid 139944546735872] [client 172.64.215.40:9569] [client 172.64.215.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgfzbb3Hg56MtJU4vyAWQAAAQ8"], referer: https://sbf-consultancy.com/
[Tue Jul 28 05:19:41.663923 2026] [:error] [pid 711:tid 139944546735872] [client 172.64.215.40:9569] [client 172.64.215.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgfzbb3Hg56MtJU4vyAWQAAAQ8"], referer: https://sbf-consultancy.com/
[Tue Jul 28 05:19:41.919170 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "amgfzbb3Hg56MtJU4vyAXAAAARE"]
[Tue Jul 28 05:19:41.920332 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "amgfzbb3Hg56MtJU4vyAXAAAARE"]
[Tue Jul 28 05:19:41.921066 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "amgfzbb3Hg56MtJU4vyAXAAAARE"]
[Tue Jul 28 05:19:41.921305 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "amgfzbb3Hg56MtJU4vyAXAAAARE"]
[Tue Jul 28 05:19:42.199966 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amgfzrb3Hg56MtJU4vyAXQAAAQA"]
[Tue Jul 28 05:19:42.200807 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amgfzrb3Hg56MtJU4vyAXQAAAQA"]
[Tue Jul 28 05:19:42.201369 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amgfzrb3Hg56MtJU4vyAXQAAAQA"]
[Tue Jul 28 05:19:42.201649 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amgfzrb3Hg56MtJU4vyAXQAAAQA"]
[Tue Jul 28 05:19:42.480002 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "amgfzrb3Hg56MtJU4vyAXwAAAQY"]
[Tue Jul 28 05:19:42.480851 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "amgfzrb3Hg56MtJU4vyAXwAAAQY"]
[Tue Jul 28 05:19:42.481380 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "amgfzrb3Hg56MtJU4vyAXwAAAQY"]
[Tue Jul 28 05:19:42.481651 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "amgfzrb3Hg56MtJU4vyAXwAAAQY"]
[Tue Jul 28 05:19:42.759904 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amgfzrb3Hg56MtJU4vyAYQAAARM"]
[Tue Jul 28 05:19:42.760535 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amgfzrb3Hg56MtJU4vyAYQAAARM"]
[Tue Jul 28 05:19:42.760953 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amgfzrb3Hg56MtJU4vyAYQAAARM"]
[Tue Jul 28 05:19:42.761168 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amgfzrb3Hg56MtJU4vyAYQAAARM"]
[Tue Jul 28 05:19:43.058665 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAZAAAAQU"]
[Tue Jul 28 05:19:43.059684 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAZAAAAQU"]
[Tue Jul 28 05:19:43.060293 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAZAAAAQU"]
[Tue Jul 28 05:19:43.060569 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAZAAAAQU"]
[Tue Jul 28 05:19:43.339860 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/site/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAZgAAARI"]
[Tue Jul 28 05:19:43.340692 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/site/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAZgAAARI"]
[Tue Jul 28 05:19:43.341193 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/site/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAZgAAARI"]
[Tue Jul 28 05:19:43.341431 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/site/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAZgAAARI"]
[Tue Jul 28 05:19:43.626630 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAZwAAAQ0"]
[Tue Jul 28 05:19:43.627464 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAZwAAAQ0"]
[Tue Jul 28 05:19:43.627996 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAZwAAAQ0"]
[Tue Jul 28 05:19:43.628242 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAZwAAAQ0"]
[Tue Jul 28 05:19:43.909699 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAaQAAAQ8"]
[Tue Jul 28 05:19:43.910630 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAaQAAAQ8"]
[Tue Jul 28 05:19:43.911168 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAaQAAAQ8"]
[Tue Jul 28 05:19:43.911434 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amgfz7b3Hg56MtJU4vyAaQAAAQ8"]
[Tue Jul 28 05:19:44.189286 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amgf0Lb3Hg56MtJU4vyAbAAAARc"]
[Tue Jul 28 05:19:44.190289 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amgf0Lb3Hg56MtJU4vyAbAAAARc"]
[Tue Jul 28 05:19:44.190906 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amgf0Lb3Hg56MtJU4vyAbAAAARc"]
[Tue Jul 28 05:19:44.191132 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amgf0Lb3Hg56MtJU4vyAbAAAARc"]
[Tue Jul 28 05:19:44.469960 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amgf0Lb3Hg56MtJU4vyAbgAAARY"]
[Tue Jul 28 05:19:44.470641 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amgf0Lb3Hg56MtJU4vyAbgAAARY"]
[Tue Jul 28 05:19:44.471021 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amgf0Lb3Hg56MtJU4vyAbgAAARY"]
[Tue Jul 28 05:19:44.471184 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amgf0Lb3Hg56MtJU4vyAbgAAARY"]
[Tue Jul 28 05:19:44.749209 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amgf0Lb3Hg56MtJU4vyAcAAAAQY"]
[Tue Jul 28 05:19:44.750155 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amgf0Lb3Hg56MtJU4vyAcAAAAQY"]
[Tue Jul 28 05:19:44.750716 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amgf0Lb3Hg56MtJU4vyAcAAAAQY"]
[Tue Jul 28 05:19:44.750952 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /frontend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amgf0Lb3Hg56MtJU4vyAcAAAAQY"]
[Tue Jul 28 05:19:45.030091 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAcgAAARM"]
[Tue Jul 28 05:19:45.031055 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAcgAAARM"]
[Tue Jul 28 05:19:45.031733 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAcgAAARM"]
[Tue Jul 28 05:19:45.031978 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAcgAAARM"]
[Tue Jul 28 05:19:45.310867 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAdAAAAQM"]
[Tue Jul 28 05:19:45.311848 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAdAAAAQM"]
[Tue Jul 28 05:19:45.312457 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAdAAAAQM"]
[Tue Jul 28 05:19:45.312691 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAdAAAAQM"]
[Tue Jul 28 05:19:45.591227 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAdQAAAQo"]
[Tue Jul 28 05:19:45.592134 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAdQAAAQo"]
[Tue Jul 28 05:19:45.593350 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAdQAAAQo"]
[Tue Jul 28 05:19:45.593644 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAdQAAAQo"]
[Tue Jul 28 05:19:45.873590 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAeAAAARg"]
[Tue Jul 28 05:19:45.874348 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAeAAAARg"]
[Tue Jul 28 05:19:45.874804 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAeAAAARg"]
[Tue Jul 28 05:19:45.874955 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amgf0bb3Hg56MtJU4vyAeAAAARg"]
[Tue Jul 28 05:19:46.152409 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amgf0rb3Hg56MtJU4vyAegAAAQE"]
[Tue Jul 28 05:19:46.153188 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amgf0rb3Hg56MtJU4vyAegAAAQE"]
[Tue Jul 28 05:19:46.153705 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amgf0rb3Hg56MtJU4vyAegAAAQE"]
[Tue Jul 28 05:19:46.153940 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /private/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amgf0rb3Hg56MtJU4vyAegAAAQE"]
[Tue Jul 28 05:19:46.432112 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amgf0rb3Hg56MtJU4vyAfAAAAQs"]
[Tue Jul 28 05:19:46.432944 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amgf0rb3Hg56MtJU4vyAfAAAAQs"]
[Tue Jul 28 05:19:46.433486 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amgf0rb3Hg56MtJU4vyAfAAAAQs"]
[Tue Jul 28 05:19:46.433739 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amgf0rb3Hg56MtJU4vyAfAAAAQs"]
[Tue Jul 28 05:19:46.722175 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "amgf0rb3Hg56MtJU4vyAfgAAAQg"]
[Tue Jul 28 05:19:46.723824 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "amgf0rb3Hg56MtJU4vyAfgAAAQg"]
[Tue Jul 28 05:19:46.724472 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "amgf0rb3Hg56MtJU4vyAfgAAAQg"]
[Tue Jul 28 05:19:46.724758 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /bootstrap/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "amgf0rb3Hg56MtJU4vyAfgAAAQg"]
[Tue Jul 28 05:19:47.004379 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/database/.env"] [unique_id "amgf07b3Hg56MtJU4vyAgAAAAQA"]
[Tue Jul 28 05:19:47.005192 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/database/.env"] [unique_id "amgf07b3Hg56MtJU4vyAgAAAAQA"]
[Tue Jul 28 05:19:47.005736 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/database/.env"] [unique_id "amgf07b3Hg56MtJU4vyAgAAAAQA"]
[Tue Jul 28 05:19:47.005970 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/database/.env"] [unique_id "amgf07b3Hg56MtJU4vyAgAAAAQA"]
[Tue Jul 28 05:19:47.284961 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "amgf07b3Hg56MtJU4vyAggAAAQ4"]
[Tue Jul 28 05:19:47.285882 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "amgf07b3Hg56MtJU4vyAggAAAQ4"]
[Tue Jul 28 05:19:47.286450 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "amgf07b3Hg56MtJU4vyAggAAAQ4"]
[Tue Jul 28 05:19:47.286723 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "amgf07b3Hg56MtJU4vyAggAAAQ4"]
[Tue Jul 28 05:19:47.568360 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "amgf07b3Hg56MtJU4vyAgwAAARA"]
[Tue Jul 28 05:19:47.569189 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "amgf07b3Hg56MtJU4vyAgwAAARA"]
[Tue Jul 28 05:19:47.569762 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "amgf07b3Hg56MtJU4vyAgwAAARA"]
[Tue Jul 28 05:19:47.570016 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /var/www/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "amgf07b3Hg56MtJU4vyAgwAAARA"]
[Tue Jul 28 05:19:47.863390 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "amgf07b3Hg56MtJU4vyAhgAAAQk"]
[Tue Jul 28 05:19:47.864232 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "amgf07b3Hg56MtJU4vyAhgAAAQk"]
[Tue Jul 28 05:19:47.864753 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "amgf07b3Hg56MtJU4vyAhgAAAQk"]
[Tue Jul 28 05:19:47.865010 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /var/www/html/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "amgf07b3Hg56MtJU4vyAhgAAAQk"]
[Tue Jul 28 05:19:48.153592 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/current/.env"] [unique_id "amgf1Lb3Hg56MtJU4vyAiAAAAQE"]
[Tue Jul 28 05:19:48.154368 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/current/.env"] [unique_id "amgf1Lb3Hg56MtJU4vyAiAAAAQE"]
[Tue Jul 28 05:19:48.155260 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/current/.env"] [unique_id "amgf1Lb3Hg56MtJU4vyAiAAAAQE"]
[Tue Jul 28 05:19:48.155570 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /current/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/current/.env"] [unique_id "amgf1Lb3Hg56MtJU4vyAiAAAAQE"]
[Tue Jul 28 05:19:48.433372 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/release/.env"] [unique_id "amgf1Lb3Hg56MtJU4vyAiwAAAQs"]
[Tue Jul 28 05:19:48.434378 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/release/.env"] [unique_id "amgf1Lb3Hg56MtJU4vyAiwAAAQs"]
[Tue Jul 28 05:19:48.434946 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/release/.env"] [unique_id "amgf1Lb3Hg56MtJU4vyAiwAAAQs"]
[Tue Jul 28 05:19:48.435185 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /release/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/release/.env"] [unique_id "amgf1Lb3Hg56MtJU4vyAiwAAAQs"]
[Tue Jul 28 05:19:48.713719 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "amgf1Lb3Hg56MtJU4vyAjQAAARc"]
[Tue Jul 28 05:19:48.714589 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "amgf1Lb3Hg56MtJU4vyAjQAAARc"]
[Tue Jul 28 05:19:48.715575 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "amgf1Lb3Hg56MtJU4vyAjQAAARc"]
[Tue Jul 28 05:19:48.715948 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /releases/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "amgf1Lb3Hg56MtJU4vyAjQAAARc"]
[Tue Jul 28 05:19:49.007701 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAjgAAAQ8"]
[Tue Jul 28 05:19:49.008565 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAjgAAAQ8"]
[Tue Jul 28 05:19:49.009097 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAjgAAAQ8"]
[Tue Jul 28 05:19:49.009378 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /shared/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAjgAAAQ8"]
[Tue Jul 28 05:19:49.293154 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAkgAAARU"]
[Tue Jul 28 05:19:49.293888 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAkgAAARU"]
[Tue Jul 28 05:19:49.294360 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAkgAAARU"]
[Tue Jul 28 05:19:49.294606 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /deploy/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAkgAAARU"]
[Tue Jul 28 05:19:49.576072 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/build/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAlAAAAQk"]
[Tue Jul 28 05:19:49.589193 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/build/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAlAAAAQk"]
[Tue Jul 28 05:19:49.589810 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/build/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAlAAAAQk"]
[Tue Jul 28 05:19:49.590056 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /build/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/build/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAlAAAAQk"]
[Tue Jul 28 05:19:49.866734 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAlgAAAQc"]
[Tue Jul 28 05:19:49.867628 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAlgAAAQc"]
[Tue Jul 28 05:19:49.868171 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAlgAAAQc"]
[Tue Jul 28 05:19:49.868415 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /dist/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "amgf1bb3Hg56MtJU4vyAlgAAAQc"]
[Tue Jul 28 05:19:50.157366 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAmAAAAQE"]
[Tue Jul 28 05:19:50.158075 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAmAAAAQE"]
[Tue Jul 28 05:19:50.158565 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAmAAAAQE"]
[Tue Jul 28 05:19:50.158809 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public_html/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAmAAAAQE"]
[Tue Jul 28 05:19:50.437603 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAmgAAAQo"]
[Tue Jul 28 05:19:50.438406 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAmgAAAQo"]
[Tue Jul 28 05:19:50.438869 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAmgAAAQo"]
[Tue Jul 28 05:19:50.439101 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /htdocs/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAmgAAAQo"]
[Tue Jul 28 05:19:50.717074 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/www/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAnAAAARc"]
[Tue Jul 28 05:19:50.718139 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/www/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAnAAAARc"]
[Tue Jul 28 05:19:50.718772 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/www/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAnAAAARc"]
[Tue Jul 28 05:19:50.719874 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /www/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/www/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAnAAAARc"]
[Tue Jul 28 05:19:50.997051 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/html/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAnQAAARI"]
[Tue Jul 28 05:19:50.997925 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/html/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAnQAAARI"]
[Tue Jul 28 05:19:50.998508 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/html/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAnQAAARI"]
[Tue Jul 28 05:19:50.998774 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /html/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/html/.env"] [unique_id "amgf1rb3Hg56MtJU4vyAnQAAARI"]
[Tue Jul 28 05:19:51.275975 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/live/.env"] [unique_id "amgf17b3Hg56MtJU4vyAnwAAAQ0"]
[Tue Jul 28 05:19:51.276826 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/live/.env"] [unique_id "amgf17b3Hg56MtJU4vyAnwAAAQ0"]
[Tue Jul 28 05:19:51.277381 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/live/.env"] [unique_id "amgf17b3Hg56MtJU4vyAnwAAAQ0"]
[Tue Jul 28 05:19:51.277658 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /live/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/live/.env"] [unique_id "amgf17b3Hg56MtJU4vyAnwAAAQ0"]
[Tue Jul 28 05:19:51.555819 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "amgf17b3Hg56MtJU4vyAoAAAAQU"]
[Tue Jul 28 05:19:51.556646 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "amgf17b3Hg56MtJU4vyAoAAAAQU"]
[Tue Jul 28 05:19:51.557126 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "amgf17b3Hg56MtJU4vyAoAAAAQU"]
[Tue Jul 28 05:19:51.557356 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prod/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "amgf17b3Hg56MtJU4vyAoAAAAQU"]
[Tue Jul 28 05:19:51.835707 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amgf17b3Hg56MtJU4vyAowAAARU"]
[Tue Jul 28 05:19:51.836642 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amgf17b3Hg56MtJU4vyAowAAARU"]
[Tue Jul 28 05:19:51.837109 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amgf17b3Hg56MtJU4vyAowAAARU"]
[Tue Jul 28 05:19:51.837284 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /dev/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amgf17b3Hg56MtJU4vyAowAAARU"]
[Tue Jul 28 05:19:52.115661 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyApQAAARg"]
[Tue Jul 28 05:19:52.116758 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyApQAAARg"]
[Tue Jul 28 05:19:52.117498 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyApQAAARg"]
[Tue Jul 28 05:19:52.117814 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /staging/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyApQAAARg"]
[Tue Jul 28 05:19:52.407610 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyAqQAAARQ"]
[Tue Jul 28 05:19:52.408704 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyAqQAAARQ"]
[Tue Jul 28 05:19:52.409343 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyAqQAAARQ"]
[Tue Jul 28 05:19:52.409631 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /opt/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyAqQAAARQ"]
[Tue Jul 28 05:19:52.687170 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyAqwAAAQ4"]
[Tue Jul 28 05:19:52.687831 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyAqwAAAQ4"]
[Tue Jul 28 05:19:52.688268 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyAqwAAAQ4"]
[Tue Jul 28 05:19:52.688443 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyAqwAAAQ4"]
[Tue Jul 28 05:19:52.967471 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyArwAAARc"]
[Tue Jul 28 05:19:52.968446 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyArwAAARc"]
[Tue Jul 28 05:19:52.969023 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyArwAAARc"]
[Tue Jul 28 05:19:52.969263 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /symfony/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "amgf2Lb3Hg56MtJU4vyArwAAARc"]
[Tue Jul 28 05:19:53.250648 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "amgf2bb3Hg56MtJU4vyAsgAAAQs"]
[Tue Jul 28 05:19:53.251537 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "amgf2bb3Hg56MtJU4vyAsgAAAQs"]
[Tue Jul 28 05:19:53.252110 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "amgf2bb3Hg56MtJU4vyAsgAAAQs"]
[Tue Jul 28 05:19:53.252357 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wordpress/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "amgf2bb3Hg56MtJU4vyAsgAAAQs"]
[Tue Jul 28 05:19:53.530034 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "amgf2bb3Hg56MtJU4vyAswAAAQ0"]
[Tue Jul 28 05:19:53.530856 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "amgf2bb3Hg56MtJU4vyAswAAAQ0"]
[Tue Jul 28 05:19:53.531273 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "amgf2bb3Hg56MtJU4vyAswAAAQ0"]
[Tue Jul 28 05:19:53.531483 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "amgf2bb3Hg56MtJU4vyAswAAAQ0"]
[Tue Jul 28 05:19:53.815044 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "amgf2bb3Hg56MtJU4vyAtgAAARU"]
[Tue Jul 28 05:19:53.816067 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "amgf2bb3Hg56MtJU4vyAtgAAARU"]
[Tue Jul 28 05:19:53.816684 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "amgf2bb3Hg56MtJU4vyAtgAAARU"]
[Tue Jul 28 05:19:53.816921 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cms/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "amgf2bb3Hg56MtJU4vyAtgAAARU"]
[Tue Jul 28 05:19:54.095252 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAtwAAAQM"]
[Tue Jul 28 05:19:54.096116 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAtwAAAQM"]
[Tue Jul 28 05:19:54.096606 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAtwAAAQM"]
[Tue Jul 28 05:19:54.096805 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /drupal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAtwAAAQM"]
[Tue Jul 28 05:19:54.377648 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAuAAAARg"]
[Tue Jul 28 05:19:54.378533 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAuAAAARg"]
[Tue Jul 28 05:19:54.379088 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAuAAAARg"]
[Tue Jul 28 05:19:54.379331 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /joomla/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAuAAAARg"]
[Tue Jul 28 05:19:54.664049 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAuwAAAQQ"]
[Tue Jul 28 05:19:54.665070 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAuwAAAQQ"]
[Tue Jul 28 05:19:54.665663 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAuwAAAQQ"]
[Tue Jul 28 05:19:54.665902 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /magento/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAuwAAAQQ"]
[Tue Jul 28 05:19:54.949333 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAvAAAAQI"]
[Tue Jul 28 05:19:54.950000 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAvAAAAQI"]
[Tue Jul 28 05:19:54.950440 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAvAAAAQI"]
[Tue Jul 28 05:19:54.950643 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /shopify/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "amgf2rb3Hg56MtJU4vyAvAAAAQI"]
[Tue Jul 28 05:19:55.238062 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "amgf27b3Hg56MtJU4vyAvgAAAQk"]
[Tue Jul 28 05:19:55.239128 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "amgf27b3Hg56MtJU4vyAvgAAAQk"]
[Tue Jul 28 05:19:55.239773 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "amgf27b3Hg56MtJU4vyAvgAAAQk"]
[Tue Jul 28 05:19:55.240002 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prestashop/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "amgf27b3Hg56MtJU4vyAvgAAAQk"]
[Tue Jul 28 05:19:55.520858 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "amgf27b3Hg56MtJU4vyAwAAAAQo"]
[Tue Jul 28 05:19:55.521757 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "amgf27b3Hg56MtJU4vyAwAAAAQo"]
[Tue Jul 28 05:19:55.522354 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "amgf27b3Hg56MtJU4vyAwAAAAQo"]
[Tue Jul 28 05:19:55.522753 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /codeigniter/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "amgf27b3Hg56MtJU4vyAwAAAAQo"]
[Tue Jul 28 05:19:55.800859 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "amgf27b3Hg56MtJU4vyAwQAAAQY"]
[Tue Jul 28 05:19:55.801840 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "amgf27b3Hg56MtJU4vyAwQAAAQY"]
[Tue Jul 28 05:19:55.802382 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "amgf27b3Hg56MtJU4vyAwQAAAQY"]
[Tue Jul 28 05:19:55.802667 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cakephp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "amgf27b3Hg56MtJU4vyAwQAAAQY"]
[Tue Jul 28 05:19:56.081893 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAxAAAARM"]
[Tue Jul 28 05:19:56.082771 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAxAAAARM"]
[Tue Jul 28 05:19:56.083356 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAxAAAARM"]
[Tue Jul 28 05:19:56.083618 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /zend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAxAAAARM"]
[Tue Jul 28 05:19:56.361180 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAxQAAAQw"]
[Tue Jul 28 05:19:56.362068 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAxQAAAQw"]
[Tue Jul 28 05:19:56.362653 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAxQAAAQw"]
[Tue Jul 28 05:19:56.362906 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /yii/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAxQAAAQw"]
[Tue Jul 28 05:19:56.642211 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAyAAAAQU"]
[Tue Jul 28 05:19:56.643204 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAyAAAAQU"]
[Tue Jul 28 05:19:56.643791 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAyAAAAQU"]
[Tue Jul 28 05:19:56.644015 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel5/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAyAAAAQU"]
[Tue Jul 28 05:19:56.933818 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAywAAAQg"]
[Tue Jul 28 05:19:56.934939 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAywAAAQg"]
[Tue Jul 28 05:19:56.935516 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAywAAAQg"]
[Tue Jul 28 05:19:56.935800 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "amgf3Lb3Hg56MtJU4vyAywAAAQg"]
[Tue Jul 28 05:19:57.224083 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "amgf3bb3Hg56MtJU4vyAzQAAARQ"]
[Tue Jul 28 05:19:57.225109 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "amgf3bb3Hg56MtJU4vyAzQAAARQ"]
[Tue Jul 28 05:19:57.225694 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "amgf3bb3Hg56MtJU4vyAzQAAARQ"]
[Tue Jul 28 05:19:57.225946 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "amgf3bb3Hg56MtJU4vyAzQAAARQ"]
[Tue Jul 28 05:19:57.506754 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "amgf3bb3Hg56MtJU4vyAzwAAARA"]
[Tue Jul 28 05:19:57.507725 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "amgf3bb3Hg56MtJU4vyAzwAAARA"]
[Tue Jul 28 05:19:57.508145 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "amgf3bb3Hg56MtJU4vyAzwAAARA"]
[Tue Jul 28 05:19:57.508408 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v3/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "amgf3bb3Hg56MtJU4vyAzwAAARA"]
[Tue Jul 28 05:19:57.788190 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "amgf3bb3Hg56MtJU4vyA0AAAAQ4"]
[Tue Jul 28 05:19:57.789038 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "amgf3bb3Hg56MtJU4vyA0AAAAQ4"]
[Tue Jul 28 05:19:57.789610 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "amgf3bb3Hg56MtJU4vyA0AAAAQ4"]
[Tue Jul 28 05:19:57.789849 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "amgf3bb3Hg56MtJU4vyA0AAAAQ4"]
[Tue Jul 28 05:19:58.067696 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA0wAAAQo"]
[Tue Jul 28 05:19:58.068531 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA0wAAAQo"]
[Tue Jul 28 05:19:58.069071 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA0wAAAQo"]
[Tue Jul 28 05:19:58.069310 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA0wAAAQo"]
[Tue Jul 28 05:19:58.346745 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA1QAAAQA"]
[Tue Jul 28 05:19:58.347360 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA1QAAAQA"]
[Tue Jul 28 05:19:58.347827 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA1QAAAQA"]
[Tue Jul 28 05:19:58.348051 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /rest/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA1QAAAQA"]
[Tue Jul 28 05:19:58.626836 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA2AAAARM"]
[Tue Jul 28 05:19:58.627905 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA2AAAARM"]
[Tue Jul 28 05:19:58.628597 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA2AAAARM"]
[Tue Jul 28 05:19:58.628846 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /graphql/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA2AAAARM"]
[Tue Jul 28 05:19:58.908655 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA2gAAAQU"]
[Tue Jul 28 05:19:58.909451 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA2gAAAQU"]
[Tue Jul 28 05:19:58.909969 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA2gAAAQU"]
[Tue Jul 28 05:19:58.910203 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /gateway/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "amgf3rb3Hg56MtJU4vyA2gAAAQU"]
[Tue Jul 28 05:19:59.197799 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "amgf37b3Hg56MtJU4vyA3AAAAQ0"]
[Tue Jul 28 05:19:59.198692 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "amgf37b3Hg56MtJU4vyA3AAAAQ0"]
[Tue Jul 28 05:19:59.199249 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "amgf37b3Hg56MtJU4vyA3AAAAQ0"]
[Tue Jul 28 05:19:59.199535 2026] [:error] [pid 711:tid 139944563521280] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /microservice/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "amgf37b3Hg56MtJU4vyA3AAAAQ0"]
[Tue Jul 28 05:19:59.479597 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/service/.env"] [unique_id "amgf37b3Hg56MtJU4vyA3QAAARQ"]
[Tue Jul 28 05:19:59.480399 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/service/.env"] [unique_id "amgf37b3Hg56MtJU4vyA3QAAARQ"]
[Tue Jul 28 05:19:59.480936 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/service/.env"] [unique_id "amgf37b3Hg56MtJU4vyA3QAAARQ"]
[Tue Jul 28 05:19:59.481180 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /service/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/service/.env"] [unique_id "amgf37b3Hg56MtJU4vyA3QAAARQ"]
[Tue Jul 28 05:19:59.761005 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "amgf37b3Hg56MtJU4vyA4AAAARc"]
[Tue Jul 28 05:19:59.762016 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "amgf37b3Hg56MtJU4vyA4AAAARc"]
[Tue Jul 28 05:19:59.762629 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "amgf37b3Hg56MtJU4vyA4AAAARc"]
[Tue Jul 28 05:19:59.762868 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/v3/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "amgf37b3Hg56MtJU4vyA4AAAARc"]
[Tue Jul 28 05:20:00.042825 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA4QAAARg"]
[Tue Jul 28 05:20:00.044138 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA4QAAARg"]
[Tue Jul 28 05:20:00.045971 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA4QAAARg"]
[Tue Jul 28 05:20:00.046445 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/dev/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA4QAAARg"]
[Tue Jul 28 05:20:00.325353 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA4wAAARY"]
[Tue Jul 28 05:20:00.326335 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA4wAAARY"]
[Tue Jul 28 05:20:00.326931 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA4wAAARY"]
[Tue Jul 28 05:20:00.327151 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/staging/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA4wAAARY"]
[Tue Jul 28 05:20:00.604723 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA5QAAAQo"]
[Tue Jul 28 05:20:00.605735 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA5QAAAQo"]
[Tue Jul 28 05:20:00.606357 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA5QAAAQo"]
[Tue Jul 28 05:20:00.606628 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /vendor/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA5QAAAQo"]
[Tue Jul 28 05:20:00.888047 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA5wAAARM"]
[Tue Jul 28 05:20:00.888770 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA5wAAARM"]
[Tue Jul 28 05:20:00.889221 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA5wAAARM"]
[Tue Jul 28 05:20:00.889481 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lib/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "amgf4Lb3Hg56MtJU4vyA5wAAARM"]
[Tue Jul 28 05:20:01.169593 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "amgf4bb3Hg56MtJU4vyA6QAAAQw"]
[Tue Jul 28 05:20:01.170426 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "amgf4bb3Hg56MtJU4vyA6QAAAQw"]
[Tue Jul 28 05:20:01.170996 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "amgf4bb3Hg56MtJU4vyA6QAAAQw"]
[Tue Jul 28 05:20:01.171243 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /resources/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "amgf4bb3Hg56MtJU4vyA6QAAAQw"]
[Tue Jul 28 05:20:01.449768 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "amgf4bb3Hg56MtJU4vyA7AAAARc"]
[Tue Jul 28 05:20:01.450590 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "amgf4bb3Hg56MtJU4vyA7AAAARc"]
[Tue Jul 28 05:20:01.451092 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "amgf4bb3Hg56MtJU4vyA7AAAARc"]
[Tue Jul 28 05:20:01.451356 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "amgf4bb3Hg56MtJU4vyA7AAAARc"]
[Tue Jul 28 05:20:01.728814 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "amgf4bb3Hg56MtJU4vyA7wAAARU"]
[Tue Jul 28 05:20:01.729657 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "amgf4bb3Hg56MtJU4vyA7wAAARU"]
[Tue Jul 28 05:20:01.730151 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "amgf4bb3Hg56MtJU4vyA7wAAARU"]
[Tue Jul 28 05:20:01.730380 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "amgf4bb3Hg56MtJU4vyA7wAAARU"]
[Tue Jul 28 05:20:02.051127 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "amgf4rb3Hg56MtJU4vyA8wAAAQ8"]
[Tue Jul 28 05:20:02.052276 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "amgf4rb3Hg56MtJU4vyA8wAAAQ8"]
[Tue Jul 28 05:20:02.053259 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "amgf4rb3Hg56MtJU4vyA8wAAAQ8"]
[Tue Jul 28 05:20:02.053604 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /internal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "amgf4rb3Hg56MtJU4vyA8wAAAQ8"]
[Tue Jul 28 05:20:02.334260 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "amgf4rb3Hg56MtJU4vyA9gAAAQo"]
[Tue Jul 28 05:20:02.335388 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "amgf4rb3Hg56MtJU4vyA9gAAAQo"]
[Tue Jul 28 05:20:02.336025 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "amgf4rb3Hg56MtJU4vyA9gAAAQo"]
[Tue Jul 28 05:20:02.336279 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "amgf4rb3Hg56MtJU4vyA9gAAAQo"]
[Tue Jul 28 05:20:02.615364 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "amgf4rb3Hg56MtJU4vyA-AAAARI"]
[Tue Jul 28 05:20:02.616020 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "amgf4rb3Hg56MtJU4vyA-AAAARI"]
[Tue Jul 28 05:20:02.616510 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "amgf4rb3Hg56MtJU4vyA-AAAARI"]
[Tue Jul 28 05:20:02.616777 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:13918] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /scripts/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "amgf4rb3Hg56MtJU4vyA-AAAARI"]
[Tue Jul 28 05:20:03.653399 2026] [:error] [pid 27702:tid 139944487986944] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "amgf44m1AQFltHspB3loKgAAAJY"]
[Tue Jul 28 05:20:03.654257 2026] [:error] [pid 27702:tid 139944487986944] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "amgf44m1AQFltHspB3loKgAAAJY"]
[Tue Jul 28 05:20:03.654772 2026] [:error] [pid 27702:tid 139944487986944] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "amgf44m1AQFltHspB3loKgAAAJY"]
[Tue Jul 28 05:20:03.655018 2026] [:error] [pid 27702:tid 139944487986944] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /bin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "amgf44m1AQFltHspB3loKgAAAJY"]
[Tue Jul 28 05:20:03.931894 2026] [:error] [pid 27702:tid 139944563521280] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "amgf44m1AQFltHspB3loLAAAAI0"]
[Tue Jul 28 05:20:03.932580 2026] [:error] [pid 27702:tid 139944563521280] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "amgf44m1AQFltHspB3loLAAAAI0"]
[Tue Jul 28 05:20:03.932976 2026] [:error] [pid 27702:tid 139944563521280] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "amgf44m1AQFltHspB3loLAAAAI0"]
[Tue Jul 28 05:20:03.933162 2026] [:error] [pid 27702:tid 139944563521280] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sbin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "amgf44m1AQFltHspB3loLAAAAI0"]
[Tue Jul 28 05:20:04.213399 2026] [:error] [pid 27702:tid 139944538343168] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/local/.env"] [unique_id "amgf5Im1AQFltHspB3loLgAAAJA"]
[Tue Jul 28 05:20:04.214015 2026] [:error] [pid 27702:tid 139944538343168] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/local/.env"] [unique_id "amgf5Im1AQFltHspB3loLgAAAJA"]
[Tue Jul 28 05:20:04.214431 2026] [:error] [pid 27702:tid 139944538343168] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/local/.env"] [unique_id "amgf5Im1AQFltHspB3loLgAAAJA"]
[Tue Jul 28 05:20:04.214599 2026] [:error] [pid 27702:tid 139944538343168] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/local/.env"] [unique_id "amgf5Im1AQFltHspB3loLgAAAJA"]
[Tue Jul 28 05:20:04.490154 2026] [:error] [pid 27702:tid 139944580306688] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "amgf5Im1AQFltHspB3loLwAAAIs"]
[Tue Jul 28 05:20:04.490884 2026] [:error] [pid 27702:tid 139944580306688] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "amgf5Im1AQFltHspB3loLwAAAIs"]
[Tue Jul 28 05:20:04.491356 2026] [:error] [pid 27702:tid 139944580306688] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "amgf5Im1AQFltHspB3loLwAAAIs"]
[Tue Jul 28 05:20:04.491543 2026] [:error] [pid 27702:tid 139944580306688] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /portal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "amgf5Im1AQFltHspB3loLwAAAIs"]
[Tue Jul 28 05:20:04.766656 2026] [:error] [pid 27702:tid 139944513165056] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "amgf5Im1AQFltHspB3loMAAAAJM"]
[Tue Jul 28 05:20:04.767254 2026] [:error] [pid 27702:tid 139944513165056] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "amgf5Im1AQFltHspB3loMAAAAJM"]
[Tue Jul 28 05:20:04.767670 2026] [:error] [pid 27702:tid 139944513165056] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "amgf5Im1AQFltHspB3loMAAAAJM"]
[Tue Jul 28 05:20:04.767859 2026] [:error] [pid 27702:tid 139944513165056] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /dashboard/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "amgf5Im1AQFltHspB3loMAAAAJM"]
[Tue Jul 28 05:20:05.045539 2026] [:error] [pid 27702:tid 139944529950464] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "amgf5Ym1AQFltHspB3loMwAAAJE"]
[Tue Jul 28 05:20:05.046437 2026] [:error] [pid 27702:tid 139944529950464] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "amgf5Ym1AQFltHspB3loMwAAAJE"]
[Tue Jul 28 05:20:05.046983 2026] [:error] [pid 27702:tid 139944529950464] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "amgf5Ym1AQFltHspB3loMwAAAJE"]
[Tue Jul 28 05:20:05.047230 2026] [:error] [pid 27702:tid 139944529950464] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "amgf5Ym1AQFltHspB3loMwAAAJE"]
[Tue Jul 28 05:20:05.335234 2026] [:error] [pid 27702:tid 139944655841024] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "amgf5Ym1AQFltHspB3loNAAAAII"]
[Tue Jul 28 05:20:05.336091 2026] [:error] [pid 27702:tid 139944655841024] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "amgf5Ym1AQFltHspB3loNAAAAII"]
[Tue Jul 28 05:20:05.336698 2026] [:error] [pid 27702:tid 139944655841024] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "amgf5Ym1AQFltHspB3loNAAAAII"]
[Tue Jul 28 05:20:05.336953 2026] [:error] [pid 27702:tid 139944655841024] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /crm/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "amgf5Ym1AQFltHspB3loNAAAAII"]
[Tue Jul 28 05:20:05.615633 2026] [:error] [pid 27702:tid 139944605484800] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "amgf5Ym1AQFltHspB3loNwAAAIg"]
[Tue Jul 28 05:20:05.616477 2026] [:error] [pid 27702:tid 139944605484800] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "amgf5Ym1AQFltHspB3loNwAAAIg"]
[Tue Jul 28 05:20:05.616907 2026] [:error] [pid 27702:tid 139944605484800] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "amgf5Ym1AQFltHspB3loNwAAAIg"]
[Tue Jul 28 05:20:05.617132 2026] [:error] [pid 27702:tid 139944605484800] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /erp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "amgf5Ym1AQFltHspB3loNwAAAIg"]
[Tue Jul 28 05:20:05.899446 2026] [:error] [pid 27702:tid 139944647448320] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "amgf5Ym1AQFltHspB3loOQAAAIM"]
[Tue Jul 28 05:20:05.900087 2026] [:error] [pid 27702:tid 139944647448320] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "amgf5Ym1AQFltHspB3loOQAAAIM"]
[Tue Jul 28 05:20:05.900500 2026] [:error] [pid 27702:tid 139944647448320] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "amgf5Ym1AQFltHspB3loOQAAAIM"]
[Tue Jul 28 05:20:05.900690 2026] [:error] [pid 27702:tid 139944647448320] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /shop/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "amgf5Ym1AQFltHspB3loOQAAAIM"]
[Tue Jul 28 05:20:06.183355 2026] [:error] [pid 27702:tid 139944630662912] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/store/.env"] [unique_id "amgf5om1AQFltHspB3loOgAAAIU"]
[Tue Jul 28 05:20:06.184205 2026] [:error] [pid 27702:tid 139944630662912] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/store/.env"] [unique_id "amgf5om1AQFltHspB3loOgAAAIU"]
[Tue Jul 28 05:20:06.184763 2026] [:error] [pid 27702:tid 139944630662912] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/store/.env"] [unique_id "amgf5om1AQFltHspB3loOgAAAIU"]
[Tue Jul 28 05:20:06.185006 2026] [:error] [pid 27702:tid 139944630662912] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /store/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/store/.env"] [unique_id "amgf5om1AQFltHspB3loOgAAAIU"]
[Tue Jul 28 05:20:06.463202 2026] [:error] [pid 27702:tid 139944555128576] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "amgf5om1AQFltHspB3loPAAAAI4"]
[Tue Jul 28 05:20:06.464060 2026] [:error] [pid 27702:tid 139944555128576] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "amgf5om1AQFltHspB3loPAAAAI4"]
[Tue Jul 28 05:20:06.464615 2026] [:error] [pid 27702:tid 139944555128576] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "amgf5om1AQFltHspB3loPAAAAI4"]
[Tue Jul 28 05:20:06.464846 2026] [:error] [pid 27702:tid 139944555128576] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "amgf5om1AQFltHspB3loPAAAAI4"]
[Tue Jul 28 05:20:06.742509 2026] [:error] [pid 27702:tid 139944479594240] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amgf5om1AQFltHspB3loPQAAAJc"]
[Tue Jul 28 05:20:06.743369 2026] [:error] [pid 27702:tid 139944479594240] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amgf5om1AQFltHspB3loPQAAAJc"]
[Tue Jul 28 05:20:06.743972 2026] [:error] [pid 27702:tid 139944479594240] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amgf5om1AQFltHspB3loPQAAAJc"]
[Tue Jul 28 05:20:06.744227 2026] [:error] [pid 27702:tid 139944479594240] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /client/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amgf5om1AQFltHspB3loPQAAAJc"]
[Tue Jul 28 05:20:07.020857 2026] [:error] [pid 27702:tid 139944588699392] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/project/.env"] [unique_id "amgf54m1AQFltHspB3loPgAAAIo"]
[Tue Jul 28 05:20:07.021470 2026] [:error] [pid 27702:tid 139944588699392] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/project/.env"] [unique_id "amgf54m1AQFltHspB3loPgAAAIo"]
[Tue Jul 28 05:20:07.021864 2026] [:error] [pid 27702:tid 139944588699392] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/project/.env"] [unique_id "amgf54m1AQFltHspB3loPgAAAIo"]
[Tue Jul 28 05:20:07.022082 2026] [:error] [pid 27702:tid 139944588699392] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /project/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/project/.env"] [unique_id "amgf54m1AQFltHspB3loPgAAAIo"]
[Tue Jul 28 05:20:07.298880 2026] [:error] [pid 27702:tid 139944487986944] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "amgf54m1AQFltHspB3loQAAAAJY"]
[Tue Jul 28 05:20:07.299795 2026] [:error] [pid 27702:tid 139944487986944] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "amgf54m1AQFltHspB3loQAAAAJY"]
[Tue Jul 28 05:20:07.300403 2026] [:error] [pid 27702:tid 139944487986944] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "amgf54m1AQFltHspB3loQAAAAJY"]
[Tue Jul 28 05:20:07.300693 2026] [:error] [pid 27702:tid 139944487986944] [client 141.101.85.25:13129] [client 141.101.85.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin-panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "amgf54m1AQFltHspB3loQAAAAJY"]
[Tue Jul 28 05:20:08.336486 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "amgf6Lb3Hg56MtJU4vyBEAAAAQw"]
[Tue Jul 28 05:20:08.337367 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "amgf6Lb3Hg56MtJU4vyBEAAAAQw"]
[Tue Jul 28 05:20:08.337925 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "amgf6Lb3Hg56MtJU4vyBEAAAAQw"]
[Tue Jul 28 05:20:08.338168 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /control-panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "amgf6Lb3Hg56MtJU4vyBEAAAAQw"]
[Tue Jul 28 05:20:08.615538 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "amgf6Lb3Hg56MtJU4vyBEgAAARY"]
[Tue Jul 28 05:20:08.616314 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "amgf6Lb3Hg56MtJU4vyBEgAAARY"]
[Tue Jul 28 05:20:08.616793 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "amgf6Lb3Hg56MtJU4vyBEgAAARY"]
[Tue Jul 28 05:20:08.616969 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /user-panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "amgf6Lb3Hg56MtJU4vyBEgAAARY"]
[Tue Jul 28 05:20:08.893216 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/node/.env"] [unique_id "amgf6Lb3Hg56MtJU4vyBFAAAAQM"]
[Tue Jul 28 05:20:08.894298 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/node/.env"] [unique_id "amgf6Lb3Hg56MtJU4vyBFAAAAQM"]
[Tue Jul 28 05:20:08.894933 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/node/.env"] [unique_id "amgf6Lb3Hg56MtJU4vyBFAAAAQM"]
[Tue Jul 28 05:20:08.895094 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/node/.env"] [unique_id "amgf6Lb3Hg56MtJU4vyBFAAAAQM"]
[Tue Jul 28 05:20:09.172295 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/express/.env"] [unique_id "amgf6bb3Hg56MtJU4vyBFgAAARE"]
[Tue Jul 28 05:20:09.173402 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/express/.env"] [unique_id "amgf6bb3Hg56MtJU4vyBFgAAARE"]
[Tue Jul 28 05:20:09.174073 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/express/.env"] [unique_id "amgf6bb3Hg56MtJU4vyBFgAAARE"]
[Tue Jul 28 05:20:09.174293 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /express/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/express/.env"] [unique_id "amgf6bb3Hg56MtJU4vyBFgAAARE"]
[Tue Jul 28 05:20:09.453884 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/next/.env"] [unique_id "amgf6bb3Hg56MtJU4vyBGAAAARQ"]
[Tue Jul 28 05:20:09.454788 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/next/.env"] [unique_id "amgf6bb3Hg56MtJU4vyBGAAAARQ"]
[Tue Jul 28 05:20:09.455354 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/next/.env"] [unique_id "amgf6bb3Hg56MtJU4vyBGAAAARQ"]
[Tue Jul 28 05:20:09.455628 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /next/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/next/.env"] [unique_id "amgf6bb3Hg56MtJU4vyBGAAAARQ"]
[Tue Jul 28 05:20:09.733643 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "amgf6bb3Hg56MtJU4vyBGwAAARI"]
[Tue Jul 28 05:20:09.734417 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "amgf6bb3Hg56MtJU4vyBGwAAARI"]
[Tue Jul 28 05:20:09.734930 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "amgf6bb3Hg56MtJU4vyBGwAAARI"]
[Tue Jul 28 05:20:09.735091 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nuxt/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "amgf6bb3Hg56MtJU4vyBGwAAARI"]
[Tue Jul 28 05:20:10.013925 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBHgAAAQU"]
[Tue Jul 28 05:20:10.014930 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBHgAAAQU"]
[Tue Jul 28 05:20:10.015512 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBHgAAAQU"]
[Tue Jul 28 05:20:10.015772 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nest/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBHgAAAQU"]
[Tue Jul 28 05:20:10.293273 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/react/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBIAAAAQE"]
[Tue Jul 28 05:20:10.294155 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/react/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBIAAAAQE"]
[Tue Jul 28 05:20:10.294727 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/react/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBIAAAAQE"]
[Tue Jul 28 05:20:10.294967 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/react/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBIAAAAQE"]
[Tue Jul 28 05:20:10.572622 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBIQAAAQ8"]
[Tue Jul 28 05:20:10.573298 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBIQAAAQ8"]
[Tue Jul 28 05:20:10.573742 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBIQAAAQ8"]
[Tue Jul 28 05:20:10.573892 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /vue/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBIQAAAQ8"]
[Tue Jul 28 05:20:10.851515 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBIgAAARg"]
[Tue Jul 28 05:20:10.852426 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBIgAAARg"]
[Tue Jul 28 05:20:10.852992 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBIgAAARg"]
[Tue Jul 28 05:20:10.853265 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /angular/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "amgf6rb3Hg56MtJU4vyBIgAAARg"]
[Tue Jul 28 05:20:11.141639 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "amgf67b3Hg56MtJU4vyBJQAAARM"]
[Tue Jul 28 05:20:11.142699 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "amgf67b3Hg56MtJU4vyBJQAAARM"]
[Tue Jul 28 05:20:11.143404 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "amgf67b3Hg56MtJU4vyBJQAAARM"]
[Tue Jul 28 05:20:11.143688 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /svelte/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "amgf67b3Hg56MtJU4vyBJQAAARM"]
[Tue Jul 28 05:20:11.421947 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "amgf67b3Hg56MtJU4vyBKAAAAQQ"]
[Tue Jul 28 05:20:11.422954 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "amgf67b3Hg56MtJU4vyBKAAAAQQ"]
[Tue Jul 28 05:20:11.423577 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "amgf67b3Hg56MtJU4vyBKAAAAQQ"]
[Tue Jul 28 05:20:11.423816 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /vite/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "amgf67b3Hg56MtJU4vyBKAAAAQQ"]
[Tue Jul 28 05:20:11.701181 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amgf67b3Hg56MtJU4vyBKwAAAQE"]
[Tue Jul 28 05:20:11.702149 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amgf67b3Hg56MtJU4vyBKwAAAQE"]
[Tue Jul 28 05:20:11.702670 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amgf67b3Hg56MtJU4vyBKwAAAQE"]
[Tue Jul 28 05:20:11.702837 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backup/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amgf67b3Hg56MtJU4vyBKwAAAQE"]
[Tue Jul 28 05:20:11.982337 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amgf67b3Hg56MtJU4vyBMAAAARY"]
[Tue Jul 28 05:20:11.983408 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amgf67b3Hg56MtJU4vyBMAAAARY"]
[Tue Jul 28 05:20:11.983842 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amgf67b3Hg56MtJU4vyBMAAAARY"]
[Tue Jul 28 05:20:11.984023 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backups/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amgf67b3Hg56MtJU4vyBMAAAARY"]
[Tue Jul 28 05:20:12.288470 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amgf7Lb3Hg56MtJU4vyBNAAAARE"]
[Tue Jul 28 05:20:12.289811 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amgf7Lb3Hg56MtJU4vyBNAAAARE"]
[Tue Jul 28 05:20:12.296812 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amgf7Lb3Hg56MtJU4vyBNAAAARE"]
[Tue Jul 28 05:20:12.298297 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /old/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amgf7Lb3Hg56MtJU4vyBNAAAARE"]
[Tue Jul 28 05:20:12.594899 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amgf7Lb3Hg56MtJU4vyBNwAAARc"]
[Tue Jul 28 05:20:12.596067 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amgf7Lb3Hg56MtJU4vyBNwAAARc"]
[Tue Jul 28 05:20:12.596644 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amgf7Lb3Hg56MtJU4vyBNwAAARc"]
[Tue Jul 28 05:20:12.596898 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tmp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amgf7Lb3Hg56MtJU4vyBNwAAARc"]
[Tue Jul 28 05:20:12.889210 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amgf7Lb3Hg56MtJU4vyBOwAAAQY"]
[Tue Jul 28 05:20:12.890416 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amgf7Lb3Hg56MtJU4vyBOwAAAQY"]
[Tue Jul 28 05:20:12.891102 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amgf7Lb3Hg56MtJU4vyBOwAAAQY"]
[Tue Jul 28 05:20:12.891371 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /temp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amgf7Lb3Hg56MtJU4vyBOwAAAQY"]
[Tue Jul 28 05:20:13.183995 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "amgf7bb3Hg56MtJU4vyBPwAAAQc"]
[Tue Jul 28 05:20:13.185001 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "amgf7bb3Hg56MtJU4vyBPwAAAQc"]
[Tue Jul 28 05:20:13.185594 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "amgf7bb3Hg56MtJU4vyBPwAAAQc"]
[Tue Jul 28 05:20:13.185850 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "amgf7bb3Hg56MtJU4vyBPwAAAQc"]
[Tue Jul 28 05:20:13.462508 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "amgf7bb3Hg56MtJU4vyBQQAAAQI"]
[Tue Jul 28 05:20:13.463471 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "amgf7bb3Hg56MtJU4vyBQQAAAQI"]
[Tue Jul 28 05:20:13.464024 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "amgf7bb3Hg56MtJU4vyBQQAAAQI"]
[Tue Jul 28 05:20:13.464256 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "amgf7bb3Hg56MtJU4vyBQQAAAQI"]
[Tue Jul 28 05:20:13.744509 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "amgf7bb3Hg56MtJU4vyBRQAAARc"]
[Tue Jul 28 05:20:13.745576 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "amgf7bb3Hg56MtJU4vyBRQAAARc"]
[Tue Jul 28 05:20:13.746164 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "amgf7bb3Hg56MtJU4vyBRQAAARc"]
[Tue Jul 28 05:20:13.746421 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "amgf7bb3Hg56MtJU4vyBRQAAARc"]
[Tue Jul 28 05:20:14.025790 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/en/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBSQAAARU"]
[Tue Jul 28 05:20:14.026537 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/en/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBSQAAARU"]
[Tue Jul 28 05:20:14.026956 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/en/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBSQAAARU"]
[Tue Jul 28 05:20:14.027104 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/en/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBSQAAARU"]
[Tue Jul 28 05:20:14.308160 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBTAAAARY"]
[Tue Jul 28 05:20:14.309215 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBTAAAARY"]
[Tue Jul 28 05:20:14.309918 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBTAAAARY"]
[Tue Jul 28 05:20:14.310193 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBTAAAARY"]
[Tue Jul 28 05:20:14.587670 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBUQAAARA"]
[Tue Jul 28 05:20:14.588611 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBUQAAARA"]
[Tue Jul 28 05:20:14.589133 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBUQAAARA"]
[Tue Jul 28 05:20:14.589403 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBUQAAARA"]
[Tue Jul 28 05:20:14.868986 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBVAAAARU"]
[Tue Jul 28 05:20:14.870048 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBVAAAARU"]
[Tue Jul 28 05:20:14.870690 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBVAAAARU"]
[Tue Jul 28 05:20:14.870943 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "amgf7rb3Hg56MtJU4vyBVAAAARU"]
[Tue Jul 28 05:20:15.150286 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "amgf77b3Hg56MtJU4vyBWQAAAQM"]
[Tue Jul 28 05:20:15.151080 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "amgf77b3Hg56MtJU4vyBWQAAAQM"]
[Tue Jul 28 05:20:15.151643 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "amgf77b3Hg56MtJU4vyBWQAAAQM"]
[Tue Jul 28 05:20:15.151814 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "amgf77b3Hg56MtJU4vyBWQAAAQM"]
[Tue Jul 28 05:20:15.433857 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "amgf77b3Hg56MtJU4vyBXAAAAQI"]
[Tue Jul 28 05:20:15.434874 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "amgf77b3Hg56MtJU4vyBXAAAAQI"]
[Tue Jul 28 05:20:15.435430 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "amgf77b3Hg56MtJU4vyBXAAAAQI"]
[Tue Jul 28 05:20:15.435692 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "amgf77b3Hg56MtJU4vyBXAAAAQI"]
[Tue Jul 28 05:20:15.717823 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "amgf77b3Hg56MtJU4vyBYAAAAQY"]
[Tue Jul 28 05:20:15.718890 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "amgf77b3Hg56MtJU4vyBYAAAAQY"]
[Tue Jul 28 05:20:15.719511 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "amgf77b3Hg56MtJU4vyBYAAAAQY"]
[Tue Jul 28 05:20:15.719774 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "amgf77b3Hg56MtJU4vyBYAAAAQY"]
[Tue Jul 28 05:20:16.000632 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "amgf77b3Hg56MtJU4vyBZAAAARE"]
[Tue Jul 28 05:20:16.001768 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "amgf77b3Hg56MtJU4vyBZAAAARE"]
[Tue Jul 28 05:20:16.002315 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "amgf77b3Hg56MtJU4vyBZAAAARE"]
[Tue Jul 28 05:20:16.002513 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /logs/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "amgf77b3Hg56MtJU4vyBZAAAARE"]
[Tue Jul 28 05:20:16.280643 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "amgf8Lb3Hg56MtJU4vyBZwAAARQ"]
[Tue Jul 28 05:20:16.281490 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "amgf8Lb3Hg56MtJU4vyBZwAAARQ"]
[Tue Jul 28 05:20:16.282035 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "amgf8Lb3Hg56MtJU4vyBZwAAARQ"]
[Tue Jul 28 05:20:16.282273 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cache/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "amgf8Lb3Hg56MtJU4vyBZwAAARQ"]
[Tue Jul 28 05:20:16.563016 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "amgf8Lb3Hg56MtJU4vyBawAAARY"]
[Tue Jul 28 05:20:16.563622 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "amgf8Lb3Hg56MtJU4vyBawAAARY"]
[Tue Jul 28 05:20:16.564055 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "amgf8Lb3Hg56MtJU4vyBawAAARY"]
[Tue Jul 28 05:20:16.584260 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailer/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "amgf8Lb3Hg56MtJU4vyBawAAARY"]
[Tue Jul 28 05:20:16.875206 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "amgf8Lb3Hg56MtJU4vyBbgAAAQU"]
[Tue Jul 28 05:20:16.876273 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "amgf8Lb3Hg56MtJU4vyBbgAAAQU"]
[Tue Jul 28 05:20:16.876909 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "amgf8Lb3Hg56MtJU4vyBbgAAAQU"]
[Tue Jul 28 05:20:16.877154 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mail/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "amgf8Lb3Hg56MtJU4vyBbgAAAQU"]
[Tue Jul 28 05:20:17.155688 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/email/.env"] [unique_id "amgf8bb3Hg56MtJU4vyBcAAAAQA"]
[Tue Jul 28 05:20:17.156599 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/email/.env"] [unique_id "amgf8bb3Hg56MtJU4vyBcAAAAQA"]
[Tue Jul 28 05:20:17.157137 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/email/.env"] [unique_id "amgf8bb3Hg56MtJU4vyBcAAAAQA"]
[Tue Jul 28 05:20:17.157402 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /email/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/email/.env"] [unique_id "amgf8bb3Hg56MtJU4vyBcAAAAQA"]
[Tue Jul 28 05:20:17.436874 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "amgf8bb3Hg56MtJU4vyBcwAAARQ"]
[Tue Jul 28 05:20:17.437783 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "amgf8bb3Hg56MtJU4vyBcwAAARQ"]
[Tue Jul 28 05:20:17.438302 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "amgf8bb3Hg56MtJU4vyBcwAAARQ"]
[Tue Jul 28 05:20:17.438515 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /smtp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "amgf8bb3Hg56MtJU4vyBcwAAARQ"]
[Tue Jul 28 05:20:17.729137 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "amgf8bb3Hg56MtJU4vyBdwAAAQY"]
[Tue Jul 28 05:20:17.730168 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "amgf8bb3Hg56MtJU4vyBdwAAAQY"]
[Tue Jul 28 05:20:17.730741 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "amgf8bb3Hg56MtJU4vyBdwAAAQY"]
[Tue Jul 28 05:20:17.730967 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailing/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "amgf8bb3Hg56MtJU4vyBdwAAAQY"]
[Tue Jul 28 05:20:18.031904 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBfAAAAQs"]
[Tue Jul 28 05:20:18.032892 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBfAAAAQs"]
[Tue Jul 28 05:20:18.033471 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBfAAAAQs"]
[Tue Jul 28 05:20:18.033733 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /notifications/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBfAAAAQs"]
[Tue Jul 28 05:20:18.310396 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBfgAAAQo"]
[Tue Jul 28 05:20:18.311314 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBfgAAAQo"]
[Tue Jul 28 05:20:18.311927 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBfgAAAQo"]
[Tue Jul 28 05:20:18.312179 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /notify/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBfgAAAQo"]
[Tue Jul 28 05:20:18.619115 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBhAAAAQs"]
[Tue Jul 28 05:20:18.620093 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBhAAAAQs"]
[Tue Jul 28 05:20:18.620689 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBhAAAAQs"]
[Tue Jul 28 05:20:18.620931 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sender/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBhAAAAQs"]
[Tue Jul 28 05:20:18.899666 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBhwAAAQc"]
[Tue Jul 28 05:20:18.900508 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBhwAAAQc"]
[Tue Jul 28 05:20:18.900995 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBhwAAAQc"]
[Tue Jul 28 05:20:18.901199 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /campaign/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "amgf8rb3Hg56MtJU4vyBhwAAAQc"]
[Tue Jul 28 05:20:19.179082 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "amgf87b3Hg56MtJU4vyBigAAARQ"]
[Tue Jul 28 05:20:19.180144 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "amgf87b3Hg56MtJU4vyBigAAARQ"]
[Tue Jul 28 05:20:19.180787 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "amgf87b3Hg56MtJU4vyBigAAARQ"]
[Tue Jul 28 05:20:19.181035 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /newsletter/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "amgf87b3Hg56MtJU4vyBigAAARQ"]
[Tue Jul 28 05:20:19.461964 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "amgf87b3Hg56MtJU4vyBjgAAAQI"]
[Tue Jul 28 05:20:19.462966 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "amgf87b3Hg56MtJU4vyBjgAAAQI"]
[Tue Jul 28 05:20:19.463536 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "amgf87b3Hg56MtJU4vyBjgAAAQI"]
[Tue Jul 28 05:20:19.463802 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /ses/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "amgf87b3Hg56MtJU4vyBjgAAAQI"]
[Tue Jul 28 05:20:19.747084 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "amgf87b3Hg56MtJU4vyBkAAAAQg"]
[Tue Jul 28 05:20:19.748084 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "amgf87b3Hg56MtJU4vyBkAAAAQg"]
[Tue Jul 28 05:20:19.748752 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "amgf87b3Hg56MtJU4vyBkAAAAQg"]
[Tue Jul 28 05:20:19.748969 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sendgrid/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "amgf87b3Hg56MtJU4vyBkAAAAQg"]
[Tue Jul 28 05:20:20.029995 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBlAAAARM"]
[Tue Jul 28 05:20:20.031052 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBlAAAARM"]
[Tue Jul 28 05:20:20.031700 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBlAAAARM"]
[Tue Jul 28 05:20:20.031965 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sparkpost/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBlAAAARM"]
[Tue Jul 28 05:20:20.333138 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBlwAAAQw"]
[Tue Jul 28 05:20:20.334293 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBlwAAAQw"]
[Tue Jul 28 05:20:20.334977 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBlwAAAQw"]
[Tue Jul 28 05:20:20.335212 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /postmark/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBlwAAAQw"]
[Tue Jul 28 05:20:20.619029 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBnQAAAQU"]
[Tue Jul 28 05:20:20.620058 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBnQAAAQU"]
[Tue Jul 28 05:20:20.620725 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBnQAAAQU"]
[Tue Jul 28 05:20:20.620959 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailgun/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBnQAAAQU"]
[Tue Jul 28 05:20:20.905863 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBoAAAARc"]
[Tue Jul 28 05:20:20.906796 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBoAAAARc"]
[Tue Jul 28 05:20:20.907383 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBoAAAARc"]
[Tue Jul 28 05:20:20.907664 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mandrill/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "amgf9Lb3Hg56MtJU4vyBoAAAARc"]
[Tue Jul 28 05:20:21.191957 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "amgf9bb3Hg56MtJU4vyBowAAAQ4"]
[Tue Jul 28 05:20:21.192779 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "amgf9bb3Hg56MtJU4vyBowAAAQ4"]
[Tue Jul 28 05:20:21.193344 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "amgf9bb3Hg56MtJU4vyBowAAAQ4"]
[Tue Jul 28 05:20:21.193603 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailjet/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "amgf9bb3Hg56MtJU4vyBowAAAQ4"]
[Tue Jul 28 05:20:21.478765 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "amgf9bb3Hg56MtJU4vyBpgAAAQw"]
[Tue Jul 28 05:20:21.479604 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "amgf9bb3Hg56MtJU4vyBpgAAAQw"]
[Tue Jul 28 05:20:21.480115 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "amgf9bb3Hg56MtJU4vyBpgAAAQw"]
[Tue Jul 28 05:20:21.480377 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /brevo/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "amgf9bb3Hg56MtJU4vyBpgAAAQw"]
[Tue Jul 28 05:20:21.784488 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "amgf9bb3Hg56MtJU4vyBrQAAAQU"]
[Tue Jul 28 05:20:21.785711 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "amgf9bb3Hg56MtJU4vyBrQAAAQU"]
[Tue Jul 28 05:20:21.786307 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "amgf9bb3Hg56MtJU4vyBrQAAAQU"]
[Tue Jul 28 05:20:21.786596 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /transactional/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "amgf9bb3Hg56MtJU4vyBrQAAAQU"]
[Tue Jul 28 05:20:22.071709 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBrwAAARI"]
[Tue Jul 28 05:20:22.072578 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBrwAAARI"]
[Tue Jul 28 05:20:22.073118 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBrwAAARI"]
[Tue Jul 28 05:20:22.073375 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /bulk/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBrwAAARI"]
[Tue Jul 28 05:20:22.360299 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBsgAAAQM"]
[Tue Jul 28 05:20:22.361274 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBsgAAAQM"]
[Tue Jul 28 05:20:22.362107 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBsgAAAQM"]
[Tue Jul 28 05:20:22.362411 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /aws/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBsgAAAQM"]
[Tue Jul 28 05:20:22.639833 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBtwAAARM"]
[Tue Jul 28 05:20:22.641059 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBtwAAARM"]
[Tue Jul 28 05:20:22.641760 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBtwAAARM"]
[Tue Jul 28 05:20:22.641958 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /azure/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBtwAAARM"]
[Tue Jul 28 05:20:22.921757 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBugAAAQc"]
[Tue Jul 28 05:20:22.922528 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBugAAAQc"]
[Tue Jul 28 05:20:22.922977 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBugAAAQc"]
[Tue Jul 28 05:20:22.923128 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /gcp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "amgf9rb3Hg56MtJU4vyBugAAAQc"]
[Tue Jul 28 05:20:23.201930 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "amgf97b3Hg56MtJU4vyBvAAAARc"]
[Tue Jul 28 05:20:23.202917 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "amgf97b3Hg56MtJU4vyBvAAAARc"]
[Tue Jul 28 05:20:23.203519 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "amgf97b3Hg56MtJU4vyBvAAAARc"]
[Tue Jul 28 05:20:23.203767 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cloud/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "amgf97b3Hg56MtJU4vyBvAAAARc"]
[Tue Jul 28 05:20:23.481672 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "amgf97b3Hg56MtJU4vyBwAAAAQs"]
[Tue Jul 28 05:20:23.482534 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "amgf97b3Hg56MtJU4vyBwAAAAQs"]
[Tue Jul 28 05:20:23.483089 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "amgf97b3Hg56MtJU4vyBwAAAAQs"]
[Tue Jul 28 05:20:23.483375 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /infrastructure/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "amgf97b3Hg56MtJU4vyBwAAAAQs"]
[Tue Jul 28 05:20:23.759567 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "amgf97b3Hg56MtJU4vyBwwAAARA"]
[Tue Jul 28 05:20:23.760414 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "amgf97b3Hg56MtJU4vyBwwAAARA"]
[Tue Jul 28 05:20:23.760948 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "amgf97b3Hg56MtJU4vyBwwAAARA"]
[Tue Jul 28 05:20:23.761195 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "amgf97b3Hg56MtJU4vyBwwAAARA"]
[Tue Jul 28 05:20:24.038533 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyBxwAAARQ"]
[Tue Jul 28 05:20:24.039463 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyBxwAAARQ"]
[Tue Jul 28 05:20:24.040019 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyBxwAAARQ"]
[Tue Jul 28 05:20:24.040317 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /k8s/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyBxwAAARQ"]
[Tue Jul 28 05:20:24.316255 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyBywAAARY"]
[Tue Jul 28 05:20:24.317223 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyBywAAARY"]
[Tue Jul 28 05:20:24.317924 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyBywAAARY"]
[Tue Jul 28 05:20:24.318163 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kubernetes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyBywAAARY"]
[Tue Jul 28 05:20:24.594960 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyBzwAAAQs"]
[Tue Jul 28 05:20:24.595778 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyBzwAAAQs"]
[Tue Jul 28 05:20:24.596183 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyBzwAAAQs"]
[Tue Jul 28 05:20:24.596407 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /terraform/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyBzwAAAQs"]
[Tue Jul 28 05:20:24.876475 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyB0gAAAQo"]
[Tue Jul 28 05:20:24.877375 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyB0gAAAQo"]
[Tue Jul 28 05:20:24.877915 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyB0gAAAQo"]
[Tue Jul 28 05:20:24.878162 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /ansible/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "amgf-Lb3Hg56MtJU4vyB0gAAAQo"]
[Tue Jul 28 05:20:25.157282 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB1QAAAQI"]
[Tue Jul 28 05:20:25.158248 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB1QAAAQI"]
[Tue Jul 28 05:20:25.158792 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB1QAAAQI"]
[Tue Jul 28 05:20:25.159004 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB1QAAAQI"]
[Tue Jul 28 05:20:25.435835 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB2AAAAQc"]
[Tue Jul 28 05:20:25.436865 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB2AAAAQc"]
[Tue Jul 28 05:20:25.437417 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB2AAAAQc"]
[Tue Jul 28 05:20:25.437634 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /ci/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB2AAAAQc"]
[Tue Jul 28 05:20:25.714802 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB2wAAAQA"]
[Tue Jul 28 05:20:25.715514 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB2wAAAQA"]
[Tue Jul 28 05:20:25.715944 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB2wAAAQA"]
[Tue Jul 28 05:20:25.716149 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cd/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB2wAAAQA"]
[Tue Jul 28 05:20:25.993164 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB3gAAARM"]
[Tue Jul 28 05:20:25.994186 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB3gAAARM"]
[Tue Jul 28 05:20:25.994862 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB3gAAARM"]
[Tue Jul 28 05:20:25.995114 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /jenkins/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "amgf-bb3Hg56MtJU4vyB3gAAARM"]
[Tue Jul 28 05:20:26.271887 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "amgf-rb3Hg56MtJU4vyB4QAAAQY"]
[Tue Jul 28 05:20:26.272924 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "amgf-rb3Hg56MtJU4vyB4QAAAQY"]
[Tue Jul 28 05:20:26.273491 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "amgf-rb3Hg56MtJU4vyB4QAAAQY"]
[Tue Jul 28 05:20:26.273729 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /gitlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "amgf-rb3Hg56MtJU4vyB4QAAAQY"]
[Tue Jul 28 05:20:26.550496 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/github/.env"] [unique_id "amgf-rb3Hg56MtJU4vyB5AAAAQI"]
[Tue Jul 28 05:20:26.551440 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/github/.env"] [unique_id "amgf-rb3Hg56MtJU4vyB5AAAAQI"]
[Tue Jul 28 05:20:26.552041 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/github/.env"] [unique_id "amgf-rb3Hg56MtJU4vyB5AAAAQI"]
[Tue Jul 28 05:20:26.552267 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /github/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/github/.env"] [unique_id "amgf-rb3Hg56MtJU4vyB5AAAAQI"]
[Tue Jul 28 05:20:26.830864 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "amgf-rb3Hg56MtJU4vyB6AAAARI"]
[Tue Jul 28 05:20:26.831813 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "amgf-rb3Hg56MtJU4vyB6AAAARI"]
[Tue Jul 28 05:20:26.832396 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "amgf-rb3Hg56MtJU4vyB6AAAARI"]
[Tue Jul 28 05:20:26.832656 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /actions/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "amgf-rb3Hg56MtJU4vyB6AAAARI"]
[Tue Jul 28 05:20:27.114420 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB7AAAAQs"]
[Tue Jul 28 05:20:27.115110 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB7AAAAQs"]
[Tue Jul 28 05:20:27.115481 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB7AAAAQs"]
[Tue Jul 28 05:20:27.115643 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /circleci/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB7AAAAQs"]
[Tue Jul 28 05:20:27.392955 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB8QAAAQI"]
[Tue Jul 28 05:20:27.393963 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB8QAAAQI"]
[Tue Jul 28 05:20:27.394545 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB8QAAAQI"]
[Tue Jul 28 05:20:27.394808 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /travis/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB8QAAAQI"]
[Tue Jul 28 05:20:27.676867 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB8wAAARg"]
[Tue Jul 28 05:20:27.678130 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB8wAAARg"]
[Tue Jul 28 05:20:27.678966 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB8wAAARg"]
[Tue Jul 28 05:20:27.679254 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /buildkite/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB8wAAARg"]
[Tue Jul 28 05:20:27.955923 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB9wAAAQ4"]
[Tue Jul 28 05:20:27.956647 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB9wAAAQ4"]
[Tue Jul 28 05:20:27.957087 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB9wAAAQ4"]
[Tue Jul 28 05:20:27.957248 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mysql/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "amgf-7b3Hg56MtJU4vyB9wAAAQ4"]
[Tue Jul 28 05:20:28.234528 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "amgf_Lb3Hg56MtJU4vyB-gAAAQk"]
[Tue Jul 28 05:20:28.235403 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "amgf_Lb3Hg56MtJU4vyB-gAAAQk"]
[Tue Jul 28 05:20:28.235874 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "amgf_Lb3Hg56MtJU4vyB-gAAAQk"]
[Tue Jul 28 05:20:28.236060 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /postgres/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "amgf_Lb3Hg56MtJU4vyB-gAAAQk"]
[Tue Jul 28 05:20:28.515621 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "amgf_Lb3Hg56MtJU4vyB_wAAAQY"]
[Tue Jul 28 05:20:28.516479 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "amgf_Lb3Hg56MtJU4vyB_wAAAQY"]
[Tue Jul 28 05:20:28.516990 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "amgf_Lb3Hg56MtJU4vyB_wAAAQY"]
[Tue Jul 28 05:20:28.517215 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mongodb/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "amgf_Lb3Hg56MtJU4vyB_wAAAQY"]
[Tue Jul 28 05:20:28.793269 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "amgf_Lb3Hg56MtJU4vyCAgAAAQw"]
[Tue Jul 28 05:20:28.794168 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "amgf_Lb3Hg56MtJU4vyCAgAAAQw"]
[Tue Jul 28 05:20:28.794728 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "amgf_Lb3Hg56MtJU4vyCAgAAAQw"]
[Tue Jul 28 05:20:28.794978 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /redis/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "amgf_Lb3Hg56MtJU4vyCAgAAAQw"]
[Tue Jul 28 05:20:29.074867 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCBgAAAQk"]
[Tue Jul 28 05:20:29.075880 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCBgAAAQk"]
[Tue Jul 28 05:20:29.076436 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCBgAAAQk"]
[Tue Jul 28 05:20:29.076719 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /elasticsearch/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCBgAAAQk"]
[Tue Jul 28 05:20:29.357804 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCCwAAAQ8"]
[Tue Jul 28 05:20:29.358587 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCCwAAAQ8"]
[Tue Jul 28 05:20:29.359054 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCCwAAAQ8"]
[Tue Jul 28 05:20:29.359249 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /rabbitmq/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCCwAAAQ8"]
[Tue Jul 28 05:20:29.635623 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCDwAAARA"]
[Tue Jul 28 05:20:29.636460 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCDwAAARA"]
[Tue Jul 28 05:20:29.636996 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCDwAAARA"]
[Tue Jul 28 05:20:29.637246 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kafka/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCDwAAARA"]
[Tue Jul 28 05:20:29.920029 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCEwAAAQk"]
[Tue Jul 28 05:20:29.921090 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCEwAAAQk"]
[Tue Jul 28 05:20:29.921709 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCEwAAAQk"]
[Tue Jul 28 05:20:29.921948 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /queue/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "amgf_bb3Hg56MtJU4vyCEwAAAQk"]
[Tue Jul 28 05:20:30.198652 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "amgf_rb3Hg56MtJU4vyCFgAAARM"]
[Tue Jul 28 05:20:30.199973 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "amgf_rb3Hg56MtJU4vyCFgAAARM"]
[Tue Jul 28 05:20:30.200815 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "amgf_rb3Hg56MtJU4vyCFgAAARM"]
[Tue Jul 28 05:20:30.201088 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /worker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "amgf_rb3Hg56MtJU4vyCFgAAARM"]
[Tue Jul 28 05:20:30.525052 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/job/.env"] [unique_id "amgf_rb3Hg56MtJU4vyCGgAAARc"]
[Tue Jul 28 05:20:30.526088 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/job/.env"] [unique_id "amgf_rb3Hg56MtJU4vyCGgAAARc"]
[Tue Jul 28 05:20:30.526728 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/job/.env"] [unique_id "amgf_rb3Hg56MtJU4vyCGgAAARc"]
[Tue Jul 28 05:20:30.526998 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /job/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/job/.env"] [unique_id "amgf_rb3Hg56MtJU4vyCGgAAARc"]
[Tue Jul 28 05:20:30.816064 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/test/.env"] [unique_id "amgf_rb3Hg56MtJU4vyCHwAAAQU"]
[Tue Jul 28 05:20:30.817150 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/test/.env"] [unique_id "amgf_rb3Hg56MtJU4vyCHwAAAQU"]
[Tue Jul 28 05:20:30.817754 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/test/.env"] [unique_id "amgf_rb3Hg56MtJU4vyCHwAAAQU"]
[Tue Jul 28 05:20:30.817981 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /test/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/test/.env"] [unique_id "amgf_rb3Hg56MtJU4vyCHwAAAQU"]
[Tue Jul 28 05:20:31.094746 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCIgAAARM"]
[Tue Jul 28 05:20:31.095786 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCIgAAARM"]
[Tue Jul 28 05:20:31.096382 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCIgAAARM"]
[Tue Jul 28 05:20:31.096633 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /qa/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCIgAAARM"]
[Tue Jul 28 05:20:31.381011 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCJQAAAQQ"]
[Tue Jul 28 05:20:31.382107 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCJQAAAQQ"]
[Tue Jul 28 05:20:31.382777 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCJQAAAQQ"]
[Tue Jul 28 05:20:31.383037 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /preview/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCJQAAAQQ"]
[Tue Jul 28 05:20:31.660887 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCKQAAARE"]
[Tue Jul 28 05:20:31.662094 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCKQAAARE"]
[Tue Jul 28 05:20:31.662701 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCKQAAARE"]
[Tue Jul 28 05:20:31.662946 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /beta/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCKQAAARE"]
[Tue Jul 28 05:20:31.941259 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCKwAAAQw"]
[Tue Jul 28 05:20:31.942201 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCKwAAAQw"]
[Tue Jul 28 05:20:31.942772 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCKwAAAQw"]
[Tue Jul 28 05:20:31.942996 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uat/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "amgf_7b3Hg56MtJU4vyCKwAAAQw"]
[Tue Jul 28 05:20:32.222116 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "amggALb3Hg56MtJU4vyCMgAAARY"]
[Tue Jul 28 05:20:32.223216 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "amggALb3Hg56MtJU4vyCMgAAARY"]
[Tue Jul 28 05:20:32.223884 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "amggALb3Hg56MtJU4vyCMgAAARY"]
[Tue Jul 28 05:20:32.224134 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /stage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "amggALb3Hg56MtJU4vyCMgAAARY"]
[Tue Jul 28 05:20:32.502273 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/development/.env"] [unique_id "amggALb3Hg56MtJU4vyCNQAAARE"]
[Tue Jul 28 05:20:32.503033 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/development/.env"] [unique_id "amggALb3Hg56MtJU4vyCNQAAARE"]
[Tue Jul 28 05:20:32.503484 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/development/.env"] [unique_id "amggALb3Hg56MtJU4vyCNQAAARE"]
[Tue Jul 28 05:20:32.503661 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /development/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/development/.env"] [unique_id "amggALb3Hg56MtJU4vyCNQAAARE"]
[Tue Jul 28 05:20:32.786117 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/production/.env"] [unique_id "amggALb3Hg56MtJU4vyCOAAAAQw"]
[Tue Jul 28 05:20:32.786885 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/production/.env"] [unique_id "amggALb3Hg56MtJU4vyCOAAAAQw"]
[Tue Jul 28 05:20:32.787358 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/production/.env"] [unique_id "amggALb3Hg56MtJU4vyCOAAAAQw"]
[Tue Jul 28 05:20:32.787525 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /production/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/production/.env"] [unique_id "amggALb3Hg56MtJU4vyCOAAAAQw"]
[Tue Jul 28 05:20:33.068296 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "amggAbb3Hg56MtJU4vyCOwAAAQ8"]
[Tue Jul 28 05:20:33.068945 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "amggAbb3Hg56MtJU4vyCOwAAAQ8"]
[Tue Jul 28 05:20:33.069315 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "amggAbb3Hg56MtJU4vyCOwAAAQ8"]
[Tue Jul 28 05:20:33.069504 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "amggAbb3Hg56MtJU4vyCOwAAAQ8"]
[Tue Jul 28 05:20:33.357679 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.vault"] [unique_id "amggAbb3Hg56MtJU4vyCPgAAARI"]
[Tue Jul 28 05:20:33.358674 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.vault"] [unique_id "amggAbb3Hg56MtJU4vyCPgAAARI"]
[Tue Jul 28 05:20:33.359128 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.vault"] [unique_id "amggAbb3Hg56MtJU4vyCPgAAARI"]
[Tue Jul 28 05:20:33.359320 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.vault"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.vault"] [unique_id "amggAbb3Hg56MtJU4vyCPgAAARI"]
[Tue Jul 28 05:20:33.635701 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.fly"] [unique_id "amggAbb3Hg56MtJU4vyCQQAAAQI"]
[Tue Jul 28 05:20:33.636358 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.fly"] [unique_id "amggAbb3Hg56MtJU4vyCQQAAAQI"]
[Tue Jul 28 05:20:33.636748 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.fly"] [unique_id "amggAbb3Hg56MtJU4vyCQQAAAQI"]
[Tue Jul 28 05:20:33.636991 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.fly"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.fly"] [unique_id "amggAbb3Hg56MtJU4vyCQQAAAQI"]
[Tue Jul 28 05:20:33.914609 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.railway"] [unique_id "amggAbb3Hg56MtJU4vyCRQAAARQ"]
[Tue Jul 28 05:20:33.915572 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.railway"] [unique_id "amggAbb3Hg56MtJU4vyCRQAAARQ"]
[Tue Jul 28 05:20:33.916175 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.railway"] [unique_id "amggAbb3Hg56MtJU4vyCRQAAARQ"]
[Tue Jul 28 05:20:33.916429 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.railway"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.railway"] [unique_id "amggAbb3Hg56MtJU4vyCRQAAARQ"]
[Tue Jul 28 05:20:34.193826 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.render"] [unique_id "amggArb3Hg56MtJU4vyCRwAAAQ8"]
[Tue Jul 28 05:20:34.194660 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.render"] [unique_id "amggArb3Hg56MtJU4vyCRwAAAQ8"]
[Tue Jul 28 05:20:34.195150 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.render"] [unique_id "amggArb3Hg56MtJU4vyCRwAAAQ8"]
[Tue Jul 28 05:20:34.195351 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.render"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.render"] [unique_id "amggArb3Hg56MtJU4vyCRwAAAQ8"]
[Tue Jul 28 05:20:34.475993 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.vercel"] [unique_id "amggArb3Hg56MtJU4vyCSgAAAQc"]
[Tue Jul 28 05:20:34.476786 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.vercel"] [unique_id "amggArb3Hg56MtJU4vyCSgAAAQc"]
[Tue Jul 28 05:20:34.477217 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.vercel"] [unique_id "amggArb3Hg56MtJU4vyCSgAAAQc"]
[Tue Jul 28 05:20:34.477402 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.vercel"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.vercel"] [unique_id "amggArb3Hg56MtJU4vyCSgAAAQc"]
[Tue Jul 28 05:20:34.769738 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.supabase"] [unique_id "amggArb3Hg56MtJU4vyCTwAAAQQ"]
[Tue Jul 28 05:20:34.771323 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.supabase"] [unique_id "amggArb3Hg56MtJU4vyCTwAAAQQ"]
[Tue Jul 28 05:20:34.771972 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.supabase"] [unique_id "amggArb3Hg56MtJU4vyCTwAAAQQ"]
[Tue Jul 28 05:20:34.772129 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.supabase"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.supabase"] [unique_id "amggArb3Hg56MtJU4vyCTwAAAQQ"]
[Tue Jul 28 05:20:35.048460 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.neon"] [unique_id "amggA7b3Hg56MtJU4vyCUgAAAQk"]
[Tue Jul 28 05:20:35.049389 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.neon"] [unique_id "amggA7b3Hg56MtJU4vyCUgAAAQk"]
[Tue Jul 28 05:20:35.049915 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.neon"] [unique_id "amggA7b3Hg56MtJU4vyCUgAAAQk"]
[Tue Jul 28 05:20:35.050168 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.neon"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.neon"] [unique_id "amggA7b3Hg56MtJU4vyCUgAAAQk"]
[Tue Jul 28 05:20:35.328683 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amggA7b3Hg56MtJU4vyCWQAAAQs"]
[Tue Jul 28 05:20:35.329496 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amggA7b3Hg56MtJU4vyCWQAAAQs"]
[Tue Jul 28 05:20:35.329994 2026] [:error] [pid 711:tid 139944580306688] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amggA7b3Hg56MtJU4vyCWQAAAQs"]
[Tue Jul 28 05:20:35.607206 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/info.php"] [unique_id "amggA7b3Hg56MtJU4vyCWwAAAQw"]
[Tue Jul 28 05:20:35.608167 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/info.php"] [unique_id "amggA7b3Hg56MtJU4vyCWwAAAQw"]
[Tue Jul 28 05:20:35.608770 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/info.php"] [unique_id "amggA7b3Hg56MtJU4vyCWwAAAQw"]
[Tue Jul 28 05:20:35.896884 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/php.php"] [unique_id "amggA7b3Hg56MtJU4vyCXwAAAQg"]
[Tue Jul 28 05:20:35.897905 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/php.php"] [unique_id "amggA7b3Hg56MtJU4vyCXwAAAQg"]
[Tue Jul 28 05:20:35.898499 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/php.php"] [unique_id "amggA7b3Hg56MtJU4vyCXwAAAQg"]
[Tue Jul 28 05:20:36.176455 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/i.php"] [unique_id "amggBLb3Hg56MtJU4vyCYgAAARI"]
[Tue Jul 28 05:20:36.177154 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/i.php"] [unique_id "amggBLb3Hg56MtJU4vyCYgAAARI"]
[Tue Jul 28 05:20:36.177672 2026] [:error] [pid 711:tid 139944521557760] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/i.php"] [unique_id "amggBLb3Hg56MtJU4vyCYgAAARI"]
[Tue Jul 28 05:20:36.456063 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/pi.php"] [unique_id "amggBLb3Hg56MtJU4vyCZQAAAQ4"]
[Tue Jul 28 05:20:36.457071 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/pi.php"] [unique_id "amggBLb3Hg56MtJU4vyCZQAAAQ4"]
[Tue Jul 28 05:20:36.457579 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/pi.php"] [unique_id "amggBLb3Hg56MtJU4vyCZQAAAQ4"]
[Tue Jul 28 05:20:36.734112 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/pinfo.php"] [unique_id "amggBLb3Hg56MtJU4vyCagAAAQw"]
[Tue Jul 28 05:20:36.735147 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/pinfo.php"] [unique_id "amggBLb3Hg56MtJU4vyCagAAAQw"]
[Tue Jul 28 05:20:36.735772 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:12479] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/pinfo.php"] [unique_id "amggBLb3Hg56MtJU4vyCagAAAQw"]
[Tue Jul 28 05:20:37.775174 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/test.php"] [unique_id "amggBbb3Hg56MtJU4vyCeAAAAQ4"]
[Tue Jul 28 05:20:37.776251 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/test.php"] [unique_id "amggBbb3Hg56MtJU4vyCeAAAAQ4"]
[Tue Jul 28 05:20:37.776844 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/test.php"] [unique_id "amggBbb3Hg56MtJU4vyCeAAAAQ4"]
[Tue Jul 28 05:20:38.053910 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo"] [unique_id "amggBrb3Hg56MtJU4vyCfAAAARE"]
[Tue Jul 28 05:20:38.054904 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo"] [unique_id "amggBrb3Hg56MtJU4vyCfAAAARE"]
[Tue Jul 28 05:20:38.055418 2026] [:error] [pid 711:tid 139944529950464] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo"] [unique_id "amggBrb3Hg56MtJU4vyCfAAAARE"]
[Tue Jul 28 05:20:38.332783 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/p.php"] [unique_id "amggBrb3Hg56MtJU4vyCgAAAAQ4"]
[Tue Jul 28 05:20:38.333691 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/p.php"] [unique_id "amggBrb3Hg56MtJU4vyCgAAAAQ4"]
[Tue Jul 28 05:20:38.334124 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/p.php"] [unique_id "amggBrb3Hg56MtJU4vyCgAAAAQ4"]
[Tue Jul 28 05:20:38.621703 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/debug.php"] [unique_id "amggBrb3Hg56MtJU4vyChAAAAQE"]
[Tue Jul 28 05:20:38.622548 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/debug.php"] [unique_id "amggBrb3Hg56MtJU4vyChAAAAQE"]
[Tue Jul 28 05:20:38.623098 2026] [:error] [pid 711:tid 139944664233728] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/debug.php"] [unique_id "amggBrb3Hg56MtJU4vyChAAAAQE"]
[Tue Jul 28 05:20:38.900001 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/admin/phpinfo.php"] [unique_id "amggBrb3Hg56MtJU4vyCiAAAAQo"]
[Tue Jul 28 05:20:38.901414 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/admin/phpinfo.php"] [unique_id "amggBrb3Hg56MtJU4vyCiAAAAQo"]
[Tue Jul 28 05:20:38.902203 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/admin/phpinfo.php"] [unique_id "amggBrb3Hg56MtJU4vyCiAAAAQo"]
[Tue Jul 28 05:20:39.197960 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/test/phpinfo.php"] [unique_id "amggB7b3Hg56MtJU4vyCigAAAQU"]
[Tue Jul 28 05:20:39.198987 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/test/phpinfo.php"] [unique_id "amggB7b3Hg56MtJU4vyCigAAAQU"]
[Tue Jul 28 05:20:39.199589 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/test/phpinfo.php"] [unique_id "amggB7b3Hg56MtJU4vyCigAAAQU"]
[Tue Jul 28 05:20:39.492978 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/dev/phpinfo.php"] [unique_id "amggB7b3Hg56MtJU4vyCjQAAAQ4"]
[Tue Jul 28 05:20:39.494018 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/dev/phpinfo.php"] [unique_id "amggB7b3Hg56MtJU4vyCjQAAAQ4"]
[Tue Jul 28 05:20:39.494661 2026] [:error] [pid 711:tid 139944555128576] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/dev/phpinfo.php"] [unique_id "amggB7b3Hg56MtJU4vyCjQAAAQ4"]
[Tue Jul 28 05:20:39.777973 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/old/phpinfo.php"] [unique_id "amggB7b3Hg56MtJU4vyCkQAAAQg"]
[Tue Jul 28 05:20:39.778893 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/old/phpinfo.php"] [unique_id "amggB7b3Hg56MtJU4vyCkQAAAQg"]
[Tue Jul 28 05:20:39.779423 2026] [:error] [pid 711:tid 139944605484800] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/old/phpinfo.php"] [unique_id "amggB7b3Hg56MtJU4vyCkQAAAQg"]
[Tue Jul 28 05:20:40.060273 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/tmp/phpinfo.php"] [unique_id "amggCLb3Hg56MtJU4vyClgAAARY"]
[Tue Jul 28 05:20:40.061066 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/tmp/phpinfo.php"] [unique_id "amggCLb3Hg56MtJU4vyClgAAARY"]
[Tue Jul 28 05:20:40.061602 2026] [:error] [pid 711:tid 139944487986944] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/tmp/phpinfo.php"] [unique_id "amggCLb3Hg56MtJU4vyClgAAARY"]
[Tue Jul 28 05:20:40.345347 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/public/phpinfo.php"] [unique_id "amggCLb3Hg56MtJU4vyCmwAAARA"]
[Tue Jul 28 05:20:40.345903 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/public/phpinfo.php"] [unique_id "amggCLb3Hg56MtJU4vyCmwAAARA"]
[Tue Jul 28 05:20:40.346358 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/public/phpinfo.php"] [unique_id "amggCLb3Hg56MtJU4vyCmwAAARA"]
[Tue Jul 28 05:20:40.623006 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/info"] [unique_id "amggCLb3Hg56MtJU4vyCngAAAQo"]
[Tue Jul 28 05:20:40.623901 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/info"] [unique_id "amggCLb3Hg56MtJU4vyCngAAAQo"]
[Tue Jul 28 05:20:40.624441 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/info"] [unique_id "amggCLb3Hg56MtJU4vyCngAAAQo"]
[Tue Jul 28 05:20:40.903568 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amggCLb3Hg56MtJU4vyCogAAAQA"]
[Tue Jul 28 05:20:40.904283 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amggCLb3Hg56MtJU4vyCogAAAQA"]
[Tue Jul 28 05:20:40.904898 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amggCLb3Hg56MtJU4vyCogAAAQA"]
[Tue Jul 28 05:20:41.187434 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpversion.php"] [unique_id "amggCbb3Hg56MtJU4vyCqAAAAQ8"]
[Tue Jul 28 05:20:41.188418 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpversion.php"] [unique_id "amggCbb3Hg56MtJU4vyCqAAAAQ8"]
[Tue Jul 28 05:20:41.189004 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13302] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpversion.php"] [unique_id "amggCbb3Hg56MtJU4vyCqAAAAQ8"]
[Tue Jul 28 05:20:42.235096 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/_phpinfo.php"] [unique_id "amggCrb3Hg56MtJU4vyCsQAAAQo"]
[Tue Jul 28 05:20:42.236180 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/_phpinfo.php"] [unique_id "amggCrb3Hg56MtJU4vyCsQAAAQo"]
[Tue Jul 28 05:20:42.236839 2026] [:error] [pid 711:tid 139944588699392] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/_phpinfo.php"] [unique_id "amggCrb3Hg56MtJU4vyCsQAAAQo"]
[Tue Jul 28 05:20:42.516974 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/old_phpinfo.php"] [unique_id "amggCrb3Hg56MtJU4vyCtQAAAQ8"]
[Tue Jul 28 05:20:42.517956 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/old_phpinfo.php"] [unique_id "amggCrb3Hg56MtJU4vyCtQAAAQ8"]
[Tue Jul 28 05:20:42.518577 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/old_phpinfo.php"] [unique_id "amggCrb3Hg56MtJU4vyCtQAAAQ8"]
[Tue Jul 28 05:20:42.795389 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/server-info.php"] [unique_id "amggCrb3Hg56MtJU4vyCuAAAARg"]
[Tue Jul 28 05:20:42.796084 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/server-info.php"] [unique_id "amggCrb3Hg56MtJU4vyCuAAAARg"]
[Tue Jul 28 05:20:42.796465 2026] [:error] [pid 711:tid 139944471201536] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/server-info.php"] [unique_id "amggCrb3Hg56MtJU4vyCuAAAARg"]
[Tue Jul 28 05:20:43.084957 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/server-status.php"] [unique_id "amggC7b3Hg56MtJU4vyCvQAAARQ"]
[Tue Jul 28 05:20:43.085928 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/server-status.php"] [unique_id "amggC7b3Hg56MtJU4vyCvQAAARQ"]
[Tue Jul 28 05:20:43.086466 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/server-status.php"] [unique_id "amggC7b3Hg56MtJU4vyCvQAAARQ"]
[Tue Jul 28 05:20:43.367054 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/_profiler/phpinfo"] [unique_id "amggC7b3Hg56MtJU4vyCwAAAAQw"]
[Tue Jul 28 05:20:43.368069 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/_profiler/phpinfo"] [unique_id "amggC7b3Hg56MtJU4vyCwAAAAQw"]
[Tue Jul 28 05:20:43.368596 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/_profiler/phpinfo"] [unique_id "amggC7b3Hg56MtJU4vyCwAAAAQw"]
[Tue Jul 28 05:20:43.653993 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/_environment"] [unique_id "amggC7b3Hg56MtJU4vyCxAAAAQY"]
[Tue Jul 28 05:20:43.655086 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/_environment"] [unique_id "amggC7b3Hg56MtJU4vyCxAAAAQY"]
[Tue Jul 28 05:20:43.655686 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/_environment"] [unique_id "amggC7b3Hg56MtJU4vyCxAAAAQY"]
[Tue Jul 28 05:20:43.950136 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/webroot/index.php/_environment"] [unique_id "amggC7b3Hg56MtJU4vyCxwAAAQI"]
[Tue Jul 28 05:20:43.951123 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/webroot/index.php/_environment"] [unique_id "amggC7b3Hg56MtJU4vyCxwAAAQI"]
[Tue Jul 28 05:20:43.951715 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/webroot/index.php/_environment"] [unique_id "amggC7b3Hg56MtJU4vyCxwAAAQI"]
[Tue Jul 28 05:20:44.235049 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mail/phpinfo.php"] [unique_id "amggDLb3Hg56MtJU4vyCywAAARQ"]
[Tue Jul 28 05:20:44.236033 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mail/phpinfo.php"] [unique_id "amggDLb3Hg56MtJU4vyCywAAARQ"]
[Tue Jul 28 05:20:44.236992 2026] [:error] [pid 711:tid 139944504772352] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mail/phpinfo.php"] [unique_id "amggDLb3Hg56MtJU4vyCywAAARQ"]
[Tue Jul 28 05:20:44.517910 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cpanel/phpinfo.php"] [unique_id "amggDLb3Hg56MtJU4vyCzQAAAQQ"]
[Tue Jul 28 05:20:46.317664 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/hosting/phpinfo.php"] [unique_id "amggDrb3Hg56MtJU4vyC2gAAAQQ"]
[Tue Jul 28 05:20:46.318444 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/hosting/phpinfo.php"] [unique_id "amggDrb3Hg56MtJU4vyC2gAAAQQ"]
[Tue Jul 28 05:20:46.318894 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/hosting/phpinfo.php"] [unique_id "amggDrb3Hg56MtJU4vyC2gAAAQQ"]
[Tue Jul 28 05:20:46.598808 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/webmail/phpinfo.php"] [unique_id "amggDrb3Hg56MtJU4vyC3gAAAQU"]
[Tue Jul 28 05:20:46.599454 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/webmail/phpinfo.php"] [unique_id "amggDrb3Hg56MtJU4vyC3gAAAQU"]
[Tue Jul 28 05:20:46.599934 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/webmail/phpinfo.php"] [unique_id "amggDrb3Hg56MtJU4vyC3gAAAQU"]
[Tue Jul 28 05:20:46.862244 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/smtp/phpinfo.php"] [unique_id "amggDrb3Hg56MtJU4vyC4QAAAQw"]
[Tue Jul 28 05:20:46.863055 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/smtp/phpinfo.php"] [unique_id "amggDrb3Hg56MtJU4vyC4QAAAQw"]
[Tue Jul 28 05:20:46.863578 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/smtp/phpinfo.php"] [unique_id "amggDrb3Hg56MtJU4vyC4QAAAQw"]
[Tue Jul 28 05:20:47.140462 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amggD7b3Hg56MtJU4vyC5QAAAQM"]
[Tue Jul 28 05:20:47.141525 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amggD7b3Hg56MtJU4vyC5QAAAQM"]
[Tue Jul 28 05:20:47.142169 2026] [:error] [pid 711:tid 139944647448320] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amggD7b3Hg56MtJU4vyC5QAAAQM"]
[Tue Jul 28 05:20:47.426168 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.old"] [unique_id "amggD7b3Hg56MtJU4vyC6gAAAQI"]
[Tue Jul 28 05:20:47.427191 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.old"] [unique_id "amggD7b3Hg56MtJU4vyC6gAAAQI"]
[Tue Jul 28 05:20:47.427830 2026] [:error] [pid 711:tid 139944655841024] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.old"] [unique_id "amggD7b3Hg56MtJU4vyC6gAAAQI"]
[Tue Jul 28 05:20:47.712884 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "amggD7b3Hg56MtJU4vyC7AAAAQc"]
[Tue Jul 28 05:20:47.713629 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "amggD7b3Hg56MtJU4vyC7AAAAQc"]
[Tue Jul 28 05:20:47.713860 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Pattern match "\\\\.[^.~]+~(?:/.*|)$" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1060"] [id "920500"] [msg "Attempt to access a backup or working file"] [data ".php~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "amggD7b3Hg56MtJU4vyC7AAAAQc"]
[Tue Jul 28 05:20:47.714114 2026] [:error] [pid 711:tid 139944613877504] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "amggD7b3Hg56MtJU4vyC7AAAAQc"]
[Tue Jul 28 05:20:47.990670 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amggD7b3Hg56MtJU4vyC8AAAAQ8"]
[Tue Jul 28 05:20:47.991518 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amggD7b3Hg56MtJU4vyC8AAAAQ8"]
[Tue Jul 28 05:20:47.992052 2026] [:error] [pid 711:tid 139944546735872] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amggD7b3Hg56MtJU4vyC8AAAAQ8"]
[Tue Jul 28 05:20:48.279233 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.save"] [unique_id "amggELb3Hg56MtJU4vyC8gAAAQY"]
[Tue Jul 28 05:20:48.280152 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.save"] [unique_id "amggELb3Hg56MtJU4vyC8gAAAQY"]
[Tue Jul 28 05:20:48.280703 2026] [:error] [pid 711:tid 139944622270208] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.save"] [unique_id "amggELb3Hg56MtJU4vyC8gAAAQY"]
[Tue Jul 28 05:20:48.575968 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/staging/phpinfo.php"] [unique_id "amggELb3Hg56MtJU4vyC-AAAAQk"]
[Tue Jul 28 05:20:48.577169 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/staging/phpinfo.php"] [unique_id "amggELb3Hg56MtJU4vyC-AAAAQk"]
[Tue Jul 28 05:20:48.577788 2026] [:error] [pid 711:tid 139944597092096] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/staging/phpinfo.php"] [unique_id "amggELb3Hg56MtJU4vyC-AAAAQk"]
[Tue Jul 28 05:20:48.863668 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/beta/phpinfo.php"] [unique_id "amggELb3Hg56MtJU4vyC-gAAAQU"]
[Tue Jul 28 05:20:48.864565 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/beta/phpinfo.php"] [unique_id "amggELb3Hg56MtJU4vyC-gAAAQU"]
[Tue Jul 28 05:20:48.865124 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/beta/phpinfo.php"] [unique_id "amggELb3Hg56MtJU4vyC-gAAAQU"]
[Tue Jul 28 05:20:49.141238 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/uat/phpinfo.php"] [unique_id "amggEbb3Hg56MtJU4vyC_AAAAQQ"]
[Tue Jul 28 05:20:49.141860 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/uat/phpinfo.php"] [unique_id "amggEbb3Hg56MtJU4vyC_AAAAQQ"]
[Tue Jul 28 05:20:49.142265 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/uat/phpinfo.php"] [unique_id "amggEbb3Hg56MtJU4vyC_AAAAQQ"]
[Tue Jul 28 05:20:49.418618 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/qa/phpinfo.php"] [unique_id "amggEbb3Hg56MtJU4vyC_wAAARc"]
[Tue Jul 28 05:20:49.419763 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/qa/phpinfo.php"] [unique_id "amggEbb3Hg56MtJU4vyC_wAAARc"]
[Tue Jul 28 05:20:49.420436 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/qa/phpinfo.php"] [unique_id "amggEbb3Hg56MtJU4vyC_wAAARc"]
[Tue Jul 28 05:20:49.701800 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/preview/phpinfo.php"] [unique_id "amggEbb3Hg56MtJU4vyDAQAAARA"]
[Tue Jul 28 05:20:49.707924 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/preview/phpinfo.php"] [unique_id "amggEbb3Hg56MtJU4vyDAQAAARA"]
[Tue Jul 28 05:20:49.708676 2026] [:error] [pid 711:tid 139944538343168] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/preview/phpinfo.php"] [unique_id "amggEbb3Hg56MtJU4vyDAQAAARA"]
[Tue Jul 28 05:20:49.991857 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/www/phpinfo.php"] [unique_id "amggEbb3Hg56MtJU4vyDCAAAAQU"]
[Tue Jul 28 05:20:49.992827 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/www/phpinfo.php"] [unique_id "amggEbb3Hg56MtJU4vyDCAAAAQU"]
[Tue Jul 28 05:20:49.993450 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/www/phpinfo.php"] [unique_id "amggEbb3Hg56MtJU4vyDCAAAAQU"]
[Tue Jul 28 05:20:50.277052 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "amggErb3Hg56MtJU4vyDDAAAARM"]
[Tue Jul 28 05:20:50.277878 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "amggErb3Hg56MtJU4vyDDAAAARM"]
[Tue Jul 28 05:20:50.278478 2026] [:error] [pid 711:tid 139944513165056] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "amggErb3Hg56MtJU4vyDDAAAARM"]
[Tue Jul 28 05:20:50.557826 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/public_html/phpinfo.php"] [unique_id "amggErb3Hg56MtJU4vyDDwAAAQA"]
[Tue Jul 28 05:20:50.558940 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/public_html/phpinfo.php"] [unique_id "amggErb3Hg56MtJU4vyDDwAAAQA"]
[Tue Jul 28 05:20:50.559493 2026] [:error] [pid 711:tid 139944747431680] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/public_html/phpinfo.php"] [unique_id "amggErb3Hg56MtJU4vyDDwAAAQA"]
[Tue Jul 28 05:20:50.838976 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/site/phpinfo.php"] [unique_id "amggErb3Hg56MtJU4vyDFQAAAQQ"]
[Tue Jul 28 05:20:50.839982 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/site/phpinfo.php"] [unique_id "amggErb3Hg56MtJU4vyDFQAAAQQ"]
[Tue Jul 28 05:20:50.840740 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/site/phpinfo.php"] [unique_id "amggErb3Hg56MtJU4vyDFQAAAQQ"]
[Tue Jul 28 05:20:51.117487 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/docs/phpinfo.php"] [unique_id "amggE7b3Hg56MtJU4vyDFwAAARc"]
[Tue Jul 28 05:20:51.118517 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/docs/phpinfo.php"] [unique_id "amggE7b3Hg56MtJU4vyDFwAAARc"]
[Tue Jul 28 05:20:51.126268 2026] [:error] [pid 711:tid 139944479594240] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/docs/phpinfo.php"] [unique_id "amggE7b3Hg56MtJU4vyDFwAAARc"]
[Tue Jul 28 05:20:51.412654 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "amggE7b3Hg56MtJU4vyDGQAAAQw"]
[Tue Jul 28 05:20:51.413528 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "amggE7b3Hg56MtJU4vyDGQAAAQw"]
[Tue Jul 28 05:20:51.414059 2026] [:error] [pid 711:tid 139944571913984] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "amggE7b3Hg56MtJU4vyDGQAAAQw"]
[Tue Jul 28 05:20:51.699919 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/administrator/phpinfo.php"] [unique_id "amggE7b3Hg56MtJU4vyDHgAAARU"]
[Tue Jul 28 05:20:51.700908 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/administrator/phpinfo.php"] [unique_id "amggE7b3Hg56MtJU4vyDHgAAARU"]
[Tue Jul 28 05:20:51.701486 2026] [:error] [pid 711:tid 139944496379648] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/administrator/phpinfo.php"] [unique_id "amggE7b3Hg56MtJU4vyDHgAAARU"]
[Tue Jul 28 05:20:51.980706 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/core/phpinfo.php"] [unique_id "amggE7b3Hg56MtJU4vyDIAAAAQQ"]
[Tue Jul 28 05:20:51.981612 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/core/phpinfo.php"] [unique_id "amggE7b3Hg56MtJU4vyDIAAAAQQ"]
[Tue Jul 28 05:20:51.982154 2026] [:error] [pid 711:tid 139944639055616] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/core/phpinfo.php"] [unique_id "amggE7b3Hg56MtJU4vyDIAAAAQQ"]
[Tue Jul 28 05:20:52.297524 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/includes/phpinfo.php"] [unique_id "amggFLb3Hg56MtJU4vyDJAAAAQU"]
[Tue Jul 28 05:20:52.298443 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/includes/phpinfo.php"] [unique_id "amggFLb3Hg56MtJU4vyDJAAAAQU"]
[Tue Jul 28 05:20:52.299015 2026] [:error] [pid 711:tid 139944630662912] [client 141.101.85.26:13308] [client 141.101.85.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/includes/phpinfo.php"] [unique_id "amggFLb3Hg56MtJU4vyDJAAAAQU"]
[Tue Jul 28 05:26:22.079193 2026] [:error] [pid 27697:tid 139944747431680] [client 172.71.103.41:12851] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amghXhkR7MhnM6j340aQOQAAAEA"]
[Tue Jul 28 05:26:22.080229 2026] [:error] [pid 27697:tid 139944747431680] [client 172.71.103.41:12851] [client 172.71.103.41] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amghXhkR7MhnM6j340aQOQAAAEA"]
[Tue Jul 28 05:26:22.080762 2026] [:error] [pid 27697:tid 139944747431680] [client 172.71.103.41:12851] [client 172.71.103.41] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amghXhkR7MhnM6j340aQOQAAAEA"]
[Tue Jul 28 05:26:22.081005 2026] [:error] [pid 27697:tid 139944747431680] [client 172.71.103.41:12851] [client 172.71.103.41] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amghXhkR7MhnM6j340aQOQAAAEA"]
[Tue Jul 28 05:35:51.012021 2026] [:error] [pid 28027:tid 139944605484800] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amgjl2zzpr4cNKr4fksGLAAAAMg"]
[Tue Jul 28 05:35:51.039674 2026] [:error] [pid 28027:tid 139944605484800] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amgjl2zzpr4cNKr4fksGLAAAAMg"]
[Tue Jul 28 05:35:51.040075 2026] [:error] [pid 28027:tid 139944605484800] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amgjl2zzpr4cNKr4fksGLAAAAMg"]
[Tue Jul 28 05:35:51.040160 2026] [:error] [pid 28027:tid 139944605484800] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amgjl2zzpr4cNKr4fksGLAAAAMg"]
[Tue Jul 28 05:35:52.112847 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amgjmGzzpr4cNKr4fksGMwAAAMA"]
[Tue Jul 28 05:35:52.113535 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amgjmGzzpr4cNKr4fksGMwAAAMA"]
[Tue Jul 28 05:35:52.113856 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amgjmGzzpr4cNKr4fksGMwAAAMA"]
[Tue Jul 28 05:35:52.113935 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amgjmGzzpr4cNKr4fksGMwAAAMA"]
[Tue Jul 28 05:35:52.435710 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sixxis.php"] [unique_id "amgjmGzzpr4cNKr4fksGNgAAANA"]
[Tue Jul 28 05:35:52.436467 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sixxis.php"] [unique_id "amgjmGzzpr4cNKr4fksGNgAAANA"]
[Tue Jul 28 05:35:52.436874 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sixxis.php"] [unique_id "amgjmGzzpr4cNKr4fksGNgAAANA"]
[Tue Jul 28 05:35:52.436957 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sixxis.php"] [unique_id "amgjmGzzpr4cNKr4fksGNgAAANA"]
[Tue Jul 28 05:35:52.473043 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/azz.php"] [unique_id "amgjmGzzpr4cNKr4fksGNwAAAM0"]
[Tue Jul 28 05:35:52.473686 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/azz.php"] [unique_id "amgjmGzzpr4cNKr4fksGNwAAAM0"]
[Tue Jul 28 05:35:52.474017 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/azz.php"] [unique_id "amgjmGzzpr4cNKr4fksGNwAAAM0"]
[Tue Jul 28 05:35:52.474097 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/azz.php"] [unique_id "amgjmGzzpr4cNKr4fksGNwAAAM0"]
[Tue Jul 28 05:35:52.595468 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/axc.php"] [unique_id "amgjmGzzpr4cNKr4fksGOAAAAM4"]
[Tue Jul 28 05:35:52.596138 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/axc.php"] [unique_id "amgjmGzzpr4cNKr4fksGOAAAAM4"]
[Tue Jul 28 05:35:52.596528 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/axc.php"] [unique_id "amgjmGzzpr4cNKr4fksGOAAAAM4"]
[Tue Jul 28 05:35:52.596608 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/axc.php"] [unique_id "amgjmGzzpr4cNKr4fksGOAAAAM4"]
[Tue Jul 28 05:35:52.632603 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/podplbusewluoyehvnhCdefault.php"] [unique_id "amgjmGzzpr4cNKr4fksGOgAAANQ"]
[Tue Jul 28 05:35:52.633324 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/podplbusewluoyehvnhCdefault.php"] [unique_id "amgjmGzzpr4cNKr4fksGOgAAANQ"]
[Tue Jul 28 05:35:52.633667 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/podplbusewluoyehvnhCdefault.php"] [unique_id "amgjmGzzpr4cNKr4fksGOgAAANQ"]
[Tue Jul 28 05:35:52.633748 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/podplbusewluoyehvnhCdefault.php"] [unique_id "amgjmGzzpr4cNKr4fksGOgAAANQ"]
[Tue Jul 28 05:35:52.727409 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/qlex1.php"] [unique_id "amgjmGzzpr4cNKr4fksGOwAAANY"]
[Tue Jul 28 05:35:52.728114 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/qlex1.php"] [unique_id "amgjmGzzpr4cNKr4fksGOwAAANY"]
[Tue Jul 28 05:35:52.728463 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/qlex1.php"] [unique_id "amgjmGzzpr4cNKr4fksGOwAAANY"]
[Tue Jul 28 05:35:52.728577 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/qlex1.php"] [unique_id "amgjmGzzpr4cNKr4fksGOwAAANY"]
[Tue Jul 28 05:35:52.806605 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dfre.php"] [unique_id "amgjmGzzpr4cNKr4fksGPQAAAMU"]
[Tue Jul 28 05:35:52.807201 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dfre.php"] [unique_id "amgjmGzzpr4cNKr4fksGPQAAAMU"]
[Tue Jul 28 05:35:52.807498 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/dfre.php"] [unique_id "amgjmGzzpr4cNKr4fksGPQAAAMU"]
[Tue Jul 28 05:35:52.807582 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dfre.php"] [unique_id "amgjmGzzpr4cNKr4fksGPQAAAMU"]
[Tue Jul 28 05:35:52.842352 2026] [:error] [pid 28027:tid 139944647448320] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-der.php"] [unique_id "amgjmGzzpr4cNKr4fksGPgAAAMM"]
[Tue Jul 28 05:35:52.843481 2026] [:error] [pid 28027:tid 139944647448320] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-der.php"] [unique_id "amgjmGzzpr4cNKr4fksGPgAAAMM"]
[Tue Jul 28 05:35:52.843994 2026] [:error] [pid 28027:tid 139944647448320] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-der.php"] [unique_id "amgjmGzzpr4cNKr4fksGPgAAAMM"]
[Tue Jul 28 05:35:52.844095 2026] [:error] [pid 28027:tid 139944647448320] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-der.php"] [unique_id "amgjmGzzpr4cNKr4fksGPgAAAMM"]
[Tue Jul 28 05:35:52.963262 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/reop1.php"] [unique_id "amgjmGzzpr4cNKr4fksGPwAAANE"]
[Tue Jul 28 05:35:52.963993 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/reop1.php"] [unique_id "amgjmGzzpr4cNKr4fksGPwAAANE"]
[Tue Jul 28 05:35:52.964323 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/reop1.php"] [unique_id "amgjmGzzpr4cNKr4fksGPwAAANE"]
[Tue Jul 28 05:35:52.964382 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/reop1.php"] [unique_id "amgjmGzzpr4cNKr4fksGPwAAANE"]
[Tue Jul 28 05:35:53.003339 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/solo1.php"] [unique_id "amgjmWzzpr4cNKr4fksGQQAAAMc"]
[Tue Jul 28 05:35:53.004427 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/solo1.php"] [unique_id "amgjmWzzpr4cNKr4fksGQQAAAMc"]
[Tue Jul 28 05:35:53.004892 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/solo1.php"] [unique_id "amgjmWzzpr4cNKr4fksGQQAAAMc"]
[Tue Jul 28 05:35:53.004992 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/solo1.php"] [unique_id "amgjmWzzpr4cNKr4fksGQQAAAMc"]
[Tue Jul 28 05:35:53.157713 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cu.php"] [unique_id "amgjmWzzpr4cNKr4fksGQgAAAMQ"]
[Tue Jul 28 05:35:53.158586 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cu.php"] [unique_id "amgjmWzzpr4cNKr4fksGQgAAAMQ"]
[Tue Jul 28 05:35:53.158958 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/cu.php"] [unique_id "amgjmWzzpr4cNKr4fksGQgAAAMQ"]
[Tue Jul 28 05:35:53.159044 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cu.php"] [unique_id "amgjmWzzpr4cNKr4fksGQgAAAMQ"]
[Tue Jul 28 05:35:53.314050 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/clasa99.php"] [unique_id "amgjmWzzpr4cNKr4fksGRQAAAMY"]
[Tue Jul 28 05:35:53.332464 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/clasa99.php"] [unique_id "amgjmWzzpr4cNKr4fksGRQAAAMY"]
[Tue Jul 28 05:35:53.333096 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/clasa99.php"] [unique_id "amgjmWzzpr4cNKr4fksGRQAAAMY"]
[Tue Jul 28 05:35:53.333215 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/clasa99.php"] [unique_id "amgjmWzzpr4cNKr4fksGRQAAAMY"]
[Tue Jul 28 05:35:53.373503 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-pp.php"] [unique_id "amgjmWzzpr4cNKr4fksGRwAAAMA"]
[Tue Jul 28 05:35:53.374350 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-pp.php"] [unique_id "amgjmWzzpr4cNKr4fksGRwAAAMA"]
[Tue Jul 28 05:35:53.374747 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-pp.php"] [unique_id "amgjmWzzpr4cNKr4fksGRwAAAMA"]
[Tue Jul 28 05:35:53.374828 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-pp.php"] [unique_id "amgjmWzzpr4cNKr4fksGRwAAAMA"]
[Tue Jul 28 05:35:53.441926 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/themes.php"] [unique_id "amgjmWzzpr4cNKr4fksGSAAAANI"]
[Tue Jul 28 05:35:53.442981 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/themes.php"] [unique_id "amgjmWzzpr4cNKr4fksGSAAAANI"]
[Tue Jul 28 05:35:53.443361 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/themes.php"] [unique_id "amgjmWzzpr4cNKr4fksGSAAAANI"]
[Tue Jul 28 05:35:53.443465 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/themes.php"] [unique_id "amgjmWzzpr4cNKr4fksGSAAAANI"]
[Tue Jul 28 05:35:53.478497 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/yanz.php"] [unique_id "amgjmWzzpr4cNKr4fksGSgAAAM0"]
[Tue Jul 28 05:35:53.479379 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/yanz.php"] [unique_id "amgjmWzzpr4cNKr4fksGSgAAAM0"]
[Tue Jul 28 05:35:53.479739 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/yanz.php"] [unique_id "amgjmWzzpr4cNKr4fksGSgAAAM0"]
[Tue Jul 28 05:35:53.479805 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/yanz.php"] [unique_id "amgjmWzzpr4cNKr4fksGSgAAAM0"]
[Tue Jul 28 05:35:53.550065 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dass.php"] [unique_id "amgjmWzzpr4cNKr4fksGTAAAAMk"]
[Tue Jul 28 05:35:53.551037 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dass.php"] [unique_id "amgjmWzzpr4cNKr4fksGTAAAAMk"]
[Tue Jul 28 05:35:53.551484 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/dass.php"] [unique_id "amgjmWzzpr4cNKr4fksGTAAAAMk"]
[Tue Jul 28 05:35:53.551613 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dass.php"] [unique_id "amgjmWzzpr4cNKr4fksGTAAAAMk"]
[Tue Jul 28 05:35:53.633821 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/base.php"] [unique_id "amgjmWzzpr4cNKr4fksGTwAAANQ"]
[Tue Jul 28 05:35:53.634760 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/base.php"] [unique_id "amgjmWzzpr4cNKr4fksGTwAAANQ"]
[Tue Jul 28 05:35:53.635066 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/base.php"] [unique_id "amgjmWzzpr4cNKr4fksGTwAAANQ"]
[Tue Jul 28 05:35:53.635125 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/base.php"] [unique_id "amgjmWzzpr4cNKr4fksGTwAAANQ"]
[Tue Jul 28 05:35:53.720630 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/1xmomo.php"] [unique_id "amgjmWzzpr4cNKr4fksGUAAAANM"]
[Tue Jul 28 05:35:53.721453 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/1xmomo.php"] [unique_id "amgjmWzzpr4cNKr4fksGUAAAANM"]
[Tue Jul 28 05:35:53.721864 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/1xmomo.php"] [unique_id "amgjmWzzpr4cNKr4fksGUAAAANM"]
[Tue Jul 28 05:35:53.721946 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/1xmomo.php"] [unique_id "amgjmWzzpr4cNKr4fksGUAAAANM"]
[Tue Jul 28 05:35:53.836251 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes//class-snoopye_wso.php"] [unique_id "amgjmWzzpr4cNKr4fksGUQAAANY"]
[Tue Jul 28 05:35:53.836854 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/class-snoopye_wso.php"] [unique_id "amgjmWzzpr4cNKr4fksGUQAAANY"]
[Tue Jul 28 05:35:53.837166 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/class-snoopye_wso.php"] [unique_id "amgjmWzzpr4cNKr4fksGUQAAANY"]
[Tue Jul 28 05:35:53.837224 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/class-snoopye_wso.php"] [unique_id "amgjmWzzpr4cNKr4fksGUQAAANY"]
[Tue Jul 28 05:35:53.875170 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/unity.php"] [unique_id "amgjmWzzpr4cNKr4fksGUgAAAMU"]
[Tue Jul 28 05:35:53.875787 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/unity.php"] [unique_id "amgjmWzzpr4cNKr4fksGUgAAAMU"]
[Tue Jul 28 05:35:53.876059 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/unity.php"] [unique_id "amgjmWzzpr4cNKr4fksGUgAAAMU"]
[Tue Jul 28 05:35:53.876126 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/unity.php"] [unique_id "amgjmWzzpr4cNKr4fksGUgAAAMU"]
[Tue Jul 28 05:35:53.987274 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sitemap.php"] [unique_id "amgjmWzzpr4cNKr4fksGVAAAAMw"]
[Tue Jul 28 05:35:53.987719 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sitemap.php"] [unique_id "amgjmWzzpr4cNKr4fksGVAAAAMw"]
[Tue Jul 28 05:35:53.987939 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sitemap.php"] [unique_id "amgjmWzzpr4cNKr4fksGVAAAAMw"]
[Tue Jul 28 05:35:53.987987 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sitemap.php"] [unique_id "amgjmWzzpr4cNKr4fksGVAAAAMw"]
[Tue Jul 28 05:35:54.022322 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-conflg.php"] [unique_id "amgjmmzzpr4cNKr4fksGVQAAAMs"]
[Tue Jul 28 05:35:54.023082 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-conflg.php"] [unique_id "amgjmmzzpr4cNKr4fksGVQAAAMs"]
[Tue Jul 28 05:35:54.023351 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-conflg.php"] [unique_id "amgjmmzzpr4cNKr4fksGVQAAAMs"]
[Tue Jul 28 05:35:54.023428 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-conflg.php"] [unique_id "amgjmmzzpr4cNKr4fksGVQAAAMs"]
[Tue Jul 28 05:35:54.219907 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known//checkbox.php"] [unique_id "amgjmmzzpr4cNKr4fksGWAAAAM8"]
[Tue Jul 28 05:35:54.221010 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/checkbox.php"] [unique_id "amgjmmzzpr4cNKr4fksGWAAAAM8"]
[Tue Jul 28 05:35:54.221491 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.well-known/checkbox.php"] [unique_id "amgjmmzzpr4cNKr4fksGWAAAAM8"]
[Tue Jul 28 05:35:54.221646 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/checkbox.php"] [unique_id "amgjmmzzpr4cNKr4fksGWAAAAM8"]
[Tue Jul 28 05:35:54.541020 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/rvixt.php"] [unique_id "amgjmmzzpr4cNKr4fksGWgAAAMA"]
[Tue Jul 28 05:35:54.545889 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/rvixt.php"] [unique_id "amgjmmzzpr4cNKr4fksGWgAAAMA"]
[Tue Jul 28 05:35:54.546298 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/rvixt.php"] [unique_id "amgjmmzzpr4cNKr4fksGWgAAAMA"]
[Tue Jul 28 05:35:54.546382 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/rvixt.php"] [unique_id "amgjmmzzpr4cNKr4fksGWgAAAMA"]
[Tue Jul 28 05:35:54.582145 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/issst.php"] [unique_id "amgjmmzzpr4cNKr4fksGWwAAAME"]
[Tue Jul 28 05:35:54.582870 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/issst.php"] [unique_id "amgjmmzzpr4cNKr4fksGWwAAAME"]
[Tue Jul 28 05:35:54.583149 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/issst.php"] [unique_id "amgjmmzzpr4cNKr4fksGWwAAAME"]
[Tue Jul 28 05:35:54.583208 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/issst.php"] [unique_id "amgjmmzzpr4cNKr4fksGWwAAAME"]
[Tue Jul 28 05:35:54.783236 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/min.php"] [unique_id "amgjmmzzpr4cNKr4fksGXgAAANQ"]
[Tue Jul 28 05:35:54.784006 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/min.php"] [unique_id "amgjmmzzpr4cNKr4fksGXgAAANQ"]
[Tue Jul 28 05:35:54.784325 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/min.php"] [unique_id "amgjmmzzpr4cNKr4fksGXgAAANQ"]
[Tue Jul 28 05:35:54.784385 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/min.php"] [unique_id "amgjmmzzpr4cNKr4fksGXgAAANQ"]
[Tue Jul 28 05:35:54.847214 2026] [:error] [pid 28027:tid 139944588699392] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/89wNbl.php"] [unique_id "amgjmmzzpr4cNKr4fksGYAAAAMo"]
[Tue Jul 28 05:35:54.848006 2026] [:error] [pid 28027:tid 139944588699392] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/89wNbl.php"] [unique_id "amgjmmzzpr4cNKr4fksGYAAAAMo"]
[Tue Jul 28 05:35:54.848378 2026] [:error] [pid 28027:tid 139944588699392] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/89wNbl.php"] [unique_id "amgjmmzzpr4cNKr4fksGYAAAAMo"]
[Tue Jul 28 05:35:54.848487 2026] [:error] [pid 28027:tid 139944588699392] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/89wNbl.php"] [unique_id "amgjmmzzpr4cNKr4fksGYAAAAMo"]
[Tue Jul 28 05:35:54.913149 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/0okj.php"] [unique_id "amgjmmzzpr4cNKr4fksGYQAAAMI"]
[Tue Jul 28 05:35:54.913649 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/0okj.php"] [unique_id "amgjmmzzpr4cNKr4fksGYQAAAMI"]
[Tue Jul 28 05:35:54.913903 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/0okj.php"] [unique_id "amgjmmzzpr4cNKr4fksGYQAAAMI"]
[Tue Jul 28 05:35:54.913952 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/0okj.php"] [unique_id "amgjmmzzpr4cNKr4fksGYQAAAMI"]
[Tue Jul 28 05:35:55.008748 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fffm.php"] [unique_id "amgjm2zzpr4cNKr4fksGYwAAAMU"]
[Tue Jul 28 05:35:55.009620 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fffm.php"] [unique_id "amgjm2zzpr4cNKr4fksGYwAAAMU"]
[Tue Jul 28 05:35:55.021511 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fffm.php"] [unique_id "amgjm2zzpr4cNKr4fksGYwAAAMU"]
[Tue Jul 28 05:35:55.021680 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/fffm.php"] [unique_id "amgjm2zzpr4cNKr4fksGYwAAAMU"]
[Tue Jul 28 05:35:55.126366 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ls.php"] [unique_id "amgjm2zzpr4cNKr4fksGZAAAANA"]
[Tue Jul 28 05:35:55.126999 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ls.php"] [unique_id "amgjm2zzpr4cNKr4fksGZAAAANA"]
[Tue Jul 28 05:35:55.127285 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ls.php"] [unique_id "amgjm2zzpr4cNKr4fksGZAAAANA"]
[Tue Jul 28 05:35:55.127339 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ls.php"] [unique_id "amgjm2zzpr4cNKr4fksGZAAAANA"]
[Tue Jul 28 05:35:55.162702 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/q7lhrgzoo7ijhnkcedq2Cdefault.php"] [unique_id "amgjm2zzpr4cNKr4fksGZQAAAMw"]
[Tue Jul 28 05:35:55.163272 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/q7lhrgzoo7ijhnkcedq2Cdefault.php"] [unique_id "amgjm2zzpr4cNKr4fksGZQAAAMw"]
[Tue Jul 28 05:35:55.163571 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/q7lhrgzoo7ijhnkcedq2Cdefault.php"] [unique_id "amgjm2zzpr4cNKr4fksGZQAAAMw"]
[Tue Jul 28 05:35:55.163637 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/q7lhrgzoo7ijhnkcedq2Cdefault.php"] [unique_id "amgjm2zzpr4cNKr4fksGZQAAAMw"]
[Tue Jul 28 05:35:55.277764 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-wlx.php"] [unique_id "amgjm2zzpr4cNKr4fksGZgAAANg"]
[Tue Jul 28 05:35:55.278375 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-wlx.php"] [unique_id "amgjm2zzpr4cNKr4fksGZgAAANg"]
[Tue Jul 28 05:35:55.278681 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-wlx.php"] [unique_id "amgjm2zzpr4cNKr4fksGZgAAANg"]
[Tue Jul 28 05:35:55.278738 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-wlx.php"] [unique_id "amgjm2zzpr4cNKr4fksGZgAAANg"]
[Tue Jul 28 05:35:55.443685 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/Nx1.php"] [unique_id "amgjm2zzpr4cNKr4fksGaAAAAM8"]
[Tue Jul 28 05:35:55.444375 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/Nx1.php"] [unique_id "amgjm2zzpr4cNKr4fksGaAAAAM8"]
[Tue Jul 28 05:35:55.444739 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/Nx1.php"] [unique_id "amgjm2zzpr4cNKr4fksGaAAAAM8"]
[Tue Jul 28 05:35:55.444804 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/Nx1.php"] [unique_id "amgjm2zzpr4cNKr4fksGaAAAAM8"]
[Tue Jul 28 05:35:55.501447 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/blog/82.php"] [unique_id "amgjm2zzpr4cNKr4fksGagAAAMY"]
[Tue Jul 28 05:35:55.502482 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/blog/82.php"] [unique_id "amgjm2zzpr4cNKr4fksGagAAAMY"]
[Tue Jul 28 05:35:55.502912 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/blog/82.php"] [unique_id "amgjm2zzpr4cNKr4fksGagAAAMY"]
[Tue Jul 28 05:35:55.503008 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/blog/82.php"] [unique_id "amgjm2zzpr4cNKr4fksGagAAAMY"]
[Tue Jul 28 05:35:55.537116 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wplogbak.php"] [unique_id "amgjm2zzpr4cNKr4fksGbQAAANc"]
[Tue Jul 28 05:35:55.537868 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wplogbak.php"] [unique_id "amgjm2zzpr4cNKr4fksGbQAAANc"]
[Tue Jul 28 05:35:55.538184 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wplogbak.php"] [unique_id "amgjm2zzpr4cNKr4fksGbQAAANc"]
[Tue Jul 28 05:35:55.538244 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wplogbak.php"] [unique_id "amgjm2zzpr4cNKr4fksGbQAAANc"]
[Tue Jul 28 05:35:55.886235 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/alr.php"] [unique_id "amgjm2zzpr4cNKr4fksGcAAAAMQ"]
[Tue Jul 28 05:35:55.887174 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/alr.php"] [unique_id "amgjm2zzpr4cNKr4fksGcAAAAMQ"]
[Tue Jul 28 05:35:55.887638 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/alr.php"] [unique_id "amgjm2zzpr4cNKr4fksGcAAAAMQ"]
[Tue Jul 28 05:35:55.887738 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/alr.php"] [unique_id "amgjm2zzpr4cNKr4fksGcAAAAMQ"]
[Tue Jul 28 05:35:56.543654 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/as.php"] [unique_id "amgjnGzzpr4cNKr4fksGdgAAAMk"]
[Tue Jul 28 05:35:56.544605 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/as.php"] [unique_id "amgjnGzzpr4cNKr4fksGdgAAAMk"]
[Tue Jul 28 05:35:56.545021 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/as.php"] [unique_id "amgjnGzzpr4cNKr4fksGdgAAAMk"]
[Tue Jul 28 05:35:56.545109 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/as.php"] [unique_id "amgjnGzzpr4cNKr4fksGdgAAAMk"]
[Tue Jul 28 05:35:56.784481 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-signup.php"] [unique_id "amgjnGzzpr4cNKr4fksGeQAAANI"]
[Tue Jul 28 05:35:56.785042 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-signup.php"] [unique_id "amgjnGzzpr4cNKr4fksGeQAAANI"]
[Tue Jul 28 05:35:56.785285 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-signup.php"] [unique_id "amgjnGzzpr4cNKr4fksGeQAAANI"]
[Tue Jul 28 05:35:56.785344 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-signup.php"] [unique_id "amgjnGzzpr4cNKr4fksGeQAAANI"]
[Tue Jul 28 05:35:57.071180 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-link-szoppm.php"] [unique_id "amgjnWzzpr4cNKr4fksGfQAAAM4"]
[Tue Jul 28 05:35:57.072090 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-link-szoppm.php"] [unique_id "amgjnWzzpr4cNKr4fksGfQAAAM4"]
[Tue Jul 28 05:35:57.072385 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-link-szoppm.php"] [unique_id "amgjnWzzpr4cNKr4fksGfQAAAM4"]
[Tue Jul 28 05:35:57.072472 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-link-szoppm.php"] [unique_id "amgjnWzzpr4cNKr4fksGfQAAAM4"]
[Tue Jul 28 05:35:57.175434 2026] [:error] [pid 28027:tid 139944647448320] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bd.php"] [unique_id "amgjnWzzpr4cNKr4fksGfgAAAMM"]
[Tue Jul 28 05:35:57.176241 2026] [:error] [pid 28027:tid 139944647448320] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bd.php"] [unique_id "amgjnWzzpr4cNKr4fksGfgAAAMM"]
[Tue Jul 28 05:35:57.176661 2026] [:error] [pid 28027:tid 139944647448320] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bd.php"] [unique_id "amgjnWzzpr4cNKr4fksGfgAAAMM"]
[Tue Jul 28 05:35:57.176746 2026] [:error] [pid 28027:tid 139944647448320] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bd.php"] [unique_id "amgjnWzzpr4cNKr4fksGfgAAAMM"]
[Tue Jul 28 05:35:57.256331 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/scxy.php"] [unique_id "amgjnWzzpr4cNKr4fksGfwAAANc"]
[Tue Jul 28 05:35:57.257112 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/scxy.php"] [unique_id "amgjnWzzpr4cNKr4fksGfwAAANc"]
[Tue Jul 28 05:35:57.257520 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/scxy.php"] [unique_id "amgjnWzzpr4cNKr4fksGfwAAANc"]
[Tue Jul 28 05:35:57.257619 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/scxy.php"] [unique_id "amgjnWzzpr4cNKr4fksGfwAAANc"]
[Tue Jul 28 05:35:57.306604 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xda.php"] [unique_id "amgjnWzzpr4cNKr4fksGgAAAANE"]
[Tue Jul 28 05:35:57.307950 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xda.php"] [unique_id "amgjnWzzpr4cNKr4fksGgAAAANE"]
[Tue Jul 28 05:35:57.308375 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/xda.php"] [unique_id "amgjnWzzpr4cNKr4fksGgAAAANE"]
[Tue Jul 28 05:35:57.308507 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xda.php"] [unique_id "amgjnWzzpr4cNKr4fksGgAAAANE"]
[Tue Jul 28 05:35:57.505408 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/000.php"] [unique_id "amgjnWzzpr4cNKr4fksGgwAAAMQ"]
[Tue Jul 28 05:35:57.506084 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/000.php"] [unique_id "amgjnWzzpr4cNKr4fksGgwAAAMQ"]
[Tue Jul 28 05:35:57.506348 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/000.php"] [unique_id "amgjnWzzpr4cNKr4fksGgwAAAMQ"]
[Tue Jul 28 05:35:57.506440 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/000.php"] [unique_id "amgjnWzzpr4cNKr4fksGgwAAAMQ"]
[Tue Jul 28 05:35:57.697972 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-ppoxua4.php"] [unique_id "amgjnWzzpr4cNKr4fksGhgAAAMU"]
[Tue Jul 28 05:35:57.698907 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-ppoxua4.php"] [unique_id "amgjnWzzpr4cNKr4fksGhgAAAMU"]
[Tue Jul 28 05:35:57.699302 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-ppoxua4.php"] [unique_id "amgjnWzzpr4cNKr4fksGhgAAAMU"]
[Tue Jul 28 05:35:57.699412 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-ppoxua4.php"] [unique_id "amgjnWzzpr4cNKr4fksGhgAAAMU"]
[Tue Jul 28 05:35:57.739973 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/green1.php"] [unique_id "amgjnWzzpr4cNKr4fksGhwAAAMA"]
[Tue Jul 28 05:35:57.740706 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/green1.php"] [unique_id "amgjnWzzpr4cNKr4fksGhwAAAMA"]
[Tue Jul 28 05:35:57.741010 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/green1.php"] [unique_id "amgjnWzzpr4cNKr4fksGhwAAAMA"]
[Tue Jul 28 05:35:57.741075 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/green1.php"] [unique_id "amgjnWzzpr4cNKr4fksGhwAAAMA"]
[Tue Jul 28 05:35:57.781369 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/petx.php"] [unique_id "amgjnWzzpr4cNKr4fksGiAAAAMc"]
[Tue Jul 28 05:35:57.782005 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/petx.php"] [unique_id "amgjnWzzpr4cNKr4fksGiAAAAMc"]
[Tue Jul 28 05:35:57.782291 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/petx.php"] [unique_id "amgjnWzzpr4cNKr4fksGiAAAAMc"]
[Tue Jul 28 05:35:57.782347 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/petx.php"] [unique_id "amgjnWzzpr4cNKr4fksGiAAAAMc"]
[Tue Jul 28 05:35:57.841714 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/Bean.php"] [unique_id "amgjnWzzpr4cNKr4fksGiQAAANQ"]
[Tue Jul 28 05:35:57.842601 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/Bean.php"] [unique_id "amgjnWzzpr4cNKr4fksGiQAAANQ"]
[Tue Jul 28 05:35:57.842984 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/Bean.php"] [unique_id "amgjnWzzpr4cNKr4fksGiQAAANQ"]
[Tue Jul 28 05:35:57.843063 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/Bean.php"] [unique_id "amgjnWzzpr4cNKr4fksGiQAAANQ"]
[Tue Jul 28 05:35:57.933710 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/w1px.php"] [unique_id "amgjnWzzpr4cNKr4fksGigAAAMI"]
[Tue Jul 28 05:35:57.934345 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/w1px.php"] [unique_id "amgjnWzzpr4cNKr4fksGigAAAMI"]
[Tue Jul 28 05:35:57.934650 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/w1px.php"] [unique_id "amgjnWzzpr4cNKr4fksGigAAAMI"]
[Tue Jul 28 05:35:57.934706 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/w1px.php"] [unique_id "amgjnWzzpr4cNKr4fksGigAAAMI"]
[Tue Jul 28 05:35:58.038905 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/fonts/send.php"] [unique_id "amgjnmzzpr4cNKr4fksGiwAAAM8"]
[Tue Jul 28 05:35:58.040164 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/fonts/send.php"] [unique_id "amgjnmzzpr4cNKr4fksGiwAAAM8"]
[Tue Jul 28 05:35:58.040673 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/fonts/send.php"] [unique_id "amgjnmzzpr4cNKr4fksGiwAAAM8"]
[Tue Jul 28 05:35:58.040825 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/fonts/send.php"] [unique_id "amgjnmzzpr4cNKr4fksGiwAAAM8"]
[Tue Jul 28 05:36:01.744080 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amgjoWzzpr4cNKr4fksGnwAAAMk"]
[Tue Jul 28 05:36:01.745219 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amgjoWzzpr4cNKr4fksGnwAAAMk"]
[Tue Jul 28 05:36:01.745708 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amgjoWzzpr4cNKr4fksGnwAAAMk"]
[Tue Jul 28 05:36:01.745788 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amgjoWzzpr4cNKr4fksGnwAAAMk"]
[Tue Jul 28 05:36:01.805640 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/uploads/wpxadmin.php"] [unique_id "amgjoWzzpr4cNKr4fksGoAAAAMI"]
[Tue Jul 28 05:36:01.806334 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/uploads/wpxadmin.php"] [unique_id "amgjoWzzpr4cNKr4fksGoAAAAMI"]
[Tue Jul 28 05:36:01.806674 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/uploads/wpxadmin.php"] [unique_id "amgjoWzzpr4cNKr4fksGoAAAAMI"]
[Tue Jul 28 05:36:01.806746 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/uploads/wpxadmin.php"] [unique_id "amgjoWzzpr4cNKr4fksGoAAAAMI"]
[Tue Jul 28 05:36:01.874635 2026] [:error] [pid 28027:tid 139944605484800] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file6.php"] [unique_id "amgjoWzzpr4cNKr4fksGogAAAMg"]
[Tue Jul 28 05:36:01.905805 2026] [:error] [pid 28027:tid 139944605484800] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file6.php"] [unique_id "amgjoWzzpr4cNKr4fksGogAAAMg"]
[Tue Jul 28 05:36:01.906469 2026] [:error] [pid 28027:tid 139944605484800] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file6.php"] [unique_id "amgjoWzzpr4cNKr4fksGogAAAMg"]
[Tue Jul 28 05:36:01.906618 2026] [:error] [pid 28027:tid 139944605484800] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file6.php"] [unique_id "amgjoWzzpr4cNKr4fksGogAAAMg"]
[Tue Jul 28 05:36:02.003355 2026] [:error] [pid 28027:tid 139944588699392] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file1.php"] [unique_id "amgjomzzpr4cNKr4fksGowAAAMo"]
[Tue Jul 28 05:36:02.005447 2026] [:error] [pid 28027:tid 139944588699392] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file1.php"] [unique_id "amgjomzzpr4cNKr4fksGowAAAMo"]
[Tue Jul 28 05:36:02.006410 2026] [:error] [pid 28027:tid 139944588699392] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file1.php"] [unique_id "amgjomzzpr4cNKr4fksGowAAAMo"]
[Tue Jul 28 05:36:02.006675 2026] [:error] [pid 28027:tid 139944588699392] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file1.php"] [unique_id "amgjomzzpr4cNKr4fksGowAAAMo"]
[Tue Jul 28 05:36:02.232606 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/appt.php"] [unique_id "amgjomzzpr4cNKr4fksGpQAAANI"]
[Tue Jul 28 05:36:02.233406 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/appt.php"] [unique_id "amgjomzzpr4cNKr4fksGpQAAANI"]
[Tue Jul 28 05:36:02.233791 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/appt.php"] [unique_id "amgjomzzpr4cNKr4fksGpQAAANI"]
[Tue Jul 28 05:36:02.233882 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/appt.php"] [unique_id "amgjomzzpr4cNKr4fksGpQAAANI"]
[Tue Jul 28 05:36:02.414703 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/rithin.php"] [unique_id "amgjomzzpr4cNKr4fksGpgAAANU"]
[Tue Jul 28 05:36:02.415655 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/rithin.php"] [unique_id "amgjomzzpr4cNKr4fksGpgAAANU"]
[Tue Jul 28 05:36:02.416039 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/rithin.php"] [unique_id "amgjomzzpr4cNKr4fksGpgAAANU"]
[Tue Jul 28 05:36:02.416135 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/rithin.php"] [unique_id "amgjomzzpr4cNKr4fksGpgAAANU"]
[Tue Jul 28 05:36:02.461688 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fi22.php"] [unique_id "amgjomzzpr4cNKr4fksGpwAAAM4"]
[Tue Jul 28 05:36:02.462597 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fi22.php"] [unique_id "amgjomzzpr4cNKr4fksGpwAAAM4"]
[Tue Jul 28 05:36:02.463012 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fi22.php"] [unique_id "amgjomzzpr4cNKr4fksGpwAAAM4"]
[Tue Jul 28 05:36:02.463109 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/fi22.php"] [unique_id "amgjomzzpr4cNKr4fksGpwAAAM4"]
[Tue Jul 28 05:36:02.521682 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-xmlsia.php"] [unique_id "amgjomzzpr4cNKr4fksGqAAAANA"]
[Tue Jul 28 05:36:02.522599 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-xmlsia.php"] [unique_id "amgjomzzpr4cNKr4fksGqAAAANA"]
[Tue Jul 28 05:36:02.522996 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-xmlsia.php"] [unique_id "amgjomzzpr4cNKr4fksGqAAAANA"]
[Tue Jul 28 05:36:02.523085 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-xmlsia.php"] [unique_id "amgjomzzpr4cNKr4fksGqAAAANA"]
[Tue Jul 28 05:36:02.599341 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/trusj18.php"] [unique_id "amgjomzzpr4cNKr4fksGqgAAANg"]
[Tue Jul 28 05:36:02.600310 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/trusj18.php"] [unique_id "amgjomzzpr4cNKr4fksGqgAAANg"]
[Tue Jul 28 05:36:02.600760 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/trusj18.php"] [unique_id "amgjomzzpr4cNKr4fksGqgAAANg"]
[Tue Jul 28 05:36:02.600852 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/trusj18.php"] [unique_id "amgjomzzpr4cNKr4fksGqgAAANg"]
[Tue Jul 28 05:36:02.697650 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/classwithtostring.php"] [unique_id "amgjomzzpr4cNKr4fksGrAAAANE"]
[Tue Jul 28 05:36:02.698499 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/classwithtostring.php"] [unique_id "amgjomzzpr4cNKr4fksGrAAAANE"]
[Tue Jul 28 05:36:02.698909 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/classwithtostring.php"] [unique_id "amgjomzzpr4cNKr4fksGrAAAANE"]
[Tue Jul 28 05:36:02.699152 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/classwithtostring.php"] [unique_id "amgjomzzpr4cNKr4fksGrAAAANE"]
[Tue Jul 28 05:36:02.743773 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/drykl.php"] [unique_id "amgjomzzpr4cNKr4fksGrgAAAMQ"]
[Tue Jul 28 05:36:02.744673 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/drykl.php"] [unique_id "amgjomzzpr4cNKr4fksGrgAAAMQ"]
[Tue Jul 28 05:36:02.745068 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/drykl.php"] [unique_id "amgjomzzpr4cNKr4fksGrgAAAMQ"]
[Tue Jul 28 05:36:02.745171 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/drykl.php"] [unique_id "amgjomzzpr4cNKr4fksGrgAAAMQ"]
[Tue Jul 28 05:36:02.779583 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fpr4.php"] [unique_id "amgjomzzpr4cNKr4fksGrwAAAMY"]
[Tue Jul 28 05:36:02.780323 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fpr4.php"] [unique_id "amgjomzzpr4cNKr4fksGrwAAAMY"]
[Tue Jul 28 05:36:02.780687 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fpr4.php"] [unique_id "amgjomzzpr4cNKr4fksGrwAAAMY"]
[Tue Jul 28 05:36:02.780776 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/fpr4.php"] [unique_id "amgjomzzpr4cNKr4fksGrwAAAMY"]
[Tue Jul 28 05:36:02.815293 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/orange3.php"] [unique_id "amgjomzzpr4cNKr4fksGsAAAAMU"]
[Tue Jul 28 05:36:02.815898 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/orange3.php"] [unique_id "amgjomzzpr4cNKr4fksGsAAAAMU"]
[Tue Jul 28 05:36:02.816161 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/orange3.php"] [unique_id "amgjomzzpr4cNKr4fksGsAAAAMU"]
[Tue Jul 28 05:36:02.816217 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/orange3.php"] [unique_id "amgjomzzpr4cNKr4fksGsAAAAMU"]
[Tue Jul 28 05:36:02.868332 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/harvestry.php"] [unique_id "amgjomzzpr4cNKr4fksGsQAAANc"]
[Tue Jul 28 05:36:02.868927 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/harvestry.php"] [unique_id "amgjomzzpr4cNKr4fksGsQAAANc"]
[Tue Jul 28 05:36:02.869208 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/harvestry.php"] [unique_id "amgjomzzpr4cNKr4fksGsQAAANc"]
[Tue Jul 28 05:36:02.869261 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/harvestry.php"] [unique_id "amgjomzzpr4cNKr4fksGsQAAANc"]
[Tue Jul 28 05:36:02.973218 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sump3.php"] [unique_id "amgjomzzpr4cNKr4fksGsgAAAMA"]
[Tue Jul 28 05:36:02.974845 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sump3.php"] [unique_id "amgjomzzpr4cNKr4fksGsgAAAMA"]
[Tue Jul 28 05:36:02.975571 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sump3.php"] [unique_id "amgjomzzpr4cNKr4fksGsgAAAMA"]
[Tue Jul 28 05:36:02.975775 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sump3.php"] [unique_id "amgjomzzpr4cNKr4fksGsgAAAMA"]
[Tue Jul 28 05:36:03.044540 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/pocenuldrvqm0cg5cna7iCdefault.php"] [unique_id "amgjo2zzpr4cNKr4fksGswAAAMw"]
[Tue Jul 28 05:36:03.045310 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/pocenuldrvqm0cg5cna7iCdefault.php"] [unique_id "amgjo2zzpr4cNKr4fksGswAAAMw"]
[Tue Jul 28 05:36:03.045640 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/pocenuldrvqm0cg5cna7iCdefault.php"] [unique_id "amgjo2zzpr4cNKr4fksGswAAAMw"]
[Tue Jul 28 05:36:03.045708 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/pocenuldrvqm0cg5cna7iCdefault.php"] [unique_id "amgjo2zzpr4cNKr4fksGswAAAMw"]
[Tue Jul 28 05:36:03.102851 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/x123.php"] [unique_id "amgjo2zzpr4cNKr4fksGtQAAAMk"]
[Tue Jul 28 05:36:03.103967 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/x123.php"] [unique_id "amgjo2zzpr4cNKr4fksGtQAAAMk"]
[Tue Jul 28 05:36:03.104604 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/x123.php"] [unique_id "amgjo2zzpr4cNKr4fksGtQAAAMk"]
[Tue Jul 28 05:36:03.104734 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/x123.php"] [unique_id "amgjo2zzpr4cNKr4fksGtQAAAMk"]
[Tue Jul 28 05:36:03.301251 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ssypu.php"] [unique_id "amgjo2zzpr4cNKr4fksGtwAAANM"]
[Tue Jul 28 05:36:03.302112 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ssypu.php"] [unique_id "amgjo2zzpr4cNKr4fksGtwAAANM"]
[Tue Jul 28 05:36:03.302517 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ssypu.php"] [unique_id "amgjo2zzpr4cNKr4fksGtwAAANM"]
[Tue Jul 28 05:36:03.302616 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ssypu.php"] [unique_id "amgjo2zzpr4cNKr4fksGtwAAANM"]
[Tue Jul 28 05:36:03.343957 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file3.php"] [unique_id "amgjo2zzpr4cNKr4fksGuAAAANI"]
[Tue Jul 28 05:36:03.345221 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file3.php"] [unique_id "amgjo2zzpr4cNKr4fksGuAAAANI"]
[Tue Jul 28 05:36:03.345768 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file3.php"] [unique_id "amgjo2zzpr4cNKr4fksGuAAAANI"]
[Tue Jul 28 05:36:03.345893 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file3.php"] [unique_id "amgjo2zzpr4cNKr4fksGuAAAANI"]
[Tue Jul 28 05:36:03.497806 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cok.php"] [unique_id "amgjo2zzpr4cNKr4fksGugAAANU"]
[Tue Jul 28 05:36:03.498582 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cok.php"] [unique_id "amgjo2zzpr4cNKr4fksGugAAANU"]
[Tue Jul 28 05:36:03.498920 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/cok.php"] [unique_id "amgjo2zzpr4cNKr4fksGugAAANU"]
[Tue Jul 28 05:36:03.498991 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cok.php"] [unique_id "amgjo2zzpr4cNKr4fksGugAAANU"]
[Tue Jul 28 05:36:03.553629 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-at.php"] [unique_id "amgjo2zzpr4cNKr4fksGvAAAAME"]
[Tue Jul 28 05:36:03.554385 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-at.php"] [unique_id "amgjo2zzpr4cNKr4fksGvAAAAME"]
[Tue Jul 28 05:36:03.554765 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-at.php"] [unique_id "amgjo2zzpr4cNKr4fksGvAAAAME"]
[Tue Jul 28 05:36:03.554833 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-at.php"] [unique_id "amgjo2zzpr4cNKr4fksGvAAAAME"]
[Tue Jul 28 05:36:03.626807 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/trusj15.php"] [unique_id "amgjo2zzpr4cNKr4fksGvQAAANA"]
[Tue Jul 28 05:36:03.627527 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/trusj15.php"] [unique_id "amgjo2zzpr4cNKr4fksGvQAAANA"]
[Tue Jul 28 05:36:03.627935 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/trusj15.php"] [unique_id "amgjo2zzpr4cNKr4fksGvQAAANA"]
[Tue Jul 28 05:36:03.628026 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/trusj15.php"] [unique_id "amgjo2zzpr4cNKr4fksGvQAAANA"]
[Tue Jul 28 05:36:03.751994 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/flox.php"] [unique_id "amgjo2zzpr4cNKr4fksGvwAAAM8"]
[Tue Jul 28 05:36:03.752939 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/flox.php"] [unique_id "amgjo2zzpr4cNKr4fksGvwAAAM8"]
[Tue Jul 28 05:36:03.753346 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/flox.php"] [unique_id "amgjo2zzpr4cNKr4fksGvwAAAM8"]
[Tue Jul 28 05:36:03.753459 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/flox.php"] [unique_id "amgjo2zzpr4cNKr4fksGvwAAAM8"]
[Tue Jul 28 05:36:03.790670 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bcfhd.php"] [unique_id "amgjo2zzpr4cNKr4fksGwAAAANE"]
[Tue Jul 28 05:36:03.791530 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bcfhd.php"] [unique_id "amgjo2zzpr4cNKr4fksGwAAAANE"]
[Tue Jul 28 05:36:03.791907 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bcfhd.php"] [unique_id "amgjo2zzpr4cNKr4fksGwAAAANE"]
[Tue Jul 28 05:36:03.791992 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bcfhd.php"] [unique_id "amgjo2zzpr4cNKr4fksGwAAAANE"]
[Tue Jul 28 05:36:03.841976 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/camara.php"] [unique_id "amgjo2zzpr4cNKr4fksGwQAAAM0"]
[Tue Jul 28 05:36:03.842606 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/camara.php"] [unique_id "amgjo2zzpr4cNKr4fksGwQAAAM0"]
[Tue Jul 28 05:36:03.842864 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/camara.php"] [unique_id "amgjo2zzpr4cNKr4fksGwQAAAM0"]
[Tue Jul 28 05:36:03.842942 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/camara.php"] [unique_id "amgjo2zzpr4cNKr4fksGwQAAAM0"]
[Tue Jul 28 05:36:03.882466 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/blog/4PJcpMFsD8B.php"] [unique_id "amgjo2zzpr4cNKr4fksGwgAAAMQ"]
[Tue Jul 28 05:36:03.883197 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/blog/4PJcpMFsD8B.php"] [unique_id "amgjo2zzpr4cNKr4fksGwgAAAMQ"]
[Tue Jul 28 05:36:03.883576 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/blog/4PJcpMFsD8B.php"] [unique_id "amgjo2zzpr4cNKr4fksGwgAAAMQ"]
[Tue Jul 28 05:36:03.883665 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/blog/4PJcpMFsD8B.php"] [unique_id "amgjo2zzpr4cNKr4fksGwgAAAMQ"]
[Tue Jul 28 05:36:04.039589 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/venom.php"] [unique_id "amgjpGzzpr4cNKr4fksGwwAAAMY"]
[Tue Jul 28 05:36:04.040474 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/venom.php"] [unique_id "amgjpGzzpr4cNKr4fksGwwAAAMY"]
[Tue Jul 28 05:36:04.040870 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/venom.php"] [unique_id "amgjpGzzpr4cNKr4fksGwwAAAMY"]
[Tue Jul 28 05:36:04.040958 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/venom.php"] [unique_id "amgjpGzzpr4cNKr4fksGwwAAAMY"]
[Tue Jul 28 05:36:04.300170 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bless24.php"] [unique_id "amgjpGzzpr4cNKr4fksGxwAAAMA"]
[Tue Jul 28 05:36:04.301098 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bless24.php"] [unique_id "amgjpGzzpr4cNKr4fksGxwAAAMA"]
[Tue Jul 28 05:36:04.319305 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bless24.php"] [unique_id "amgjpGzzpr4cNKr4fksGxwAAAMA"]
[Tue Jul 28 05:36:04.319476 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bless24.php"] [unique_id "amgjpGzzpr4cNKr4fksGxwAAAMA"]
[Tue Jul 28 05:36:04.661815 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-omao.php"] [unique_id "amgjpGzzpr4cNKr4fksGyQAAAMk"]
[Tue Jul 28 05:36:04.662233 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-omao.php"] [unique_id "amgjpGzzpr4cNKr4fksGyQAAAMk"]
[Tue Jul 28 05:36:04.662539 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-omao.php"] [unique_id "amgjpGzzpr4cNKr4fksGyQAAAMk"]
[Tue Jul 28 05:36:04.662606 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-omao.php"] [unique_id "amgjpGzzpr4cNKr4fksGyQAAAMk"]
[Tue Jul 28 05:36:04.739263 2026] [:error] [pid 28027:tid 139944605484800] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gptsh.php"] [unique_id "amgjpGzzpr4cNKr4fksGygAAAMg"]
[Tue Jul 28 05:36:04.739745 2026] [:error] [pid 28027:tid 139944605484800] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gptsh.php"] [unique_id "amgjpGzzpr4cNKr4fksGygAAAMg"]
[Tue Jul 28 05:36:04.739969 2026] [:error] [pid 28027:tid 139944605484800] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/gptsh.php"] [unique_id "amgjpGzzpr4cNKr4fksGygAAAMg"]
[Tue Jul 28 05:36:04.740044 2026] [:error] [pid 28027:tid 139944605484800] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gptsh.php"] [unique_id "amgjpGzzpr4cNKr4fksGygAAAMg"]
[Tue Jul 28 05:36:04.826517 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/p-blog.php"] [unique_id "amgjpGzzpr4cNKr4fksGzAAAANM"]
[Tue Jul 28 05:36:04.827297 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/p-blog.php"] [unique_id "amgjpGzzpr4cNKr4fksGzAAAANM"]
[Tue Jul 28 05:36:04.827734 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/p-blog.php"] [unique_id "amgjpGzzpr4cNKr4fksGzAAAANM"]
[Tue Jul 28 05:36:04.827825 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/p-blog.php"] [unique_id "amgjpGzzpr4cNKr4fksGzAAAANM"]
[Tue Jul 28 05:36:04.907817 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-curl-file.php"] [unique_id "amgjpGzzpr4cNKr4fksGzgAAANU"]
[Tue Jul 28 05:36:04.908832 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-curl-file.php"] [unique_id "amgjpGzzpr4cNKr4fksGzgAAANU"]
[Tue Jul 28 05:36:04.909217 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-curl-file.php"] [unique_id "amgjpGzzpr4cNKr4fksGzgAAANU"]
[Tue Jul 28 05:36:04.909308 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-curl-file.php"] [unique_id "amgjpGzzpr4cNKr4fksGzgAAANU"]
[Tue Jul 28 05:36:04.943674 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/assacc.php"] [unique_id "amgjpGzzpr4cNKr4fksGzwAAAME"]
[Tue Jul 28 05:36:04.944538 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/assacc.php"] [unique_id "amgjpGzzpr4cNKr4fksGzwAAAME"]
[Tue Jul 28 05:36:04.944940 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/assacc.php"] [unique_id "amgjpGzzpr4cNKr4fksGzwAAAME"]
[Tue Jul 28 05:36:04.945021 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/assacc.php"] [unique_id "amgjpGzzpr4cNKr4fksGzwAAAME"]
[Tue Jul 28 05:36:05.017432 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-cloak.php"] [unique_id "amgjpWzzpr4cNKr4fksG0AAAAM4"]
[Tue Jul 28 05:36:05.018214 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-cloak.php"] [unique_id "amgjpWzzpr4cNKr4fksG0AAAAM4"]
[Tue Jul 28 05:36:05.018535 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-cloak.php"] [unique_id "amgjpWzzpr4cNKr4fksG0AAAAM4"]
[Tue Jul 28 05:36:05.018607 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-cloak.php"] [unique_id "amgjpWzzpr4cNKr4fksG0AAAAM4"]
[Tue Jul 28 05:36:05.095103 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wander.php"] [unique_id "amgjpWzzpr4cNKr4fksG0QAAAM8"]
[Tue Jul 28 05:36:05.095918 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wander.php"] [unique_id "amgjpWzzpr4cNKr4fksG0QAAAM8"]
[Tue Jul 28 05:36:05.096242 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wander.php"] [unique_id "amgjpWzzpr4cNKr4fksG0QAAAM8"]
[Tue Jul 28 05:36:05.096317 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wander.php"] [unique_id "amgjpWzzpr4cNKr4fksG0QAAAM8"]
[Tue Jul 28 05:36:05.136072 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xozx.php"] [unique_id "amgjpWzzpr4cNKr4fksG0wAAAMc"]
[Tue Jul 28 05:36:05.137030 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xozx.php"] [unique_id "amgjpWzzpr4cNKr4fksG0wAAAMc"]
[Tue Jul 28 05:36:05.137523 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/xozx.php"] [unique_id "amgjpWzzpr4cNKr4fksG0wAAAMc"]
[Tue Jul 28 05:36:05.138884 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xozx.php"] [unique_id "amgjpWzzpr4cNKr4fksG0wAAAMc"]
[Tue Jul 28 05:36:05.296640 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/w3llscc.php"] [unique_id "amgjpWzzpr4cNKr4fksG1AAAAM0"]
[Tue Jul 28 05:36:05.297481 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/w3llscc.php"] [unique_id "amgjpWzzpr4cNKr4fksG1AAAAM0"]
[Tue Jul 28 05:36:05.297868 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/w3llscc.php"] [unique_id "amgjpWzzpr4cNKr4fksG1AAAAM0"]
[Tue Jul 28 05:36:05.297962 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/w3llscc.php"] [unique_id "amgjpWzzpr4cNKr4fksG1AAAAM0"]
[Tue Jul 28 05:36:05.341314 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ctex1.php"] [unique_id "amgjpWzzpr4cNKr4fksG1gAAAMI"]
[Tue Jul 28 05:36:05.342243 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ctex1.php"] [unique_id "amgjpWzzpr4cNKr4fksG1gAAAMI"]
[Tue Jul 28 05:36:05.342648 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ctex1.php"] [unique_id "amgjpWzzpr4cNKr4fksG1gAAAMI"]
[Tue Jul 28 05:36:05.342712 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ctex1.php"] [unique_id "amgjpWzzpr4cNKr4fksG1gAAAMI"]
[Tue Jul 28 05:36:05.389943 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-su.php"] [unique_id "amgjpWzzpr4cNKr4fksG1wAAANQ"]
[Tue Jul 28 05:36:05.391003 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-su.php"] [unique_id "amgjpWzzpr4cNKr4fksG1wAAANQ"]
[Tue Jul 28 05:36:05.391456 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-su.php"] [unique_id "amgjpWzzpr4cNKr4fksG1wAAANQ"]
[Tue Jul 28 05:36:05.391568 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-su.php"] [unique_id "amgjpWzzpr4cNKr4fksG1wAAANQ"]
[Tue Jul 28 05:36:05.426378 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/blog/xyn.php"] [unique_id "amgjpWzzpr4cNKr4fksG2AAAAMY"]
[Tue Jul 28 05:36:05.427267 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/blog/xyn.php"] [unique_id "amgjpWzzpr4cNKr4fksG2AAAAMY"]
[Tue Jul 28 05:36:05.427699 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/blog/xyn.php"] [unique_id "amgjpWzzpr4cNKr4fksG2AAAAMY"]
[Tue Jul 28 05:36:05.427793 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/blog/xyn.php"] [unique_id "amgjpWzzpr4cNKr4fksG2AAAAMY"]
[Tue Jul 28 05:36:05.502481 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-wz.php"] [unique_id "amgjpWzzpr4cNKr4fksG2QAAAMs"]
[Tue Jul 28 05:36:05.503245 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-wz.php"] [unique_id "amgjpWzzpr4cNKr4fksG2QAAAMs"]
[Tue Jul 28 05:36:05.503604 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-wz.php"] [unique_id "amgjpWzzpr4cNKr4fksG2QAAAMs"]
[Tue Jul 28 05:36:05.503717 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-wz.php"] [unique_id "amgjpWzzpr4cNKr4fksG2QAAAMs"]
[Tue Jul 28 05:36:05.563036 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-happy.php"] [unique_id "amgjpWzzpr4cNKr4fksG2gAAANg"]
[Tue Jul 28 05:36:05.563835 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-happy.php"] [unique_id "amgjpWzzpr4cNKr4fksG2gAAANg"]
[Tue Jul 28 05:36:05.564198 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-happy.php"] [unique_id "amgjpWzzpr4cNKr4fksG2gAAANg"]
[Tue Jul 28 05:36:05.564278 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-happy.php"] [unique_id "amgjpWzzpr4cNKr4fksG2gAAANg"]
[Tue Jul 28 05:36:05.722648 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "amgjpWzzpr4cNKr4fksG2wAAAMA"]
[Tue Jul 28 05:36:05.723436 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "amgjpWzzpr4cNKr4fksG2wAAAMA"]
[Tue Jul 28 05:36:05.723780 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "amgjpWzzpr4cNKr4fksG2wAAAMA"]
[Tue Jul 28 05:36:05.723857 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "amgjpWzzpr4cNKr4fksG2wAAAMA"]
[Tue Jul 28 05:36:06.391782 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-ver.php"] [unique_id "amgjpmzzpr4cNKr4fksG3wAAAMU"]
[Tue Jul 28 05:36:06.392701 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-ver.php"] [unique_id "amgjpmzzpr4cNKr4fksG3wAAAMU"]
[Tue Jul 28 05:36:06.393088 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-ver.php"] [unique_id "amgjpmzzpr4cNKr4fksG3wAAAMU"]
[Tue Jul 28 05:36:06.393173 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-ver.php"] [unique_id "amgjpmzzpr4cNKr4fksG3wAAAMU"]
[Tue Jul 28 05:36:06.740955 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/rum.php"] [unique_id "amgjpmzzpr4cNKr4fksG4gAAANU"]
[Tue Jul 28 05:36:06.741824 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/rum.php"] [unique_id "amgjpmzzpr4cNKr4fksG4gAAANU"]
[Tue Jul 28 05:36:06.742211 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/rum.php"] [unique_id "amgjpmzzpr4cNKr4fksG4gAAANU"]
[Tue Jul 28 05:36:06.742300 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/rum.php"] [unique_id "amgjpmzzpr4cNKr4fksG4gAAANU"]
[Tue Jul 28 05:36:06.780518 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file88.php"] [unique_id "amgjpmzzpr4cNKr4fksG4wAAAM4"]
[Tue Jul 28 05:36:06.781136 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file88.php"] [unique_id "amgjpmzzpr4cNKr4fksG4wAAAM4"]
[Tue Jul 28 05:36:06.781415 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file88.php"] [unique_id "amgjpmzzpr4cNKr4fksG4wAAAM4"]
[Tue Jul 28 05:36:06.781473 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file88.php"] [unique_id "amgjpmzzpr4cNKr4fksG4wAAAM4"]
[Tue Jul 28 05:36:06.860659 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ss.php"] [unique_id "amgjpmzzpr4cNKr4fksG5AAAAMw"]
[Tue Jul 28 05:36:06.861631 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ss.php"] [unique_id "amgjpmzzpr4cNKr4fksG5AAAAMw"]
[Tue Jul 28 05:36:06.862015 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ss.php"] [unique_id "amgjpmzzpr4cNKr4fksG5AAAAMw"]
[Tue Jul 28 05:36:06.862102 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ss.php"] [unique_id "amgjpmzzpr4cNKr4fksG5AAAAMw"]
[Tue Jul 28 05:36:07.000660 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/rft8.php"] [unique_id "amgjpmzzpr4cNKr4fksG5gAAAMc"]
[Tue Jul 28 05:36:07.001480 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/rft8.php"] [unique_id "amgjpmzzpr4cNKr4fksG5gAAAMc"]
[Tue Jul 28 05:36:07.001862 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/rft8.php"] [unique_id "amgjpmzzpr4cNKr4fksG5gAAAMc"]
[Tue Jul 28 05:36:07.001963 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/rft8.php"] [unique_id "amgjpmzzpr4cNKr4fksG5gAAAMc"]
[Tue Jul 28 05:36:07.076681 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sg.php"] [unique_id "amgjp2zzpr4cNKr4fksG6AAAAMI"]
[Tue Jul 28 05:36:07.077658 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sg.php"] [unique_id "amgjp2zzpr4cNKr4fksG6AAAAMI"]
[Tue Jul 28 05:36:07.078072 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sg.php"] [unique_id "amgjp2zzpr4cNKr4fksG6AAAAMI"]
[Tue Jul 28 05:36:07.078160 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sg.php"] [unique_id "amgjp2zzpr4cNKr4fksG6AAAAMI"]
[Tue Jul 28 05:36:07.122615 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bajah.php"] [unique_id "amgjp2zzpr4cNKr4fksG6QAAANQ"]
[Tue Jul 28 05:36:07.123470 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bajah.php"] [unique_id "amgjp2zzpr4cNKr4fksG6QAAANQ"]
[Tue Jul 28 05:36:07.123841 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bajah.php"] [unique_id "amgjp2zzpr4cNKr4fksG6QAAANQ"]
[Tue Jul 28 05:36:07.123921 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bajah.php"] [unique_id "amgjp2zzpr4cNKr4fksG6QAAANQ"]
[Tue Jul 28 05:36:07.233445 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cc13.php"] [unique_id "amgjp2zzpr4cNKr4fksG6wAAAMY"]
[Tue Jul 28 05:36:07.234411 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cc13.php"] [unique_id "amgjp2zzpr4cNKr4fksG6wAAAMY"]
[Tue Jul 28 05:36:07.234846 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/cc13.php"] [unique_id "amgjp2zzpr4cNKr4fksG6wAAAMY"]
[Tue Jul 28 05:36:07.234945 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:10047] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cc13.php"] [unique_id "amgjp2zzpr4cNKr4fksG6wAAAMY"]
[Tue Jul 28 05:36:07.332650 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/son.php"] [unique_id "amgjp2zzpr4cNKr4fksG7AAAANg"]
[Tue Jul 28 05:36:07.333502 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/son.php"] [unique_id "amgjp2zzpr4cNKr4fksG7AAAANg"]
[Tue Jul 28 05:36:07.333911 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/son.php"] [unique_id "amgjp2zzpr4cNKr4fksG7AAAANg"]
[Tue Jul 28 05:36:07.333999 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/son.php"] [unique_id "amgjp2zzpr4cNKr4fksG7AAAANg"]
[Tue Jul 28 05:36:07.497797 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wpurl.php"] [unique_id "amgjp2zzpr4cNKr4fksG7QAAANE"]
[Tue Jul 28 05:36:07.498410 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wpurl.php"] [unique_id "amgjp2zzpr4cNKr4fksG7QAAANE"]
[Tue Jul 28 05:36:07.498857 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wpurl.php"] [unique_id "amgjp2zzpr4cNKr4fksG7QAAANE"]
[Tue Jul 28 05:36:07.498927 2026] [:error] [pid 28027:tid 139944529950464] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wpurl.php"] [unique_id "amgjp2zzpr4cNKr4fksG7QAAANE"]
[Tue Jul 28 05:36:07.595143 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/zi-936.php"] [unique_id "amgjp2zzpr4cNKr4fksG8AAAAMQ"]
[Tue Jul 28 05:36:07.596000 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/zi-936.php"] [unique_id "amgjp2zzpr4cNKr4fksG8AAAAMQ"]
[Tue Jul 28 05:36:07.596415 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/zi-936.php"] [unique_id "amgjp2zzpr4cNKr4fksG8AAAAMQ"]
[Tue Jul 28 05:36:07.596508 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/zi-936.php"] [unique_id "amgjp2zzpr4cNKr4fksG8AAAAMQ"]
[Tue Jul 28 05:36:07.686568 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ortasekerli1.php"] [unique_id "amgjp2zzpr4cNKr4fksG8QAAAMk"]
[Tue Jul 28 05:36:07.687401 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ortasekerli1.php"] [unique_id "amgjp2zzpr4cNKr4fksG8QAAAMk"]
[Tue Jul 28 05:36:07.687781 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ortasekerli1.php"] [unique_id "amgjp2zzpr4cNKr4fksG8QAAAMk"]
[Tue Jul 28 05:36:07.687883 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ortasekerli1.php"] [unique_id "amgjp2zzpr4cNKr4fksG8QAAAMk"]
[Tue Jul 28 05:36:07.738623 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/tx58.php"] [unique_id "amgjp2zzpr4cNKr4fksG8gAAAMU"]
[Tue Jul 28 05:36:07.739437 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/tx58.php"] [unique_id "amgjp2zzpr4cNKr4fksG8gAAAMU"]
[Tue Jul 28 05:36:07.741727 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/tx58.php"] [unique_id "amgjp2zzpr4cNKr4fksG8gAAAMU"]
[Tue Jul 28 05:36:07.741829 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/tx58.php"] [unique_id "amgjp2zzpr4cNKr4fksG8gAAAMU"]
[Tue Jul 28 05:36:07.829959 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp5.php"] [unique_id "amgjp2zzpr4cNKr4fksG9AAAANA"]
[Tue Jul 28 05:36:07.830924 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp5.php"] [unique_id "amgjp2zzpr4cNKr4fksG9AAAANA"]
[Tue Jul 28 05:36:07.831350 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp5.php"] [unique_id "amgjp2zzpr4cNKr4fksG9AAAANA"]
[Tue Jul 28 05:36:07.831461 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp5.php"] [unique_id "amgjp2zzpr4cNKr4fksG9AAAANA"]
[Tue Jul 28 05:36:07.872590 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xper1.php"] [unique_id "amgjp2zzpr4cNKr4fksG9QAAANU"]
[Tue Jul 28 05:36:07.873210 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xper1.php"] [unique_id "amgjp2zzpr4cNKr4fksG9QAAANU"]
[Tue Jul 28 05:36:07.873519 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/xper1.php"] [unique_id "amgjp2zzpr4cNKr4fksG9QAAANU"]
[Tue Jul 28 05:36:07.873596 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xper1.php"] [unique_id "amgjp2zzpr4cNKr4fksG9QAAANU"]
[Tue Jul 28 05:36:07.930858 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/for.php"] [unique_id "amgjp2zzpr4cNKr4fksG9wAAAM4"]
[Tue Jul 28 05:36:07.931773 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/for.php"] [unique_id "amgjp2zzpr4cNKr4fksG9wAAAM4"]
[Tue Jul 28 05:36:07.932147 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/for.php"] [unique_id "amgjp2zzpr4cNKr4fksG9wAAAM4"]
[Tue Jul 28 05:36:07.932249 2026] [:error] [pid 28027:tid 139944555128576] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/for.php"] [unique_id "amgjp2zzpr4cNKr4fksG9wAAAM4"]
[Tue Jul 28 05:36:07.973564 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-vu6yj0b7.php"] [unique_id "amgjp2zzpr4cNKr4fksG-AAAAMw"]
[Tue Jul 28 05:36:07.974338 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-vu6yj0b7.php"] [unique_id "amgjp2zzpr4cNKr4fksG-AAAAMw"]
[Tue Jul 28 05:36:07.974745 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-vu6yj0b7.php"] [unique_id "amgjp2zzpr4cNKr4fksG-AAAAMw"]
[Tue Jul 28 05:36:07.974833 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-vu6yj0b7.php"] [unique_id "amgjp2zzpr4cNKr4fksG-AAAAMw"]
[Tue Jul 28 05:36:08.058303 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bless18.php"] [unique_id "amgjqGzzpr4cNKr4fksG-QAAANM"]
[Tue Jul 28 05:36:08.059165 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bless18.php"] [unique_id "amgjqGzzpr4cNKr4fksG-QAAANM"]
[Tue Jul 28 05:36:08.059453 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bless18.php"] [unique_id "amgjqGzzpr4cNKr4fksG-QAAANM"]
[Tue Jul 28 05:36:08.059508 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bless18.php"] [unique_id "amgjqGzzpr4cNKr4fksG-QAAANM"]
[Tue Jul 28 05:36:08.123877 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/jj.php"] [unique_id "amgjqGzzpr4cNKr4fksG-gAAAMc"]
[Tue Jul 28 05:36:08.124745 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/jj.php"] [unique_id "amgjqGzzpr4cNKr4fksG-gAAAMc"]
[Tue Jul 28 05:36:08.125148 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/jj.php"] [unique_id "amgjqGzzpr4cNKr4fksG-gAAAMc"]
[Tue Jul 28 05:36:08.125236 2026] [:error] [pid 28027:tid 139944613877504] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/jj.php"] [unique_id "amgjqGzzpr4cNKr4fksG-gAAAMc"]
[Tue Jul 28 05:36:08.186115 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/diidi.php"] [unique_id "amgjqGzzpr4cNKr4fksG-wAAANY"]
[Tue Jul 28 05:36:08.186915 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/diidi.php"] [unique_id "amgjqGzzpr4cNKr4fksG-wAAANY"]
[Tue Jul 28 05:36:08.187265 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/diidi.php"] [unique_id "amgjqGzzpr4cNKr4fksG-wAAANY"]
[Tue Jul 28 05:36:08.187344 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/diidi.php"] [unique_id "amgjqGzzpr4cNKr4fksG-wAAANY"]
[Tue Jul 28 05:36:08.245512 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/777.php"] [unique_id "amgjqGzzpr4cNKr4fksG_QAAANQ"]
[Tue Jul 28 05:36:08.246950 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/777.php"] [unique_id "amgjqGzzpr4cNKr4fksG_QAAANQ"]
[Tue Jul 28 05:36:08.247425 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/777.php"] [unique_id "amgjqGzzpr4cNKr4fksG_QAAANQ"]
[Tue Jul 28 05:36:08.247515 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/777.php"] [unique_id "amgjqGzzpr4cNKr4fksG_QAAANQ"]
[Tue Jul 28 05:36:08.333886 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/media.php"] [unique_id "amgjqGzzpr4cNKr4fksG_wAAAMY"]
[Tue Jul 28 05:36:08.334878 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/media.php"] [unique_id "amgjqGzzpr4cNKr4fksG_wAAAMY"]
[Tue Jul 28 05:36:08.335264 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/media.php"] [unique_id "amgjqGzzpr4cNKr4fksG_wAAAMY"]
[Tue Jul 28 05:36:08.335361 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-content/media.php"] [unique_id "amgjqGzzpr4cNKr4fksG_wAAAMY"]
[Tue Jul 28 05:36:08.387639 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes//css.php"] [unique_id "amgjqGzzpr4cNKr4fksHAAAAAMs"]
[Tue Jul 28 05:36:08.388481 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css.php"] [unique_id "amgjqGzzpr4cNKr4fksHAAAAAMs"]
[Tue Jul 28 05:36:08.388862 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css.php"] [unique_id "amgjqGzzpr4cNKr4fksHAAAAAMs"]
[Tue Jul 28 05:36:08.388961 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css.php"] [unique_id "amgjqGzzpr4cNKr4fksHAAAAAMs"]
[Tue Jul 28 05:36:08.425613 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sql.php"] [unique_id "amgjqGzzpr4cNKr4fksHAQAAANg"]
[Tue Jul 28 05:36:08.426455 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sql.php"] [unique_id "amgjqGzzpr4cNKr4fksHAQAAANg"]
[Tue Jul 28 05:36:08.426855 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sql.php"] [unique_id "amgjqGzzpr4cNKr4fksHAQAAANg"]
[Tue Jul 28 05:36:08.426943 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sql.php"] [unique_id "amgjqGzzpr4cNKr4fksHAQAAANg"]
[Tue Jul 28 05:36:08.476632 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/jjost.php"] [unique_id "amgjqGzzpr4cNKr4fksHAgAAAM8"]
[Tue Jul 28 05:36:08.477424 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/jjost.php"] [unique_id "amgjqGzzpr4cNKr4fksHAgAAAM8"]
[Tue Jul 28 05:36:08.477774 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/jjost.php"] [unique_id "amgjqGzzpr4cNKr4fksHAgAAAM8"]
[Tue Jul 28 05:36:08.477852 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/jjost.php"] [unique_id "amgjqGzzpr4cNKr4fksHAgAAAM8"]
[Tue Jul 28 05:36:08.530882 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/albin.php"] [unique_id "amgjqGzzpr4cNKr4fksHBAAAAMQ"]
[Tue Jul 28 05:36:08.531844 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/albin.php"] [unique_id "amgjqGzzpr4cNKr4fksHBAAAAMQ"]
[Tue Jul 28 05:36:08.532263 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/albin.php"] [unique_id "amgjqGzzpr4cNKr4fksHBAAAAMQ"]
[Tue Jul 28 05:36:08.532348 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/albin.php"] [unique_id "amgjqGzzpr4cNKr4fksHBAAAAMQ"]
[Tue Jul 28 05:36:08.567383 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gk.php"] [unique_id "amgjqGzzpr4cNKr4fksHBQAAAM0"]
[Tue Jul 28 05:36:08.568404 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gk.php"] [unique_id "amgjqGzzpr4cNKr4fksHBQAAAM0"]
[Tue Jul 28 05:36:08.568838 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/gk.php"] [unique_id "amgjqGzzpr4cNKr4fksHBQAAAM0"]
[Tue Jul 28 05:36:08.568947 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gk.php"] [unique_id "amgjqGzzpr4cNKr4fksHBQAAAM0"]
[Tue Jul 28 05:36:08.694591 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/reop3.php"] [unique_id "amgjqGzzpr4cNKr4fksHBgAAAMk"]
[Tue Jul 28 05:36:08.695351 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/reop3.php"] [unique_id "amgjqGzzpr4cNKr4fksHBgAAAMk"]
[Tue Jul 28 05:36:08.695745 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/reop3.php"] [unique_id "amgjqGzzpr4cNKr4fksHBgAAAMk"]
[Tue Jul 28 05:36:08.695830 2026] [:error] [pid 28027:tid 139944597092096] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/reop3.php"] [unique_id "amgjqGzzpr4cNKr4fksHBgAAAMk"]
[Tue Jul 28 05:36:08.747190 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes//wp-type.php"] [unique_id "amgjqGzzpr4cNKr4fksHCAAAANI"]
[Tue Jul 28 05:36:08.748245 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/wp-type.php"] [unique_id "amgjqGzzpr4cNKr4fksHCAAAANI"]
[Tue Jul 28 05:36:08.748692 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/wp-type.php"] [unique_id "amgjqGzzpr4cNKr4fksHCAAAANI"]
[Tue Jul 28 05:36:08.748792 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/wp-type.php"] [unique_id "amgjqGzzpr4cNKr4fksHCAAAANI"]
[Tue Jul 28 05:36:08.844694 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cilus.php"] [unique_id "amgjqGzzpr4cNKr4fksHCQAAANU"]
[Tue Jul 28 05:36:08.845544 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cilus.php"] [unique_id "amgjqGzzpr4cNKr4fksHCQAAANU"]
[Tue Jul 28 05:36:08.845926 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/cilus.php"] [unique_id "amgjqGzzpr4cNKr4fksHCQAAANU"]
[Tue Jul 28 05:36:08.846003 2026] [:error] [pid 28027:tid 139944496379648] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cilus.php"] [unique_id "amgjqGzzpr4cNKr4fksHCQAAANU"]
[Tue Jul 28 05:36:08.931329 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cream3.php"] [unique_id "amgjqGzzpr4cNKr4fksHCwAAAMw"]
[Tue Jul 28 05:36:08.932351 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cream3.php"] [unique_id "amgjqGzzpr4cNKr4fksHCwAAAMw"]
[Tue Jul 28 05:36:08.932806 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/cream3.php"] [unique_id "amgjqGzzpr4cNKr4fksHCwAAAMw"]
[Tue Jul 28 05:36:08.932898 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cream3.php"] [unique_id "amgjqGzzpr4cNKr4fksHCwAAAMw"]
[Tue Jul 28 05:36:09.012361 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-block.php"] [unique_id "amgjqWzzpr4cNKr4fksHDAAAAMA"]
[Tue Jul 28 05:36:09.013206 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-block.php"] [unique_id "amgjqWzzpr4cNKr4fksHDAAAAMA"]
[Tue Jul 28 05:36:09.013614 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-block.php"] [unique_id "amgjqWzzpr4cNKr4fksHDAAAAMA"]
[Tue Jul 28 05:36:09.013696 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-block.php"] [unique_id "amgjqWzzpr4cNKr4fksHDAAAAMA"]
[Tue Jul 28 05:36:09.387444 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ccc.php"] [unique_id "amgjqWzzpr4cNKr4fksHDQAAANQ"]
[Tue Jul 28 05:36:09.388112 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ccc.php"] [unique_id "amgjqWzzpr4cNKr4fksHDQAAANQ"]
[Tue Jul 28 05:36:09.388368 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ccc.php"] [unique_id "amgjqWzzpr4cNKr4fksHDQAAANQ"]
[Tue Jul 28 05:36:09.388437 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ccc.php"] [unique_id "amgjqWzzpr4cNKr4fksHDQAAANQ"]
[Tue Jul 28 05:36:09.424501 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file11.php"] [unique_id "amgjqWzzpr4cNKr4fksHDgAAAMY"]
[Tue Jul 28 05:36:09.425644 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file11.php"] [unique_id "amgjqWzzpr4cNKr4fksHDgAAAMY"]
[Tue Jul 28 05:36:09.426192 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file11.php"] [unique_id "amgjqWzzpr4cNKr4fksHDgAAAMY"]
[Tue Jul 28 05:36:09.426329 2026] [:error] [pid 28027:tid 139944622270208] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file11.php"] [unique_id "amgjqWzzpr4cNKr4fksHDgAAAMY"]
[Tue Jul 28 05:36:09.579930 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/miru3.php"] [unique_id "amgjqWzzpr4cNKr4fksHEQAAAME"]
[Tue Jul 28 05:36:09.580798 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/miru3.php"] [unique_id "amgjqWzzpr4cNKr4fksHEQAAAME"]
[Tue Jul 28 05:36:09.581262 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/miru3.php"] [unique_id "amgjqWzzpr4cNKr4fksHEQAAAME"]
[Tue Jul 28 05:36:09.581358 2026] [:error] [pid 28027:tid 139944664233728] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/miru3.php"] [unique_id "amgjqWzzpr4cNKr4fksHEQAAAME"]
[Tue Jul 28 05:36:09.663674 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-u3nxbvx.php"] [unique_id "amgjqWzzpr4cNKr4fksHEgAAANg"]
[Tue Jul 28 05:36:09.664537 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-u3nxbvx.php"] [unique_id "amgjqWzzpr4cNKr4fksHEgAAANg"]
[Tue Jul 28 05:36:09.665097 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-u3nxbvx.php"] [unique_id "amgjqWzzpr4cNKr4fksHEgAAANg"]
[Tue Jul 28 05:36:09.665247 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-u3nxbvx.php"] [unique_id "amgjqWzzpr4cNKr4fksHEgAAANg"]
[Tue Jul 28 05:36:09.742677 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-x7.php"] [unique_id "amgjqWzzpr4cNKr4fksHEwAAAM8"]
[Tue Jul 28 05:36:09.743428 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-x7.php"] [unique_id "amgjqWzzpr4cNKr4fksHEwAAAM8"]
[Tue Jul 28 05:36:09.743756 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-x7.php"] [unique_id "amgjqWzzpr4cNKr4fksHEwAAAM8"]
[Tue Jul 28 05:36:09.743830 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-x7.php"] [unique_id "amgjqWzzpr4cNKr4fksHEwAAAM8"]
[Tue Jul 28 05:36:09.834407 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file6.php"] [unique_id "amgjqWzzpr4cNKr4fksHFAAAAMQ"]
[Tue Jul 28 05:36:09.834984 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file6.php"] [unique_id "amgjqWzzpr4cNKr4fksHFAAAAMQ"]
[Tue Jul 28 05:36:09.835278 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file6.php"] [unique_id "amgjqWzzpr4cNKr4fksHFAAAAMQ"]
[Tue Jul 28 05:36:09.835347 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file6.php"] [unique_id "amgjqWzzpr4cNKr4fksHFAAAAMQ"]
[Tue Jul 28 05:36:09.926039 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/blog/3PJcpMFsD8B.php"] [unique_id "amgjqWzzpr4cNKr4fksHFQAAAM0"]
[Tue Jul 28 05:36:09.926693 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/blog/3PJcpMFsD8B.php"] [unique_id "amgjqWzzpr4cNKr4fksHFQAAAM0"]
[Tue Jul 28 05:36:09.926954 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/blog/3PJcpMFsD8B.php"] [unique_id "amgjqWzzpr4cNKr4fksHFQAAAM0"]
[Tue Jul 28 05:36:09.927029 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/blog/3PJcpMFsD8B.php"] [unique_id "amgjqWzzpr4cNKr4fksHFQAAAM0"]
[Tue Jul 28 05:36:10.078093 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-l3u4lha.php"] [unique_id "amgjqmzzpr4cNKr4fksHFwAAAMI"]
[Tue Jul 28 05:36:10.078808 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-l3u4lha.php"] [unique_id "amgjqmzzpr4cNKr4fksHFwAAAMI"]
[Tue Jul 28 05:36:10.079121 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-l3u4lha.php"] [unique_id "amgjqmzzpr4cNKr4fksHFwAAAMI"]
[Tue Jul 28 05:36:10.079182 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-l3u4lha.php"] [unique_id "amgjqmzzpr4cNKr4fksHFwAAAMI"]
[Tue Jul 28 05:36:10.154484 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fx.php"] [unique_id "amgjqmzzpr4cNKr4fksHGQAAANI"]
[Tue Jul 28 05:36:10.155416 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fx.php"] [unique_id "amgjqmzzpr4cNKr4fksHGQAAANI"]
[Tue Jul 28 05:36:10.155846 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fx.php"] [unique_id "amgjqmzzpr4cNKr4fksHGQAAANI"]
[Tue Jul 28 05:36:10.155946 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/fx.php"] [unique_id "amgjqmzzpr4cNKr4fksHGQAAANI"]
[Tue Jul 28 05:36:10.195683 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/insta.php"] [unique_id "amgjqmzzpr4cNKr4fksHGgAAANA"]
[Tue Jul 28 05:36:10.196517 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/insta.php"] [unique_id "amgjqmzzpr4cNKr4fksHGgAAANA"]
[Tue Jul 28 05:36:10.196925 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/insta.php"] [unique_id "amgjqmzzpr4cNKr4fksHGgAAANA"]
[Tue Jul 28 05:36:10.197003 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/insta.php"] [unique_id "amgjqmzzpr4cNKr4fksHGgAAANA"]
[Tue Jul 28 05:36:10.254356 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-thi.php"] [unique_id "amgjqmzzpr4cNKr4fksHHAAAAMw"]
[Tue Jul 28 05:36:10.255031 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-thi.php"] [unique_id "amgjqmzzpr4cNKr4fksHHAAAAMw"]
[Tue Jul 28 05:36:10.255320 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-thi.php"] [unique_id "amgjqmzzpr4cNKr4fksHHAAAAMw"]
[Tue Jul 28 05:36:10.255402 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-thi.php"] [unique_id "amgjqmzzpr4cNKr4fksHHAAAAMw"]
[Tue Jul 28 05:36:10.290933 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/uploads/hega.php"] [unique_id "amgjqmzzpr4cNKr4fksHHQAAANM"]
[Tue Jul 28 05:36:10.291753 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/uploads/hega.php"] [unique_id "amgjqmzzpr4cNKr4fksHHQAAANM"]
[Tue Jul 28 05:36:10.292123 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/uploads/hega.php"] [unique_id "amgjqmzzpr4cNKr4fksHHQAAANM"]
[Tue Jul 28 05:36:10.292205 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/uploads/hega.php"] [unique_id "amgjqmzzpr4cNKr4fksHHQAAANM"]
[Tue Jul 28 05:36:10.350730 2026] [:error] [pid 28027:tid 139944588699392] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ssla.php"] [unique_id "amgjqmzzpr4cNKr4fksHHgAAAMo"]
[Tue Jul 28 05:36:10.351576 2026] [:error] [pid 28027:tid 139944588699392] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ssla.php"] [unique_id "amgjqmzzpr4cNKr4fksHHgAAAMo"]
[Tue Jul 28 05:36:10.351948 2026] [:error] [pid 28027:tid 139944588699392] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ssla.php"] [unique_id "amgjqmzzpr4cNKr4fksHHgAAAMo"]
[Tue Jul 28 05:36:10.352039 2026] [:error] [pid 28027:tid 139944588699392] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ssla.php"] [unique_id "amgjqmzzpr4cNKr4fksHHgAAAMo"]
[Tue Jul 28 05:36:10.406269 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/btx25.php"] [unique_id "amgjqmzzpr4cNKr4fksHHwAAAMA"]
[Tue Jul 28 05:36:10.406873 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/btx25.php"] [unique_id "amgjqmzzpr4cNKr4fksHHwAAAMA"]
[Tue Jul 28 05:36:10.407125 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/btx25.php"] [unique_id "amgjqmzzpr4cNKr4fksHHwAAAMA"]
[Tue Jul 28 05:36:10.407179 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/btx25.php"] [unique_id "amgjqmzzpr4cNKr4fksHHwAAAMA"]
[Tue Jul 28 05:36:10.506157 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes//BVeA9.php"] [unique_id "amgjqmzzpr4cNKr4fksHIAAAANc"]
[Tue Jul 28 05:36:10.506936 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/BVeA9.php"] [unique_id "amgjqmzzpr4cNKr4fksHIAAAANc"]
[Tue Jul 28 05:36:10.507298 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/BVeA9.php"] [unique_id "amgjqmzzpr4cNKr4fksHIAAAANc"]
[Tue Jul 28 05:36:10.507380 2026] [:error] [pid 28027:tid 139944479594240] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/BVeA9.php"] [unique_id "amgjqmzzpr4cNKr4fksHIAAAANc"]
[Tue Jul 28 05:36:10.596481 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/s_8.php"] [unique_id "amgjqmzzpr4cNKr4fksHIQAAAMU"]
[Tue Jul 28 05:36:10.597252 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/s_8.php"] [unique_id "amgjqmzzpr4cNKr4fksHIQAAAMU"]
[Tue Jul 28 05:36:10.597641 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/s_8.php"] [unique_id "amgjqmzzpr4cNKr4fksHIQAAAMU"]
[Tue Jul 28 05:36:10.597737 2026] [:error] [pid 28027:tid 139944630662912] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/s_8.php"] [unique_id "amgjqmzzpr4cNKr4fksHIQAAAMU"]
[Tue Jul 28 05:36:10.664490 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-inic3.php"] [unique_id "amgjqmzzpr4cNKr4fksHIgAAANY"]
[Tue Jul 28 05:36:10.665327 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-inic3.php"] [unique_id "amgjqmzzpr4cNKr4fksHIgAAANY"]
[Tue Jul 28 05:36:10.665730 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-inic3.php"] [unique_id "amgjqmzzpr4cNKr4fksHIgAAANY"]
[Tue Jul 28 05:36:10.665833 2026] [:error] [pid 28027:tid 139944487986944] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-inic3.php"] [unique_id "amgjqmzzpr4cNKr4fksHIgAAANY"]
[Tue Jul 28 05:36:10.731591 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-link-zorm.php"] [unique_id "amgjqmzzpr4cNKr4fksHIwAAANQ"]
[Tue Jul 28 05:36:10.732382 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-link-zorm.php"] [unique_id "amgjqmzzpr4cNKr4fksHIwAAANQ"]
[Tue Jul 28 05:36:10.732784 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-link-zorm.php"] [unique_id "amgjqmzzpr4cNKr4fksHIwAAANQ"]
[Tue Jul 28 05:36:10.732873 2026] [:error] [pid 28027:tid 139944504772352] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-link-zorm.php"] [unique_id "amgjqmzzpr4cNKr4fksHIwAAANQ"]
[Tue Jul 28 05:36:10.882070 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cdjyf.php"] [unique_id "amgjqmzzpr4cNKr4fksHJQAAAMs"]
[Tue Jul 28 05:36:10.882969 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cdjyf.php"] [unique_id "amgjqmzzpr4cNKr4fksHJQAAAMs"]
[Tue Jul 28 05:36:10.883356 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/cdjyf.php"] [unique_id "amgjqmzzpr4cNKr4fksHJQAAAMs"]
[Tue Jul 28 05:36:10.883466 2026] [:error] [pid 28027:tid 139944580306688] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cdjyf.php"] [unique_id "amgjqmzzpr4cNKr4fksHJQAAAMs"]
[Tue Jul 28 05:36:10.988034 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/crgio.php"] [unique_id "amgjqmzzpr4cNKr4fksHKAAAANg"]
[Tue Jul 28 05:36:10.989053 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/crgio.php"] [unique_id "amgjqmzzpr4cNKr4fksHKAAAANg"]
[Tue Jul 28 05:36:10.989514 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/crgio.php"] [unique_id "amgjqmzzpr4cNKr4fksHKAAAANg"]
[Tue Jul 28 05:36:10.989640 2026] [:error] [pid 28027:tid 139944471201536] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/crgio.php"] [unique_id "amgjqmzzpr4cNKr4fksHKAAAANg"]
[Tue Jul 28 05:36:11.051600 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/buds1.php"] [unique_id "amgjq2zzpr4cNKr4fksHKQAAAM8"]
[Tue Jul 28 05:36:11.052421 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/buds1.php"] [unique_id "amgjq2zzpr4cNKr4fksHKQAAAM8"]
[Tue Jul 28 05:36:11.052808 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/buds1.php"] [unique_id "amgjq2zzpr4cNKr4fksHKQAAAM8"]
[Tue Jul 28 05:36:11.052896 2026] [:error] [pid 28027:tid 139944546735872] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/buds1.php"] [unique_id "amgjq2zzpr4cNKr4fksHKQAAAM8"]
[Tue Jul 28 05:36:11.113539 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-aothait.php"] [unique_id "amgjq2zzpr4cNKr4fksHKgAAAMQ"]
[Tue Jul 28 05:36:11.114192 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-aothait.php"] [unique_id "amgjq2zzpr4cNKr4fksHKgAAAMQ"]
[Tue Jul 28 05:36:11.114588 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-aothait.php"] [unique_id "amgjq2zzpr4cNKr4fksHKgAAAMQ"]
[Tue Jul 28 05:36:11.114672 2026] [:error] [pid 28027:tid 139944639055616] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-aothait.php"] [unique_id "amgjq2zzpr4cNKr4fksHKgAAAMQ"]
[Tue Jul 28 05:36:11.149314 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/pomo/css_.php"] [unique_id "amgjq2zzpr4cNKr4fksHKwAAAM0"]
[Tue Jul 28 05:36:11.150135 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/pomo/css_.php"] [unique_id "amgjq2zzpr4cNKr4fksHKwAAAM0"]
[Tue Jul 28 05:36:11.150575 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/pomo/css_.php"] [unique_id "amgjq2zzpr4cNKr4fksHKwAAAM0"]
[Tue Jul 28 05:36:11.150658 2026] [:error] [pid 28027:tid 139944563521280] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/pomo/css_.php"] [unique_id "amgjq2zzpr4cNKr4fksHKwAAAM0"]
[Tue Jul 28 05:36:11.185737 2026] [:error] [pid 28027:tid 139944647448320] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bk.php"] [unique_id "amgjq2zzpr4cNKr4fksHLQAAAMM"]
[Tue Jul 28 05:36:11.186679 2026] [:error] [pid 28027:tid 139944647448320] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bk.php"] [unique_id "amgjq2zzpr4cNKr4fksHLQAAAMM"]
[Tue Jul 28 05:36:11.187097 2026] [:error] [pid 28027:tid 139944647448320] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bk.php"] [unique_id "amgjq2zzpr4cNKr4fksHLQAAAMM"]
[Tue Jul 28 05:36:11.187188 2026] [:error] [pid 28027:tid 139944647448320] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bk.php"] [unique_id "amgjq2zzpr4cNKr4fksHLQAAAMM"]
[Tue Jul 28 05:36:11.228286 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cx.php"] [unique_id "amgjq2zzpr4cNKr4fksHLgAAAMI"]
[Tue Jul 28 05:36:11.229214 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cx.php"] [unique_id "amgjq2zzpr4cNKr4fksHLgAAAMI"]
[Tue Jul 28 05:36:11.229652 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/cx.php"] [unique_id "amgjq2zzpr4cNKr4fksHLgAAAMI"]
[Tue Jul 28 05:36:11.229745 2026] [:error] [pid 28027:tid 139944655841024] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cx.php"] [unique_id "amgjq2zzpr4cNKr4fksHLgAAAMI"]
[Tue Jul 28 05:36:11.272611 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/webx.php"] [unique_id "amgjq2zzpr4cNKr4fksHLwAAANI"]
[Tue Jul 28 05:36:11.273410 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/webx.php"] [unique_id "amgjq2zzpr4cNKr4fksHLwAAANI"]
[Tue Jul 28 05:36:11.273800 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/webx.php"] [unique_id "amgjq2zzpr4cNKr4fksHLwAAANI"]
[Tue Jul 28 05:36:11.273885 2026] [:error] [pid 28027:tid 139944521557760] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/webx.php"] [unique_id "amgjq2zzpr4cNKr4fksHLwAAANI"]
[Tue Jul 28 05:36:11.318523 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/satan.php"] [unique_id "amgjq2zzpr4cNKr4fksHMAAAANA"]
[Tue Jul 28 05:36:11.319428 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/satan.php"] [unique_id "amgjq2zzpr4cNKr4fksHMAAAANA"]
[Tue Jul 28 05:36:11.319980 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/satan.php"] [unique_id "amgjq2zzpr4cNKr4fksHMAAAANA"]
[Tue Jul 28 05:36:11.320073 2026] [:error] [pid 28027:tid 139944538343168] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/satan.php"] [unique_id "amgjq2zzpr4cNKr4fksHMAAAANA"]
[Tue Jul 28 05:36:11.354875 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/chomu.php"] [unique_id "amgjq2zzpr4cNKr4fksHMQAAAMw"]
[Tue Jul 28 05:36:11.355721 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/chomu.php"] [unique_id "amgjq2zzpr4cNKr4fksHMQAAAMw"]
[Tue Jul 28 05:36:11.356099 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/chomu.php"] [unique_id "amgjq2zzpr4cNKr4fksHMQAAAMw"]
[Tue Jul 28 05:36:11.356209 2026] [:error] [pid 28027:tid 139944571913984] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/chomu.php"] [unique_id "amgjq2zzpr4cNKr4fksHMQAAAMw"]
[Tue Jul 28 05:36:11.391886 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-good.php"] [unique_id "amgjq2zzpr4cNKr4fksHMgAAANM"]
[Tue Jul 28 05:36:11.392716 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-good.php"] [unique_id "amgjq2zzpr4cNKr4fksHMgAAANM"]
[Tue Jul 28 05:36:11.393100 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-good.php"] [unique_id "amgjq2zzpr4cNKr4fksHMgAAANM"]
[Tue Jul 28 05:36:11.393183 2026] [:error] [pid 28027:tid 139944513165056] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-good.php"] [unique_id "amgjq2zzpr4cNKr4fksHMgAAANM"]
[Tue Jul 28 05:36:11.452667 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes//jvc.php"] [unique_id "amgjq2zzpr4cNKr4fksHNQAAAMA"]
[Tue Jul 28 05:36:11.453361 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/jvc.php"] [unique_id "amgjq2zzpr4cNKr4fksHNQAAAMA"]
[Tue Jul 28 05:36:11.466028 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/jvc.php"] [unique_id "amgjq2zzpr4cNKr4fksHNQAAAMA"]
[Tue Jul 28 05:36:11.466172 2026] [:error] [pid 28027:tid 139944747431680] [client 172.70.216.82:13774] [client 172.70.216.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/jvc.php"] [unique_id "amgjq2zzpr4cNKr4fksHNQAAAMA"]
[Tue Jul 28 05:38:42.154959 2026] [:error] [pid 711:tid 139944588699392] [client 104.23.168.93:12112] [client 104.23.168.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amgkQrb3Hg56MtJU4vygRgAAAQo"]
[Tue Jul 28 05:38:42.155546 2026] [:error] [pid 711:tid 139944588699392] [client 104.23.168.93:12112] [client 104.23.168.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amgkQrb3Hg56MtJU4vygRgAAAQo"]
[Tue Jul 28 05:38:42.155874 2026] [:error] [pid 711:tid 139944588699392] [client 104.23.168.93:12112] [client 104.23.168.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amgkQrb3Hg56MtJU4vygRgAAAQo"]
[Tue Jul 28 05:38:42.156016 2026] [:error] [pid 711:tid 139944588699392] [client 104.23.168.93:12112] [client 104.23.168.93] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amgkQrb3Hg56MtJU4vygRgAAAQo"]
[Tue Jul 28 05:49:57.990243 2026] [:error] [pid 27702:tid 139944655841024] [client 172.68.130.154:13515] [client 172.68.130.154] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgm5Ym1AQFltHspB3l5GgAAAII"]
[Tue Jul 28 05:49:57.992167 2026] [:error] [pid 27702:tid 139944655841024] [client 172.68.130.154:13515] [client 172.68.130.154] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgm5Ym1AQFltHspB3l5GgAAAII"]
[Tue Jul 28 05:49:57.993240 2026] [:error] [pid 27702:tid 139944655841024] [client 172.68.130.154:13515] [client 172.68.130.154] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgm5Ym1AQFltHspB3l5GgAAAII"]
[Tue Jul 28 05:52:06.548101 2026] [:error] [pid 27697:tid 139944479594240] [client 172.68.130.150:11959] [client 172.68.130.150] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amgnZhkR7MhnM6j340acsAAAAFc"]
[Tue Jul 28 05:52:06.549014 2026] [:error] [pid 27697:tid 139944479594240] [client 172.68.130.150:11959] [client 172.68.130.150] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amgnZhkR7MhnM6j340acsAAAAFc"]
[Tue Jul 28 05:52:06.549588 2026] [:error] [pid 27697:tid 139944479594240] [client 172.68.130.150:11959] [client 172.68.130.150] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amgnZhkR7MhnM6j340acsAAAAFc"]
[Tue Jul 28 05:53:25.067827 2026] [:error] [pid 27697:tid 139944747431680] [client 104.23.168.5:13675] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgntRkR7MhnM6j340adHQAAAEA"]
[Tue Jul 28 05:53:25.068804 2026] [:error] [pid 27697:tid 139944747431680] [client 104.23.168.5:13675] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgntRkR7MhnM6j340adHQAAAEA"]
[Tue Jul 28 05:53:25.069392 2026] [:error] [pid 27697:tid 139944747431680] [client 104.23.168.5:13675] [client 104.23.168.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amgntRkR7MhnM6j340adHQAAAEA"]
[Tue Jul 28 06:10:28.231671 2026] [:error] [pid 14757:tid 140635617097472] [client 104.23.243.18:10748] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amgrtB8tpddNF-UrsIViRAAAAIM"]
[Tue Jul 28 06:10:28.232415 2026] [:error] [pid 14757:tid 140635617097472] [client 104.23.243.18:10748] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amgrtB8tpddNF-UrsIViRAAAAIM"]
[Tue Jul 28 06:10:28.232863 2026] [:error] [pid 14757:tid 140635617097472] [client 104.23.243.18:10748] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amgrtB8tpddNF-UrsIViRAAAAIM"]
[Tue Jul 28 06:10:28.642575 2026] [:error] [pid 14755:tid 140635583526656] [client 104.23.197.76:13699] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amgrtKf64wRy3HlU5UNwLwAAAAc"]
[Tue Jul 28 06:10:28.643252 2026] [:error] [pid 14755:tid 140635583526656] [client 104.23.197.76:13699] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amgrtKf64wRy3HlU5UNwLwAAAAc"]
[Tue Jul 28 06:10:28.643663 2026] [:error] [pid 14755:tid 140635583526656] [client 104.23.197.76:13699] [client 104.23.197.76] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amgrtKf64wRy3HlU5UNwLwAAAAc"]
[Tue Jul 28 06:26:37.119232 2026] [:error] [pid 14859:tid 140635474421504] [client 172.70.248.40:13256] [client 172.70.248.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amgvfbBlXBlS8_TwuUZ7rgAAANQ"]
[Tue Jul 28 06:26:37.120292 2026] [:error] [pid 14859:tid 140635474421504] [client 172.70.248.40:13256] [client 172.70.248.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amgvfbBlXBlS8_TwuUZ7rgAAANQ"]
[Tue Jul 28 06:26:37.120933 2026] [:error] [pid 14859:tid 140635474421504] [client 172.70.248.40:13256] [client 172.70.248.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amgvfbBlXBlS8_TwuUZ7rgAAANQ"]
[Tue Jul 28 07:01:26.668076 2026] [:error] [pid 14859:tid 140635591919360] [client 104.23.197.77:10596] [client 104.23.197.77] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amg3prBlXBlS8_TwuUaXEAAAAMY"]
[Tue Jul 28 07:01:26.677633 2026] [:error] [pid 14859:tid 140635591919360] [client 104.23.197.77:10596] [client 104.23.197.77] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amg3prBlXBlS8_TwuUaXEAAAAMY"]
[Tue Jul 28 07:01:26.678153 2026] [:error] [pid 14859:tid 140635591919360] [client 104.23.197.77:10596] [client 104.23.197.77] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amg3prBlXBlS8_TwuUaXEAAAAMY"]
[Tue Jul 28 07:14:02.332178 2026] [:error] [pid 14756:tid 140635698231040] [client 172.71.182.87:11011] [client 172.71.182.87] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amg6mpQnCSs8VI2YeM_ceAAAAEI"]
[Tue Jul 28 07:14:02.333049 2026] [:error] [pid 14756:tid 140635698231040] [client 172.71.182.87:11011] [client 172.71.182.87] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amg6mpQnCSs8VI2YeM_ceAAAAEI"]
[Tue Jul 28 07:14:02.333596 2026] [:error] [pid 14756:tid 140635698231040] [client 172.71.182.87:11011] [client 172.71.182.87] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amg6mpQnCSs8VI2YeM_ceAAAAEI"]
[Tue Jul 28 07:47:39.858669 2026] [:error] [pid 23518:tid 140635449243392] [client 172.68.245.4:13412] [client 172.68.245.4] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhCewOqbX7Z9ycSlCLZQAAAARc"]
[Tue Jul 28 07:47:39.866627 2026] [:error] [pid 23518:tid 140635449243392] [client 172.68.245.4:13412] [client 172.68.245.4] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhCewOqbX7Z9ycSlCLZQAAAARc"]
[Tue Jul 28 07:47:39.867297 2026] [:error] [pid 23518:tid 140635449243392] [client 172.68.245.4:13412] [client 172.68.245.4] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhCewOqbX7Z9ycSlCLZQAAAARc"]
[Tue Jul 28 07:59:56.743411 2026] [:error] [pid 11209:tid 140635466028800] [client 104.23.172.15:9227] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhFXJIwGwWJ8iALx6J-iwAAAVU"]
[Tue Jul 28 07:59:56.744480 2026] [:error] [pid 11209:tid 140635466028800] [client 104.23.172.15:9227] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhFXJIwGwWJ8iALx6J-iwAAAVU"]
[Tue Jul 28 07:59:56.745012 2026] [:error] [pid 11209:tid 140635466028800] [client 104.23.172.15:9227] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhFXJIwGwWJ8iALx6J-iwAAAVU"]
[Tue Jul 28 08:00:04.866245 2026] [:error] [pid 11209:tid 140635449243392] [client 104.23.172.24:12730] [client 104.23.172.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/1uxk9kckion4m1lgwv2h7egawb"] [unique_id "amhFZJIwGwWJ8iALx6J-sQAAAVc"]
[Tue Jul 28 08:00:04.867199 2026] [:error] [pid 11209:tid 140635449243392] [client 104.23.172.24:12730] [client 104.23.172.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/1uxk9kckion4m1lgwv2h7egawb"] [unique_id "amhFZJIwGwWJ8iALx6J-sQAAAVc"]
[Tue Jul 28 08:00:04.867819 2026] [:error] [pid 11209:tid 140635449243392] [client 104.23.172.24:12730] [client 104.23.172.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/1uxk9kckion4m1lgwv2h7egawb"] [unique_id "amhFZJIwGwWJ8iALx6J-sQAAAVc"]
[Tue Jul 28 08:00:06.181816 2026] [:error] [pid 23518:tid 140635617097472] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/4fe3or6niaoy1hgbbtfrhbt55.html"] [unique_id "amhFZgOqbX7Z9ycSlCLwlAAAAQM"]
[Tue Jul 28 08:00:06.182791 2026] [:error] [pid 23518:tid 140635617097472] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/4fe3or6niaoy1hgbbtfrhbt55.html"] [unique_id "amhFZgOqbX7Z9ycSlCLwlAAAAQM"]
[Tue Jul 28 08:00:06.183293 2026] [:error] [pid 23518:tid 140635617097472] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/4fe3or6niaoy1hgbbtfrhbt55.html"] [unique_id "amhFZgOqbX7Z9ycSlCLwlAAAAQM"]
[Tue Jul 28 08:00:06.431916 2026] [:error] [pid 11209:tid 140635549955840] [client 172.64.217.182:11758] [client 172.64.217.182] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amhFZpIwGwWJ8iALx6J-uAAAAUs"]
[Tue Jul 28 08:00:06.432938 2026] [:error] [pid 11209:tid 140635549955840] [client 172.64.217.182:11758] [client 172.64.217.182] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amhFZpIwGwWJ8iALx6J-uAAAAUs"]
[Tue Jul 28 08:00:06.433483 2026] [:error] [pid 11209:tid 140635549955840] [client 172.64.217.182:11758] [client 172.64.217.182] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amhFZpIwGwWJ8iALx6J-uAAAAUs"]
[Tue Jul 28 08:00:07.366772 2026] [:error] [pid 14859:tid 140635449243392] [client 172.64.217.78:9683] [client 172.64.217.78] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/"] [unique_id "amhFZ7BlXBlS8_TwuUbFRQAAANc"]
[Tue Jul 28 08:00:07.367603 2026] [:error] [pid 14859:tid 140635449243392] [client 172.64.217.78:9683] [client 172.64.217.78] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/"] [unique_id "amhFZ7BlXBlS8_TwuUbFRQAAANc"]
[Tue Jul 28 08:00:07.368058 2026] [:error] [pid 14859:tid 140635449243392] [client 172.64.217.78:9683] [client 172.64.217.78] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/"] [unique_id "amhFZ7BlXBlS8_TwuUbFRQAAANc"]
[Tue Jul 28 08:00:07.768380 2026] [:error] [pid 11209:tid 140635541563136] [client 172.64.217.182:11758] [client 172.64.217.182] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhFZ5IwGwWJ8iALx6J-vwAAAUw"]
[Tue Jul 28 08:00:07.769123 2026] [:error] [pid 11209:tid 140635541563136] [client 172.64.217.182:11758] [client 172.64.217.182] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhFZ5IwGwWJ8iALx6J-vwAAAUw"]
[Tue Jul 28 08:00:07.769538 2026] [:error] [pid 11209:tid 140635541563136] [client 172.64.217.182:11758] [client 172.64.217.182] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhFZ5IwGwWJ8iALx6J-vwAAAUw"]
[Tue Jul 28 08:00:08.171438 2026] [:error] [pid 14859:tid 140635617097472] [client 172.64.217.78:9683] [client 172.64.217.78] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhFaLBlXBlS8_TwuUbFRwAAAMM"]
[Tue Jul 28 08:00:08.172108 2026] [:error] [pid 14859:tid 140635617097472] [client 172.64.217.78:9683] [client 172.64.217.78] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhFaLBlXBlS8_TwuUbFRwAAAMM"]
[Tue Jul 28 08:00:08.172523 2026] [:error] [pid 14859:tid 140635617097472] [client 172.64.217.78:9683] [client 172.64.217.78] ModSecurity: Warning. Found 3 byte(s) in ARGS:rest_route outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:rest_route=/wp/v2/users"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhFaLBlXBlS8_TwuUbFRwAAAMM"]
[Tue Jul 28 08:00:08.172596 2026] [:error] [pid 14859:tid 140635617097472] [client 172.64.217.78:9683] [client 172.64.217.78] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhFaLBlXBlS8_TwuUbFRwAAAMM"]
[Tue Jul 28 08:00:08.523161 2026] [:error] [pid 14859:tid 140635440850688] [client 172.64.217.78:9683] [client 172.64.217.78] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/feed"] [unique_id "amhFaLBlXBlS8_TwuUbFSAAAANg"]
[Tue Jul 28 08:00:08.524002 2026] [:error] [pid 14859:tid 140635440850688] [client 172.64.217.78:9683] [client 172.64.217.78] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/feed"] [unique_id "amhFaLBlXBlS8_TwuUbFSAAAANg"]
[Tue Jul 28 08:00:08.524532 2026] [:error] [pid 14859:tid 140635440850688] [client 172.64.217.78:9683] [client 172.64.217.78] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/feed"] [unique_id "amhFaLBlXBlS8_TwuUbFSAAAANg"]
[Tue Jul 28 08:00:09.873258 2026] [:error] [pid 23518:tid 140635566741248] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/9oow09a4get5avxk8h0uq4mw.php"] [unique_id "amhFaQOqbX7Z9ycSlCLwsgAAAQk"]
[Tue Jul 28 08:00:09.874030 2026] [:error] [pid 23518:tid 140635566741248] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/9oow09a4get5avxk8h0uq4mw.php"] [unique_id "amhFaQOqbX7Z9ycSlCLwsgAAAQk"]
[Tue Jul 28 08:00:09.874501 2026] [:error] [pid 23518:tid 140635566741248] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/9oow09a4get5avxk8h0uq4mw.php"] [unique_id "amhFaQOqbX7Z9ycSlCLwsgAAAQk"]
[Tue Jul 28 08:00:11.898128 2026] [:error] [pid 23518:tid 140635541563136] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/WEB-INF/web.xml"] [unique_id "amhFawOqbX7Z9ycSlCLw-AAAAQw"]
[Tue Jul 28 08:00:11.898818 2026] [:error] [pid 23518:tid 140635541563136] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/WEB-INF/web.xml"] [unique_id "amhFawOqbX7Z9ycSlCLw-AAAAQw"]
[Tue Jul 28 08:00:11.899463 2026] [:error] [pid 23518:tid 140635541563136] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/WEB-INF/web.xml"] [unique_id "amhFawOqbX7Z9ycSlCLw-AAAAQw"]
[Tue Jul 28 08:00:11.928296 2026] [:error] [pid 11209:tid 140635541563136] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhFa5IwGwWJ8iALx6J-zAAAAUw"]
[Tue Jul 28 08:00:11.928935 2026] [:error] [pid 11209:tid 140635541563136] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhFa5IwGwWJ8iALx6J-zAAAAUw"]
[Tue Jul 28 08:00:11.929293 2026] [:error] [pid 11209:tid 140635541563136] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhFa5IwGwWJ8iALx6J-zAAAAUw"]
[Tue Jul 28 08:00:11.929431 2026] [:error] [pid 11209:tid 140635541563136] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhFa5IwGwWJ8iALx6J-zAAAAUw"]
[Tue Jul 28 08:00:11.953689 2026] [:error] [pid 23518:tid 140635524777728] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amhFawOqbX7Z9ycSlCLw_AAAAQ4"]
[Tue Jul 28 08:00:11.954683 2026] [:error] [pid 23518:tid 140635524777728] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amhFawOqbX7Z9ycSlCLw_AAAAQ4"]
[Tue Jul 28 08:00:11.955157 2026] [:error] [pid 23518:tid 140635524777728] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amhFawOqbX7Z9ycSlCLw_AAAAQ4"]
[Tue Jul 28 08:00:11.955400 2026] [:error] [pid 23518:tid 140635524777728] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amhFawOqbX7Z9ycSlCLw_AAAAQ4"]
[Tue Jul 28 08:00:15.674798 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amhFbwOqbX7Z9ycSlCLxgwAAAQU"]
[Tue Jul 28 08:00:15.675654 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amhFbwOqbX7Z9ycSlCLxgwAAAQU"]
[Tue Jul 28 08:00:15.676128 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amhFbwOqbX7Z9ycSlCLxgwAAAQU"]
[Tue Jul 28 08:00:15.676361 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amhFbwOqbX7Z9ycSlCLxgwAAAQU"]
[Tue Jul 28 08:00:15.693673 2026] [:error] [pid 11209:tid 140635698231040] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.gitlab-ci.yml"] [unique_id "amhFb5IwGwWJ8iALx6J-2QAAAUI"]
[Tue Jul 28 08:00:15.694587 2026] [:error] [pid 11209:tid 140635698231040] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.gitlab-ci.yml"] [unique_id "amhFb5IwGwWJ8iALx6J-2QAAAUI"]
[Tue Jul 28 08:00:15.695091 2026] [:error] [pid 11209:tid 140635698231040] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.gitlab-ci.yml"] [unique_id "amhFb5IwGwWJ8iALx6J-2QAAAUI"]
[Tue Jul 28 08:00:15.695369 2026] [:error] [pid 11209:tid 140635698231040] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.gitlab-ci.yml"] [unique_id "amhFb5IwGwWJ8iALx6J-2QAAAUI"]
[Tue Jul 28 08:00:15.734051 2026] [:error] [pid 23518:tid 140635449243392] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/deploy.sh"] [unique_id "amhFbwOqbX7Z9ycSlCLxhQAAARc"]
[Tue Jul 28 08:00:15.734974 2026] [:error] [pid 23518:tid 140635449243392] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/deploy.sh"] [unique_id "amhFbwOqbX7Z9ycSlCLxhQAAARc"]
[Tue Jul 28 08:00:15.735474 2026] [:error] [pid 23518:tid 140635449243392] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/deploy.sh"] [unique_id "amhFbwOqbX7Z9ycSlCLxhQAAARc"]
[Tue Jul 28 08:00:16.386832 2026] [:error] [pid 11209:tid 140635533170432] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/framework/.env"] [unique_id "amhFcJIwGwWJ8iALx6J-3AAAAU0"]
[Tue Jul 28 08:00:16.386859 2026] [:error] [pid 23518:tid 140635558348544] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/source/.env"] [unique_id "amhFcAOqbX7Z9ycSlCLxigAAAQo"]
[Tue Jul 28 08:00:16.387515 2026] [:error] [pid 11209:tid 140635533170432] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/framework/.env"] [unique_id "amhFcJIwGwWJ8iALx6J-3AAAAU0"]
[Tue Jul 28 08:00:16.387616 2026] [:error] [pid 23518:tid 140635558348544] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/source/.env"] [unique_id "amhFcAOqbX7Z9ycSlCLxigAAAQo"]
[Tue Jul 28 08:00:16.387868 2026] [:error] [pid 11209:tid 140635533170432] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/framework/.env"] [unique_id "amhFcJIwGwWJ8iALx6J-3AAAAU0"]
[Tue Jul 28 08:00:16.388040 2026] [:error] [pid 23518:tid 140635558348544] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/source/.env"] [unique_id "amhFcAOqbX7Z9ycSlCLxigAAAQo"]
[Tue Jul 28 08:00:16.388060 2026] [:error] [pid 11209:tid 140635533170432] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /framework/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/framework/.env"] [unique_id "amhFcJIwGwWJ8iALx6J-3AAAAU0"]
[Tue Jul 28 08:00:16.388263 2026] [:error] [pid 23518:tid 140635558348544] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /source/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/source/.env"] [unique_id "amhFcAOqbX7Z9ycSlCLxigAAAQo"]
[Tue Jul 28 08:00:16.390309 2026] [:error] [pid 23518:tid 140635524777728] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.env"] [unique_id "amhFcAOqbX7Z9ycSlCLxiwAAAQ4"]
[Tue Jul 28 08:00:16.391097 2026] [:error] [pid 23518:tid 140635524777728] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.env"] [unique_id "amhFcAOqbX7Z9ycSlCLxiwAAAQ4"]
[Tue Jul 28 08:00:16.391601 2026] [:error] [pid 23518:tid 140635524777728] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.env"] [unique_id "amhFcAOqbX7Z9ycSlCLxiwAAAQ4"]
[Tue Jul 28 08:00:17.050516 2026] [:error] [pid 11209:tid 140635499599616] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/ikiwiki/.env"] [unique_id "amhFcZIwGwWJ8iALx6J-3gAAAVE"]
[Tue Jul 28 08:00:17.051197 2026] [:error] [pid 11209:tid 140635499599616] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/ikiwiki/.env"] [unique_id "amhFcZIwGwWJ8iALx6J-3gAAAVE"]
[Tue Jul 28 08:00:17.051568 2026] [:error] [pid 11209:tid 140635499599616] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/ikiwiki/.env"] [unique_id "amhFcZIwGwWJ8iALx6J-3gAAAVE"]
[Tue Jul 28 08:00:17.051717 2026] [:error] [pid 11209:tid 140635499599616] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /ikiwiki/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/ikiwiki/.env"] [unique_id "amhFcZIwGwWJ8iALx6J-3gAAAVE"]
[Tue Jul 28 08:00:17.052136 2026] [:error] [pid 23518:tid 140635583526656] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.inc.php"] [unique_id "amhFcQOqbX7Z9ycSlCLxjwAAAQc"]
[Tue Jul 28 08:00:17.053070 2026] [:error] [pid 23518:tid 140635583526656] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.inc.php"] [unique_id "amhFcQOqbX7Z9ycSlCLxjwAAAQc"]
[Tue Jul 28 08:00:17.053080 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/system/.env"] [unique_id "amhFcQOqbX7Z9ycSlCLxkAAAAQU"]
[Tue Jul 28 08:00:17.053639 2026] [:error] [pid 23518:tid 140635583526656] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.inc.php"] [unique_id "amhFcQOqbX7Z9ycSlCLxjwAAAQc"]
[Tue Jul 28 08:00:17.053987 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/system/.env"] [unique_id "amhFcQOqbX7Z9ycSlCLxkAAAAQU"]
[Tue Jul 28 08:00:17.054490 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/system/.env"] [unique_id "amhFcQOqbX7Z9ycSlCLxkAAAAQU"]
[Tue Jul 28 08:00:17.054752 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /system/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/system/.env"] [unique_id "amhFcQOqbX7Z9ycSlCLxkAAAAQU"]
[Tue Jul 28 08:00:17.731498 2026] [:error] [pid 11209:tid 140635457636096] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/test/"] [unique_id "amhFcZIwGwWJ8iALx6J-5AAAAVY"]
[Tue Jul 28 08:00:17.731800 2026] [:error] [pid 23518:tid 140635558348544] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amhFcQOqbX7Z9ycSlCLxlQAAAQo"]
[Tue Jul 28 08:00:17.732129 2026] [:error] [pid 11209:tid 140635457636096] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/test/"] [unique_id "amhFcZIwGwWJ8iALx6J-5AAAAVY"]
[Tue Jul 28 08:00:17.732323 2026] [:error] [pid 23518:tid 140635558348544] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amhFcQOqbX7Z9ycSlCLxlQAAAQo"]
[Tue Jul 28 08:00:17.732545 2026] [:error] [pid 11209:tid 140635457636096] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/test/"] [unique_id "amhFcZIwGwWJ8iALx6J-5AAAAVY"]
[Tue Jul 28 08:00:17.732700 2026] [:error] [pid 23518:tid 140635558348544] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amhFcQOqbX7Z9ycSlCLxlQAAAQo"]
[Tue Jul 28 08:00:17.732891 2026] [:error] [pid 23518:tid 140635558348544] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amhFcQOqbX7Z9ycSlCLxlQAAAQo"]
[Tue Jul 28 08:00:19.564828 2026] [:error] [pid 23518:tid 140635457636096] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amhFcwOqbX7Z9ycSlCLxoQAAARY"]
[Tue Jul 28 08:00:19.565430 2026] [:error] [pid 23518:tid 140635457636096] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amhFcwOqbX7Z9ycSlCLxoQAAARY"]
[Tue Jul 28 08:00:19.565870 2026] [:error] [pid 23518:tid 140635457636096] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amhFcwOqbX7Z9ycSlCLxoQAAARY"]
[Tue Jul 28 08:00:19.566076 2026] [:error] [pid 23518:tid 140635457636096] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amhFcwOqbX7Z9ycSlCLxoQAAARY"]
[Tue Jul 28 08:00:19.848121 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "amhFc5IwGwWJ8iALx6J-6QAAAUA"]
[Tue Jul 28 08:00:19.848940 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "amhFc5IwGwWJ8iALx6J-6QAAAUA"]
[Tue Jul 28 08:00:19.849357 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in ARGS:file outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:file=app/config/parameters.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "amhFc5IwGwWJ8iALx6J-6QAAAUA"]
[Tue Jul 28 08:00:19.849417 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "amhFc5IwGwWJ8iALx6J-6QAAAUA"]
[Tue Jul 28 08:00:19.849714 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Matched phrase "parameters.yml" at ARGS:file. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "97"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: parameters.yml found within ARGS:file: app/config/parameters.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "amhFc5IwGwWJ8iALx6J-6QAAAUA"]
[Tue Jul 28 08:00:19.857500 2026] [:error] [pid 23518:tid 140635516385024] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/wp-content/mysql.sql"] [unique_id "amhFcwOqbX7Z9ycSlCLxpwAAAQ8"]
[Tue Jul 28 08:00:19.858642 2026] [:error] [pid 23518:tid 140635516385024] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/wp-content/mysql.sql"] [unique_id "amhFcwOqbX7Z9ycSlCLxpwAAAQ8"]
[Tue Jul 28 08:00:19.859204 2026] [:error] [pid 23518:tid 140635516385024] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/wp-content/mysql.sql"] [unique_id "amhFcwOqbX7Z9ycSlCLxpwAAAQ8"]
[Tue Jul 28 08:00:20.280381 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhFdAOqbX7Z9ycSlCLxqQAAAQU"]
[Tue Jul 28 08:00:20.281294 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhFdAOqbX7Z9ycSlCLxqQAAAQU"]
[Tue Jul 28 08:00:20.281819 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhFdAOqbX7Z9ycSlCLxqQAAAQU"]
[Tue Jul 28 08:00:20.282017 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhFdAOqbX7Z9ycSlCLxqQAAAQU"]
[Tue Jul 28 08:00:20.694306 2026] [:error] [pid 23518:tid 140635617097472] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev.local"] [unique_id "amhFdAOqbX7Z9ycSlCLxrwAAAQM"]
[Tue Jul 28 08:00:20.695049 2026] [:error] [pid 23518:tid 140635617097472] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev.local"] [unique_id "amhFdAOqbX7Z9ycSlCLxrwAAAQM"]
[Tue Jul 28 08:00:20.695437 2026] [:error] [pid 23518:tid 140635617097472] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev.local"] [unique_id "amhFdAOqbX7Z9ycSlCLxrwAAAQM"]
[Tue Jul 28 08:00:20.695605 2026] [:error] [pid 23518:tid 140635617097472] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev.local"] [unique_id "amhFdAOqbX7Z9ycSlCLxrwAAAQM"]
[Tue Jul 28 08:00:20.701033 2026] [:error] [pid 11209:tid 140635566741248] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amhFdJIwGwWJ8iALx6J-7gAAAUk"]
[Tue Jul 28 08:00:20.701954 2026] [:error] [pid 11209:tid 140635566741248] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amhFdJIwGwWJ8iALx6J-7gAAAUk"]
[Tue Jul 28 08:00:20.702451 2026] [:error] [pid 11209:tid 140635566741248] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amhFdJIwGwWJ8iALx6J-7gAAAUk"]
[Tue Jul 28 08:00:21.496572 2026] [:error] [pid 23518:tid 140635583526656] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amhFdQOqbX7Z9ycSlCLxtwAAAQc"]
[Tue Jul 28 08:00:21.497149 2026] [:error] [pid 23518:tid 140635583526656] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amhFdQOqbX7Z9ycSlCLxtwAAAQc"]
[Tue Jul 28 08:00:21.497511 2026] [:error] [pid 23518:tid 140635583526656] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amhFdQOqbX7Z9ycSlCLxtwAAAQc"]
[Tue Jul 28 08:00:21.497661 2026] [:error] [pid 23518:tid 140635583526656] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amhFdQOqbX7Z9ycSlCLxtwAAAQc"]
[Tue Jul 28 08:00:24.597960 2026] [:error] [pid 23518:tid 140635541563136] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amhFeAOqbX7Z9ycSlCLxygAAAQw"]
[Tue Jul 28 08:00:24.599003 2026] [:error] [pid 23518:tid 140635541563136] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amhFeAOqbX7Z9ycSlCLxygAAAQw"]
[Tue Jul 28 08:00:24.599574 2026] [:error] [pid 23518:tid 140635541563136] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amhFeAOqbX7Z9ycSlCLxygAAAQw"]
[Tue Jul 28 08:00:24.599825 2026] [:error] [pid 23518:tid 140635541563136] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amhFeAOqbX7Z9ycSlCLxygAAAQw"]
[Tue Jul 28 08:00:24.744450 2026] [:error] [pid 11209:tid 140635608704768] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amhFeJIwGwWJ8iALx6J--QAAAUQ"]
[Tue Jul 28 08:00:24.745469 2026] [:error] [pid 11209:tid 140635608704768] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amhFeJIwGwWJ8iALx6J--QAAAUQ"]
[Tue Jul 28 08:00:24.749500 2026] [:error] [pid 11209:tid 140635608704768] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amhFeJIwGwWJ8iALx6J--QAAAUQ"]
[Tue Jul 28 08:00:24.855958 2026] [:error] [pid 23518:tid 140635583526656] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amhFeAOqbX7Z9ycSlCLxywAAAQc"]
[Tue Jul 28 08:00:24.856759 2026] [:error] [pid 23518:tid 140635583526656] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amhFeAOqbX7Z9ycSlCLxywAAAQc"]
[Tue Jul 28 08:00:24.857089 2026] [:error] [pid 23518:tid 140635583526656] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amhFeAOqbX7Z9ycSlCLxywAAAQc"]
[Tue Jul 28 08:00:24.954076 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amhFeAOqbX7Z9ycSlCLxzQAAAQU"]
[Tue Jul 28 08:00:24.955132 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amhFeAOqbX7Z9ycSlCLxzQAAAQU"]
[Tue Jul 28 08:00:24.955662 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amhFeAOqbX7Z9ycSlCLxzQAAAQU"]
[Tue Jul 28 08:00:24.955909 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amhFeAOqbX7Z9ycSlCLxzQAAAQU"]
[Tue Jul 28 08:00:25.241005 2026] [:error] [pid 11209:tid 140635549955840] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/info.txt"] [unique_id "amhFeZIwGwWJ8iALx6J--wAAAUs"]
[Tue Jul 28 08:00:25.241233 2026] [:error] [pid 23518:tid 140635591919360] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/env/.env"] [unique_id "amhFeQOqbX7Z9ycSlCLxzwAAAQY"]
[Tue Jul 28 08:00:25.241962 2026] [:error] [pid 11209:tid 140635549955840] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/info.txt"] [unique_id "amhFeZIwGwWJ8iALx6J--wAAAUs"]
[Tue Jul 28 08:00:25.241970 2026] [:error] [pid 23518:tid 140635591919360] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/env/.env"] [unique_id "amhFeQOqbX7Z9ycSlCLxzwAAAQY"]
[Tue Jul 28 08:00:25.242456 2026] [:error] [pid 23518:tid 140635591919360] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/env/.env"] [unique_id "amhFeQOqbX7Z9ycSlCLxzwAAAQY"]
[Tue Jul 28 08:00:25.242463 2026] [:error] [pid 11209:tid 140635549955840] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/info.txt"] [unique_id "amhFeZIwGwWJ8iALx6J--wAAAUs"]
[Tue Jul 28 08:00:25.242717 2026] [:error] [pid 23518:tid 140635591919360] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /env/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/env/.env"] [unique_id "amhFeQOqbX7Z9ycSlCLxzwAAAQY"]
[Tue Jul 28 08:00:26.709921 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amhFegOqbX7Z9ycSlCLx2QAAAQQ"]
[Tue Jul 28 08:00:26.709920 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amhFegOqbX7Z9ycSlCLx2AAAAQU"]
[Tue Jul 28 08:00:26.709921 2026] [:error] [pid 11209:tid 140635482814208] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amhFepIwGwWJ8iALx6J_AAAAAVM"]
[Tue Jul 28 08:00:26.710715 2026] [:error] [pid 11209:tid 140635482814208] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amhFepIwGwWJ8iALx6J_AAAAAVM"]
[Tue Jul 28 08:00:26.710719 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amhFegOqbX7Z9ycSlCLx2AAAAQU"]
[Tue Jul 28 08:00:26.710721 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amhFegOqbX7Z9ycSlCLx2QAAAQQ"]
[Tue Jul 28 08:00:26.711183 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amhFegOqbX7Z9ycSlCLx2QAAAQQ"]
[Tue Jul 28 08:00:26.711193 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amhFegOqbX7Z9ycSlCLx2AAAAQU"]
[Tue Jul 28 08:00:26.711193 2026] [:error] [pid 11209:tid 140635482814208] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.json"] [unique_id "amhFepIwGwWJ8iALx6J_AAAAAVM"]
[Tue Jul 28 08:00:26.711431 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_copy"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amhFegOqbX7Z9ycSlCLx2AAAAQU"]
[Tue Jul 28 08:00:26.711432 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amhFegOqbX7Z9ycSlCLx2QAAAQQ"]
[Tue Jul 28 08:00:29.478659 2026] [:error] [pid 11209:tid 140635457636096] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/env.example"] [unique_id "amhFfZIwGwWJ8iALx6J_BQAAAVY"]
[Tue Jul 28 08:00:29.478664 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config/app.php"] [unique_id "amhFfQOqbX7Z9ycSlCLx4gAAAQQ"]
[Tue Jul 28 08:00:29.478668 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amhFfQOqbX7Z9ycSlCLx4QAAAQU"]
[Tue Jul 28 08:00:29.479485 2026] [:error] [pid 11209:tid 140635457636096] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/env.example"] [unique_id "amhFfZIwGwWJ8iALx6J_BQAAAVY"]
[Tue Jul 28 08:00:29.479508 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amhFfQOqbX7Z9ycSlCLx4QAAAQU"]
[Tue Jul 28 08:00:29.479514 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config/app.php"] [unique_id "amhFfQOqbX7Z9ycSlCLx4gAAAQQ"]
[Tue Jul 28 08:00:29.479871 2026] [:error] [pid 11209:tid 140635457636096] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/env.example"] [unique_id "amhFfZIwGwWJ8iALx6J_BQAAAVY"]
[Tue Jul 28 08:00:29.479874 2026] [:error] [pid 23518:tid 140635600312064] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amhFfQOqbX7Z9ycSlCLx4QAAAQU"]
[Tue Jul 28 08:00:29.479944 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config/app.php"] [unique_id "amhFfQOqbX7Z9ycSlCLx4gAAAQQ"]
[Tue Jul 28 08:00:31.100361 2026] [:error] [pid 23518:tid 140635541563136] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amhFfwOqbX7Z9ycSlCLx7QAAAQw"]
[Tue Jul 28 08:00:31.101090 2026] [:error] [pid 23518:tid 140635541563136] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amhFfwOqbX7Z9ycSlCLx7QAAAQw"]
[Tue Jul 28 08:00:31.101441 2026] [:error] [pid 23518:tid 140635541563136] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amhFfwOqbX7Z9ycSlCLx7QAAAQw"]
[Tue Jul 28 08:00:31.101621 2026] [:error] [pid 23518:tid 140635541563136] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amhFfwOqbX7Z9ycSlCLx7QAAAQw"]
[Tue Jul 28 08:00:31.103432 2026] [:error] [pid 23518:tid 140635558348544] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php3"] [unique_id "amhFfwOqbX7Z9ycSlCLx7gAAAQo"]
[Tue Jul 28 08:00:31.103945 2026] [:error] [pid 23518:tid 140635558348544] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php3"] [unique_id "amhFfwOqbX7Z9ycSlCLx7gAAAQo"]
[Tue Jul 28 08:00:31.104294 2026] [:error] [pid 23518:tid 140635558348544] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php3"] [unique_id "amhFfwOqbX7Z9ycSlCLx7gAAAQo"]
[Tue Jul 28 08:00:31.110816 2026] [:error] [pid 11209:tid 140635482814208] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amhFf5IwGwWJ8iALx6J_DQAAAVM"]
[Tue Jul 28 08:00:31.111753 2026] [:error] [pid 11209:tid 140635482814208] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amhFf5IwGwWJ8iALx6J_DQAAAVM"]
[Tue Jul 28 08:00:31.112254 2026] [:error] [pid 11209:tid 140635482814208] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amhFf5IwGwWJ8iALx6J_DQAAAVM"]
[Tue Jul 28 08:00:31.112482 2026] [:error] [pid 11209:tid 140635482814208] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amhFf5IwGwWJ8iALx6J_DQAAAVM"]
[Tue Jul 28 08:00:31.869936 2026] [:error] [pid 11209:tid 140635698231040] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amhFf5IwGwWJ8iALx6J_EAAAAUI"]
[Tue Jul 28 08:00:31.870653 2026] [:error] [pid 11209:tid 140635698231040] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amhFf5IwGwWJ8iALx6J_EAAAAUI"]
[Tue Jul 28 08:00:31.871062 2026] [:error] [pid 11209:tid 140635698231040] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amhFf5IwGwWJ8iALx6J_EAAAAUI"]
[Tue Jul 28 08:00:31.871224 2026] [:error] [pid 11209:tid 140635698231040] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envrc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amhFf5IwGwWJ8iALx6J_EAAAAUI"]
[Tue Jul 28 08:00:31.876212 2026] [:error] [pid 23518:tid 140635591919360] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/env"] [unique_id "amhFfwOqbX7Z9ycSlCLx9QAAAQY"]
[Tue Jul 28 08:00:31.876217 2026] [:error] [pid 23518:tid 140635698231040] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.bashrc"] [unique_id "amhFfwOqbX7Z9ycSlCLx9gAAAQI"]
[Tue Jul 28 08:00:31.877157 2026] [:error] [pid 23518:tid 140635591919360] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/env"] [unique_id "amhFfwOqbX7Z9ycSlCLx9QAAAQY"]
[Tue Jul 28 08:00:31.877171 2026] [:error] [pid 23518:tid 140635698231040] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.bashrc"] [unique_id "amhFfwOqbX7Z9ycSlCLx9gAAAQI"]
[Tue Jul 28 08:00:31.877676 2026] [:error] [pid 23518:tid 140635591919360] [client 104.23.172.15:11339] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/env"] [unique_id "amhFfwOqbX7Z9ycSlCLx9QAAAQY"]
[Tue Jul 28 08:00:31.877691 2026] [:error] [pid 23518:tid 140635698231040] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.bashrc"] [unique_id "amhFfwOqbX7Z9ycSlCLx9gAAAQI"]
[Tue Jul 28 08:00:31.877927 2026] [:error] [pid 23518:tid 140635698231040] [client 104.23.172.15:11341] [client 104.23.172.15] ModSecurity: Warning. Matched phrase ".bashrc" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .bashrc found within REQUEST_FILENAME: /.bashrc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.bashrc"] [unique_id "amhFfwOqbX7Z9ycSlCLx9gAAAQI"]
[Tue Jul 28 08:00:33.662637 2026] [:error] [pid 11209:tid 140635516385024] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhFgZIwGwWJ8iALx6J_FAAAAU8"]
[Tue Jul 28 08:00:33.663317 2026] [:error] [pid 11209:tid 140635516385024] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhFgZIwGwWJ8iALx6J_FAAAAU8"]
[Tue Jul 28 08:00:33.663664 2026] [:error] [pid 11209:tid 140635516385024] [client 104.23.172.14:10290] [client 104.23.172.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhFgZIwGwWJ8iALx6J_FAAAAU8"]
[Tue Jul 28 08:10:14.161169 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.217.116:10447] [client 104.23.217.116] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amhHxgOqbX7Z9ycSlCICswAAAQQ"]
[Tue Jul 28 08:10:14.162226 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.217.116:10447] [client 104.23.217.116] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amhHxgOqbX7Z9ycSlCICswAAAQQ"]
[Tue Jul 28 08:10:14.162872 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.217.116:10447] [client 104.23.217.116] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amhHxgOqbX7Z9ycSlCICswAAAQQ"]
[Tue Jul 28 08:27:08.082324 2026] [:error] [pid 14859:tid 140635600312064] [client 172.68.164.94:13066] [client 172.68.164.94] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhLvLBlXBlS8_TwuUbT3QAAAMU"]
[Tue Jul 28 08:27:08.082956 2026] [:error] [pid 14859:tid 140635600312064] [client 172.68.164.94:13066] [client 172.68.164.94] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhLvLBlXBlS8_TwuUbT3QAAAMU"]
[Tue Jul 28 08:27:08.083338 2026] [:error] [pid 14859:tid 140635600312064] [client 172.68.164.94:13066] [client 172.68.164.94] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhLvLBlXBlS8_TwuUbT3QAAAMU"]
[Tue Jul 28 08:46:23.794749 2026] [:error] [pid 11209:tid 140635499599616] [client 104.23.243.19:12465] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amhQP5IwGwWJ8iALx6KtbgAAAVE"]
[Tue Jul 28 08:46:23.853597 2026] [:error] [pid 11209:tid 140635499599616] [client 104.23.243.19:12465] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amhQP5IwGwWJ8iALx6KtbgAAAVE"]
[Tue Jul 28 08:46:23.854155 2026] [:error] [pid 11209:tid 140635499599616] [client 104.23.243.19:12465] [client 104.23.243.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amhQP5IwGwWJ8iALx6KtbgAAAVE"]
[Tue Jul 28 09:05:35.848522 2026] [:error] [pid 14757:tid 140635617097472] [client 141.101.76.184:12963] [client 141.101.76.184] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhUvx8tpddNF-UrsIWyWAAAAIM"]
[Tue Jul 28 09:05:35.849461 2026] [:error] [pid 14757:tid 140635617097472] [client 141.101.76.184:12963] [client 141.101.76.184] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhUvx8tpddNF-UrsIWyWAAAAIM"]
[Tue Jul 28 09:05:35.850013 2026] [:error] [pid 14757:tid 140635617097472] [client 141.101.76.184:12963] [client 141.101.76.184] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhUvx8tpddNF-UrsIWyWAAAAIM"]
[Tue Jul 28 09:05:36.556758 2026] [:error] [pid 14757:tid 140635558348544] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amhUwB8tpddNF-UrsIWyWwAAAIo"]
[Tue Jul 28 09:05:36.557490 2026] [:error] [pid 14757:tid 140635558348544] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amhUwB8tpddNF-UrsIWyWwAAAIo"]
[Tue Jul 28 09:05:36.557794 2026] [:error] [pid 14757:tid 140635558348544] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amhUwB8tpddNF-UrsIWyWwAAAIo"]
[Tue Jul 28 09:05:36.557859 2026] [:error] [pid 14757:tid 140635558348544] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amhUwB8tpddNF-UrsIWyWwAAAIo"]
[Tue Jul 28 09:05:36.558008 2026] [:error] [pid 14757:tid 140635558348544] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amhUwB8tpddNF-UrsIWyWwAAAIo"]
[Tue Jul 28 09:05:36.660468 2026] [:error] [pid 11209:tid 140635466028800] [client 172.71.183.11:10734] [client 172.71.183.11] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.min.js"] [unique_id "amhUwJIwGwWJ8iALx6K9FwAAAVU"]
[Tue Jul 28 09:05:36.661287 2026] [:error] [pid 11209:tid 140635466028800] [client 172.71.183.11:10734] [client 172.71.183.11] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.min.js"] [unique_id "amhUwJIwGwWJ8iALx6K9FwAAAVU"]
[Tue Jul 28 09:05:36.661794 2026] [:error] [pid 11209:tid 140635466028800] [client 172.71.183.11:10734] [client 172.71.183.11] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.min.js"] [unique_id "amhUwJIwGwWJ8iALx6K9FwAAAVU"]
[Tue Jul 28 09:05:36.933668 2026] [:error] [pid 14757:tid 140635608704768] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/%2eenv"] [unique_id "amhUwB8tpddNF-UrsIWyXQAAAIQ"]
[Tue Jul 28 09:05:36.934567 2026] [:error] [pid 14757:tid 140635608704768] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amhUwB8tpddNF-UrsIWyXQAAAIQ"]
[Tue Jul 28 09:05:36.934996 2026] [:error] [pid 14757:tid 140635608704768] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amhUwB8tpddNF-UrsIWyXQAAAIQ"]
[Tue Jul 28 09:05:36.935095 2026] [:error] [pid 14757:tid 140635608704768] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amhUwB8tpddNF-UrsIWyXQAAAIQ"]
[Tue Jul 28 09:05:36.935316 2026] [:error] [pid 14757:tid 140635608704768] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amhUwB8tpddNF-UrsIWyXQAAAIQ"]
[Tue Jul 28 09:05:37.233066 2026] [:error] [pid 14757:tid 140635516385024] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/%2f%2eenv"] [unique_id "amhUwR8tpddNF-UrsIWyXgAAAI8"]
[Tue Jul 28 09:05:37.298445 2026] [:error] [pid 14757:tid 140635449243392] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhUwR8tpddNF-UrsIWyXwAAAJc"]
[Tue Jul 28 09:05:37.299227 2026] [:error] [pid 14757:tid 140635449243392] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhUwR8tpddNF-UrsIWyXwAAAJc"]
[Tue Jul 28 09:05:37.299706 2026] [:error] [pid 14757:tid 140635449243392] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhUwR8tpddNF-UrsIWyXwAAAJc"]
[Tue Jul 28 09:05:37.299823 2026] [:error] [pid 14757:tid 140635449243392] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhUwR8tpddNF-UrsIWyXwAAAJc"]
[Tue Jul 28 09:05:37.607645 2026] [:error] [pid 14757:tid 140635482814208] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amhUwR8tpddNF-UrsIWyYAAAAJM"]
[Tue Jul 28 09:05:37.608493 2026] [:error] [pid 14757:tid 140635482814208] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amhUwR8tpddNF-UrsIWyYAAAAJM"]
[Tue Jul 28 09:05:37.608989 2026] [:error] [pid 14757:tid 140635482814208] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amhUwR8tpddNF-UrsIWyYAAAAJM"]
[Tue Jul 28 09:05:37.609289 2026] [:error] [pid 14757:tid 140635482814208] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amhUwR8tpddNF-UrsIWyYAAAAJM"]
[Tue Jul 28 09:05:37.866348 2026] [:error] [pid 14757:tid 140635466028800] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhUwR8tpddNF-UrsIWyYgAAAJU"]
[Tue Jul 28 09:05:37.867353 2026] [:error] [pid 14757:tid 140635466028800] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhUwR8tpddNF-UrsIWyYgAAAJU"]
[Tue Jul 28 09:05:37.867887 2026] [:error] [pid 14757:tid 140635466028800] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhUwR8tpddNF-UrsIWyYgAAAJU"]
[Tue Jul 28 09:05:37.868122 2026] [:error] [pid 14757:tid 140635466028800] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhUwR8tpddNF-UrsIWyYgAAAJU"]
[Tue Jul 28 09:05:38.393785 2026] [:error] [pid 14757:tid 140635583526656] [client 141.101.76.184:12963] [client 141.101.76.184] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amhUwh8tpddNF-UrsIWyYwAAAIc"]
[Tue Jul 28 09:05:38.394462 2026] [:error] [pid 14757:tid 140635583526656] [client 141.101.76.184:12963] [client 141.101.76.184] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amhUwh8tpddNF-UrsIWyYwAAAIc"]
[Tue Jul 28 09:05:38.394895 2026] [:error] [pid 14757:tid 140635583526656] [client 141.101.76.184:12963] [client 141.101.76.184] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amhUwh8tpddNF-UrsIWyYwAAAIc"]
[Tue Jul 28 09:05:38.395104 2026] [:error] [pid 14757:tid 140635583526656] [client 141.101.76.184:12963] [client 141.101.76.184] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amhUwh8tpddNF-UrsIWyYwAAAIc"]
[Tue Jul 28 09:05:38.755335 2026] [:error] [pid 14757:tid 140635591919360] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/aws-ses.json"] [unique_id "amhUwh8tpddNF-UrsIWyZgAAAIY"]
[Tue Jul 28 09:05:38.755951 2026] [:error] [pid 14757:tid 140635591919360] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/aws-ses.json"] [unique_id "amhUwh8tpddNF-UrsIWyZgAAAIY"]
[Tue Jul 28 09:05:38.775911 2026] [:error] [pid 14757:tid 140635591919360] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/aws-ses.json"] [unique_id "amhUwh8tpddNF-UrsIWyZgAAAIY"]
[Tue Jul 28 09:05:39.140684 2026] [:error] [pid 14757:tid 140635566741248] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.stripe/"] [unique_id "amhUwx8tpddNF-UrsIWyZwAAAIk"]
[Tue Jul 28 09:05:39.141581 2026] [:error] [pid 14757:tid 140635566741248] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.stripe/"] [unique_id "amhUwx8tpddNF-UrsIWyZwAAAIk"]
[Tue Jul 28 09:05:39.142038 2026] [:error] [pid 14757:tid 140635566741248] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.stripe/"] [unique_id "amhUwx8tpddNF-UrsIWyZwAAAIk"]
[Tue Jul 28 09:05:39.480112 2026] [:error] [pid 14757:tid 140635507992320] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/stripe/.env"] [unique_id "amhUwx8tpddNF-UrsIWyaAAAAJA"]
[Tue Jul 28 09:05:39.481056 2026] [:error] [pid 14757:tid 140635507992320] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/stripe/.env"] [unique_id "amhUwx8tpddNF-UrsIWyaAAAAJA"]
[Tue Jul 28 09:05:39.482767 2026] [:error] [pid 14757:tid 140635507992320] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/stripe/.env"] [unique_id "amhUwx8tpddNF-UrsIWyaAAAAJA"]
[Tue Jul 28 09:05:39.482958 2026] [:error] [pid 14757:tid 140635507992320] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /stripe/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/stripe/.env"] [unique_id "amhUwx8tpddNF-UrsIWyaAAAAJA"]
[Tue Jul 28 09:05:39.802971 2026] [:error] [pid 14757:tid 140635617097472] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.aws"] [unique_id "amhUwx8tpddNF-UrsIWyagAAAIM"]
[Tue Jul 28 09:05:39.803947 2026] [:error] [pid 14757:tid 140635617097472] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.aws"] [unique_id "amhUwx8tpddNF-UrsIWyagAAAIM"]
[Tue Jul 28 09:05:39.804404 2026] [:error] [pid 14757:tid 140635617097472] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.env.aws"] [unique_id "amhUwx8tpddNF-UrsIWyagAAAIM"]
[Tue Jul 28 09:05:39.804544 2026] [:error] [pid 14757:tid 140635617097472] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.aws"] [unique_id "amhUwx8tpddNF-UrsIWyagAAAIM"]
[Tue Jul 28 09:05:39.804783 2026] [:error] [pid 14757:tid 140635617097472] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.aws"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.aws"] [unique_id "amhUwx8tpddNF-UrsIWyagAAAIM"]
[Tue Jul 28 09:05:40.167734 2026] [:error] [pid 14757:tid 140635524777728] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amhUxB8tpddNF-UrsIWybAAAAI4"]
[Tue Jul 28 09:05:40.168543 2026] [:error] [pid 14757:tid 140635524777728] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amhUxB8tpddNF-UrsIWybAAAAI4"]
[Tue Jul 28 09:05:40.169033 2026] [:error] [pid 14757:tid 140635524777728] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amhUxB8tpddNF-UrsIWybAAAAI4"]
[Tue Jul 28 09:05:40.169271 2026] [:error] [pid 14757:tid 140635524777728] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amhUxB8tpddNF-UrsIWybAAAAI4"]
[Tue Jul 28 09:05:40.561596 2026] [:error] [pid 14757:tid 140635706623744] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amhUxB8tpddNF-UrsIWybQAAAIE"]
[Tue Jul 28 09:05:40.562383 2026] [:error] [pid 14757:tid 140635706623744] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amhUxB8tpddNF-UrsIWybQAAAIE"]
[Tue Jul 28 09:05:40.562883 2026] [:error] [pid 14757:tid 140635706623744] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amhUxB8tpddNF-UrsIWybQAAAIE"]
[Tue Jul 28 09:05:40.563117 2026] [:error] [pid 14757:tid 140635706623744] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amhUxB8tpddNF-UrsIWybQAAAIE"]
[Tue Jul 28 09:05:41.778617 2026] [:error] [pid 14757:tid 140635549955840] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhUxR8tpddNF-UrsIWybwAAAIs"]
[Tue Jul 28 09:05:41.779397 2026] [:error] [pid 14757:tid 140635549955840] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhUxR8tpddNF-UrsIWybwAAAIs"]
[Tue Jul 28 09:05:41.779876 2026] [:error] [pid 14757:tid 140635549955840] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhUxR8tpddNF-UrsIWybwAAAIs"]
[Tue Jul 28 09:05:41.780097 2026] [:error] [pid 14757:tid 140635549955840] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhUxR8tpddNF-UrsIWybwAAAIs"]
[Tue Jul 28 09:05:42.309375 2026] [:error] [pid 14757:tid 140635516385024] [client 141.101.76.184:12963] [client 141.101.76.184] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/test.php"] [unique_id "amhUxh8tpddNF-UrsIWycQAAAI8"]
[Tue Jul 28 09:05:42.310124 2026] [:error] [pid 14757:tid 140635516385024] [client 141.101.76.184:12963] [client 141.101.76.184] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/test.php"] [unique_id "amhUxh8tpddNF-UrsIWycQAAAI8"]
[Tue Jul 28 09:05:42.310470 2026] [:error] [pid 14757:tid 140635516385024] [client 141.101.76.184:12963] [client 141.101.76.184] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/test.php"] [unique_id "amhUxh8tpddNF-UrsIWycQAAAI8"]
[Tue Jul 28 09:05:42.811447 2026] [:error] [pid 14757:tid 140635449243392] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amhUxh8tpddNF-UrsIWycgAAAJc"]
[Tue Jul 28 09:05:42.812330 2026] [:error] [pid 14757:tid 140635449243392] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amhUxh8tpddNF-UrsIWycgAAAJc"]
[Tue Jul 28 09:05:42.812797 2026] [:error] [pid 14757:tid 140635449243392] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amhUxh8tpddNF-UrsIWycgAAAJc"]
[Tue Jul 28 09:05:42.812908 2026] [:error] [pid 14757:tid 140635449243392] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amhUxh8tpddNF-UrsIWycgAAAJc"]
[Tue Jul 28 09:05:42.813136 2026] [:error] [pid 14757:tid 140635449243392] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amhUxh8tpddNF-UrsIWycgAAAJc"]
[Tue Jul 28 09:05:44.133326 2026] [:error] [pid 14757:tid 140635583526656] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amhUyB8tpddNF-UrsIWydgAAAIc"]
[Tue Jul 28 09:05:44.133850 2026] [:error] [pid 14757:tid 140635583526656] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amhUyB8tpddNF-UrsIWydgAAAIc"]
[Tue Jul 28 09:05:44.134208 2026] [:error] [pid 14757:tid 140635583526656] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amhUyB8tpddNF-UrsIWydgAAAIc"]
[Tue Jul 28 09:05:44.134336 2026] [:error] [pid 14757:tid 140635583526656] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amhUyB8tpddNF-UrsIWydgAAAIc"]
[Tue Jul 28 09:05:44.351630 2026] [:error] [pid 14757:tid 140635591919360] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amhUyB8tpddNF-UrsIWydwAAAIY"]
[Tue Jul 28 09:05:44.352457 2026] [:error] [pid 14757:tid 140635591919360] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amhUyB8tpddNF-UrsIWydwAAAIY"]
[Tue Jul 28 09:05:44.352925 2026] [:error] [pid 14757:tid 140635591919360] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amhUyB8tpddNF-UrsIWydwAAAIY"]
[Tue Jul 28 09:05:44.353158 2026] [:error] [pid 14757:tid 140635591919360] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.tmp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amhUyB8tpddNF-UrsIWydwAAAIY"]
[Tue Jul 28 09:05:44.613415 2026] [:error] [pid 14757:tid 140635566741248] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.php.bak"] [unique_id "amhUyB8tpddNF-UrsIWyeAAAAIk"]
[Tue Jul 28 09:05:44.613984 2026] [:error] [pid 14757:tid 140635566741248] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.php.bak"] [unique_id "amhUyB8tpddNF-UrsIWyeAAAAIk"]
[Tue Jul 28 09:05:44.614295 2026] [:error] [pid 14757:tid 140635566741248] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.env.php.bak"] [unique_id "amhUyB8tpddNF-UrsIWyeAAAAIk"]
[Tue Jul 28 09:05:44.614381 2026] [:error] [pid 14757:tid 140635566741248] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.php.bak"] [unique_id "amhUyB8tpddNF-UrsIWyeAAAAIk"]
[Tue Jul 28 09:05:44.614582 2026] [:error] [pid 14757:tid 140635566741248] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.php.bak"] [unique_id "amhUyB8tpddNF-UrsIWyeAAAAIk"]
[Tue Jul 28 09:05:45.001275 2026] [:error] [pid 14757:tid 140635457636096] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.php"] [unique_id "amhUyR8tpddNF-UrsIWyegAAAJY"]
[Tue Jul 28 09:05:45.002159 2026] [:error] [pid 14757:tid 140635457636096] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.php"] [unique_id "amhUyR8tpddNF-UrsIWyegAAAJY"]
[Tue Jul 28 09:05:45.002702 2026] [:error] [pid 14757:tid 140635457636096] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.php"] [unique_id "amhUyR8tpddNF-UrsIWyegAAAJY"]
[Tue Jul 28 09:05:45.002938 2026] [:error] [pid 14757:tid 140635457636096] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.php"] [unique_id "amhUyR8tpddNF-UrsIWyegAAAJY"]
[Tue Jul 28 09:05:45.361633 2026] [:error] [pid 14757:tid 140635541563136] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amhUyR8tpddNF-UrsIWyfQAAAIw"]
[Tue Jul 28 09:05:45.362400 2026] [:error] [pid 14757:tid 140635541563136] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amhUyR8tpddNF-UrsIWyfQAAAIw"]
[Tue Jul 28 09:05:45.362924 2026] [:error] [pid 14757:tid 140635541563136] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amhUyR8tpddNF-UrsIWyfQAAAIw"]
[Tue Jul 28 09:05:45.363164 2026] [:error] [pid 14757:tid 140635541563136] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.txt"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amhUyR8tpddNF-UrsIWyfQAAAIw"]
[Tue Jul 28 09:05:46.137037 2026] [:error] [pid 14757:tid 140635617097472] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amhUyh8tpddNF-UrsIWyfgAAAIM"]
[Tue Jul 28 09:05:46.137824 2026] [:error] [pid 14757:tid 140635617097472] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amhUyh8tpddNF-UrsIWyfgAAAIM"]
[Tue Jul 28 09:05:46.138250 2026] [:error] [pid 14757:tid 140635617097472] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amhUyh8tpddNF-UrsIWyfgAAAIM"]
[Tue Jul 28 09:05:46.138464 2026] [:error] [pid 14757:tid 140635617097472] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amhUyh8tpddNF-UrsIWyfgAAAIM"]
[Tue Jul 28 09:05:46.323622 2026] [:error] [pid 14757:tid 140635706623744] [client 141.101.76.184:12963] [client 141.101.76.184] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amhUyh8tpddNF-UrsIWyfwAAAIE"]
[Tue Jul 28 09:05:46.324453 2026] [:error] [pid 14757:tid 140635706623744] [client 141.101.76.184:12963] [client 141.101.76.184] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amhUyh8tpddNF-UrsIWyfwAAAIE"]
[Tue Jul 28 09:05:46.324945 2026] [:error] [pid 14757:tid 140635706623744] [client 141.101.76.184:12963] [client 141.101.76.184] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amhUyh8tpddNF-UrsIWyfwAAAIE"]
[Tue Jul 28 09:05:46.325185 2026] [:error] [pid 14757:tid 140635706623744] [client 141.101.76.184:12963] [client 141.101.76.184] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amhUyh8tpddNF-UrsIWyfwAAAIE"]
[Tue Jul 28 09:05:46.705185 2026] [:error] [pid 14757:tid 140635516385024] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.json.save"] [unique_id "amhUyh8tpddNF-UrsIWygwAAAI8"]
[Tue Jul 28 09:05:46.706209 2026] [:error] [pid 14757:tid 140635516385024] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.json.save"] [unique_id "amhUyh8tpddNF-UrsIWygwAAAI8"]
[Tue Jul 28 09:05:46.706732 2026] [:error] [pid 14757:tid 140635516385024] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.json.save"] [unique_id "amhUyh8tpddNF-UrsIWygwAAAI8"]
[Tue Jul 28 09:05:47.112619 2026] [:error] [pid 14757:tid 140635600312064] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amhUyx8tpddNF-UrsIWyhwAAAIU"]
[Tue Jul 28 09:05:47.113662 2026] [:error] [pid 14757:tid 140635600312064] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amhUyx8tpddNF-UrsIWyhwAAAIU"]
[Tue Jul 28 09:05:47.114159 2026] [:error] [pid 14757:tid 140635600312064] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amhUyx8tpddNF-UrsIWyhwAAAIU"]
[Tue Jul 28 09:05:47.114292 2026] [:error] [pid 14757:tid 140635600312064] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amhUyx8tpddNF-UrsIWyhwAAAIU"]
[Tue Jul 28 09:05:47.114596 2026] [:error] [pid 14757:tid 140635600312064] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amhUyx8tpddNF-UrsIWyhwAAAIU"]
[Tue Jul 28 09:05:47.806861 2026] [:error] [pid 14757:tid 140635583526656] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.php"] [unique_id "amhUyx8tpddNF-UrsIWyiQAAAIc"]
[Tue Jul 28 09:05:47.807794 2026] [:error] [pid 14757:tid 140635583526656] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.php"] [unique_id "amhUyx8tpddNF-UrsIWyiQAAAIc"]
[Tue Jul 28 09:05:47.808237 2026] [:error] [pid 14757:tid 140635583526656] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/config.php"] [unique_id "amhUyx8tpddNF-UrsIWyiQAAAIc"]
[Tue Jul 28 09:05:47.808351 2026] [:error] [pid 14757:tid 140635583526656] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.php"] [unique_id "amhUyx8tpddNF-UrsIWyiQAAAIc"]
[Tue Jul 28 09:05:48.045078 2026] [:error] [pid 14757:tid 140635566741248] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.php.bak"] [unique_id "amhUzB8tpddNF-UrsIWyigAAAIk"]
[Tue Jul 28 09:05:48.045900 2026] [:error] [pid 14757:tid 140635566741248] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.php.bak"] [unique_id "amhUzB8tpddNF-UrsIWyigAAAIk"]
[Tue Jul 28 09:05:48.046350 2026] [:error] [pid 14757:tid 140635566741248] [client 141.101.76.71:11167] [client 141.101.76.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.php.bak"] [unique_id "amhUzB8tpddNF-UrsIWyigAAAIk"]
[Tue Jul 28 09:05:48.238408 2026] [:error] [pid 14755:tid 140635566741248] [client 162.159.113.55:11328] [client 162.159.113.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.js"] [unique_id "amhUzKf64wRy3HlU5UOUlQAAAAk"]
[Tue Jul 28 09:05:48.239235 2026] [:error] [pid 14755:tid 140635566741248] [client 162.159.113.55:11328] [client 162.159.113.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.js"] [unique_id "amhUzKf64wRy3HlU5UOUlQAAAAk"]
[Tue Jul 28 09:05:48.239688 2026] [:error] [pid 14755:tid 140635566741248] [client 162.159.113.55:11328] [client 162.159.113.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.js"] [unique_id "amhUzKf64wRy3HlU5UOUlQAAAAk"]
[Tue Jul 28 09:05:49.612454 2026] [:error] [pid 14859:tid 140635449243392] [client 104.23.168.114:11471] [client 104.23.168.114] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/aws-config.js"] [unique_id "amhUzbBlXBlS8_TwuUbssQAAANc"]
[Tue Jul 28 09:05:49.613391 2026] [:error] [pid 14859:tid 140635449243392] [client 104.23.168.114:11471] [client 104.23.168.114] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/aws-config.js"] [unique_id "amhUzbBlXBlS8_TwuUbssQAAANc"]
[Tue Jul 28 09:05:49.613929 2026] [:error] [pid 14859:tid 140635449243392] [client 104.23.168.114:11471] [client 104.23.168.114] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/aws-config.js"] [unique_id "amhUzbBlXBlS8_TwuUbssQAAANc"]
[Tue Jul 28 09:05:50.165155 2026] [:error] [pid 11209:tid 140635533170432] [client 172.71.95.93:10172] [client 172.71.95.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/aws.config.js"] [unique_id "amhUzpIwGwWJ8iALx6K9RgAAAU0"]
[Tue Jul 28 09:05:50.166036 2026] [:error] [pid 11209:tid 140635533170432] [client 172.71.95.93:10172] [client 172.71.95.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/aws.config.js"] [unique_id "amhUzpIwGwWJ8iALx6K9RgAAAU0"]
[Tue Jul 28 09:05:50.166538 2026] [:error] [pid 11209:tid 140635533170432] [client 172.71.95.93:10172] [client 172.71.95.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/aws.config.js"] [unique_id "amhUzpIwGwWJ8iALx6K9RgAAAU0"]
[Tue Jul 28 09:05:50.926881 2026] [:error] [pid 23518:tid 140635440850688] [client 141.101.76.184:11339] [client 141.101.76.184] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amhUzgOqbX7Z9ycSlCJX4gAAARg"]
[Tue Jul 28 09:05:50.927704 2026] [:error] [pid 23518:tid 140635440850688] [client 141.101.76.184:11339] [client 141.101.76.184] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amhUzgOqbX7Z9ycSlCJX4gAAARg"]
[Tue Jul 28 09:05:50.928241 2026] [:error] [pid 23518:tid 140635440850688] [client 141.101.76.184:11339] [client 141.101.76.184] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amhUzgOqbX7Z9ycSlCJX4gAAARg"]
[Tue Jul 28 09:14:15.341756 2026] [:error] [pid 14756:tid 140635524777728] [client 104.23.197.76:14070] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amhWx5QnCSs8VI2YeM8DUQAAAE4"]
[Tue Jul 28 09:14:15.342799 2026] [:error] [pid 14756:tid 140635524777728] [client 104.23.197.76:14070] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amhWx5QnCSs8VI2YeM8DUQAAAE4"]
[Tue Jul 28 09:14:15.343304 2026] [:error] [pid 14756:tid 140635524777728] [client 104.23.197.76:14070] [client 104.23.197.76] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amhWx5QnCSs8VI2YeM8DUQAAAE4"]
[Tue Jul 28 09:16:55.674221 2026] [:error] [pid 23518:tid 140635507992320] [client 172.70.114.249:13572] [client 172.70.114.249] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhXZwOqbX7Z9ycSlCJnywAAARA"]
[Tue Jul 28 09:16:55.675085 2026] [:error] [pid 23518:tid 140635507992320] [client 172.70.114.249:13572] [client 172.70.114.249] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhXZwOqbX7Z9ycSlCJnywAAARA"]
[Tue Jul 28 09:16:55.675690 2026] [:error] [pid 23518:tid 140635507992320] [client 172.70.114.249:13572] [client 172.70.114.249] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhXZwOqbX7Z9ycSlCJnywAAARA"]
[Tue Jul 28 09:16:55.675740 2026] [:error] [pid 23518:tid 140635507992320] [client 172.70.114.249:13572] [client 172.70.114.249] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhXZwOqbX7Z9ycSlCJnywAAARA"]
[Tue Jul 28 09:16:55.874448 2026] [:error] [pid 23518:tid 140635474421504] [client 172.70.115.139:10208] [client 172.70.115.139] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amhXZwOqbX7Z9ycSlCJnzwAAARQ"], referer: http://www.sbf-consultancy.com/
[Tue Jul 28 09:16:55.895711 2026] [:error] [pid 23518:tid 140635474421504] [client 172.70.115.139:10208] [client 172.70.115.139] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amhXZwOqbX7Z9ycSlCJnzwAAARQ"], referer: http://www.sbf-consultancy.com/
[Tue Jul 28 09:16:55.896679 2026] [:error] [pid 23518:tid 140635474421504] [client 172.70.115.139:10208] [client 172.70.115.139] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amhXZwOqbX7Z9ycSlCJnzwAAARQ"], referer: http://www.sbf-consultancy.com/
[Tue Jul 28 09:16:55.896742 2026] [:error] [pid 23518:tid 140635474421504] [client 172.70.115.139:10208] [client 172.70.115.139] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amhXZwOqbX7Z9ycSlCJnzwAAARQ"], referer: http://www.sbf-consultancy.com/
[Tue Jul 28 09:16:56.306384 2026] [:error] [pid 23518:tid 140635491206912] [client 104.23.190.95:10281] [client 104.23.190.95] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhXaAOqbX7Z9ycSlCJn0wAAARI"]
[Tue Jul 28 09:16:56.307243 2026] [:error] [pid 23518:tid 140635491206912] [client 104.23.190.95:10281] [client 104.23.190.95] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhXaAOqbX7Z9ycSlCJn0wAAARI"]
[Tue Jul 28 09:16:56.307848 2026] [:error] [pid 23518:tid 140635491206912] [client 104.23.190.95:10281] [client 104.23.190.95] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amhXaAOqbX7Z9ycSlCJn0wAAARI"]
[Tue Jul 28 09:16:56.843984 2026] [:error] [pid 11209:tid 140635608704768] [client 172.70.115.139:11214] [client 172.70.115.139] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amhXaJIwGwWJ8iALx6LHNAAAAUQ"], referer: https://www.sbf-consultancy.com/
[Tue Jul 28 09:16:56.844886 2026] [:error] [pid 11209:tid 140635608704768] [client 172.70.115.139:11214] [client 172.70.115.139] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amhXaJIwGwWJ8iALx6LHNAAAAUQ"], referer: https://www.sbf-consultancy.com/
[Tue Jul 28 09:16:56.845668 2026] [:error] [pid 11209:tid 140635608704768] [client 172.70.115.139:11214] [client 172.70.115.139] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amhXaJIwGwWJ8iALx6LHNAAAAUQ"], referer: https://www.sbf-consultancy.com/
[Tue Jul 28 09:35:45.127243 2026] [:error] [pid 14757:tid 140635541563136] [client 162.158.183.12:12961] [client 162.158.183.12] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhb0R8tpddNF-UrsIXCLQAAAIw"]
[Tue Jul 28 09:35:45.145330 2026] [:error] [pid 14757:tid 140635541563136] [client 162.158.183.12:12961] [client 162.158.183.12] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhb0R8tpddNF-UrsIXCLQAAAIw"]
[Tue Jul 28 09:35:45.145919 2026] [:error] [pid 14757:tid 140635541563136] [client 162.158.183.12:12961] [client 162.158.183.12] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhb0R8tpddNF-UrsIXCLQAAAIw"]
[Tue Jul 28 09:36:55.875616 2026] [:error] [pid 23518:tid 140635541563136] [client 172.68.130.154:10554] [client 172.68.130.154] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhcFwOqbX7Z9ycSlCKIyQAAAQw"]
[Tue Jul 28 09:36:55.876406 2026] [:error] [pid 23518:tid 140635541563136] [client 172.68.130.154:10554] [client 172.68.130.154] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhcFwOqbX7Z9ycSlCKIyQAAAQw"]
[Tue Jul 28 09:36:55.876949 2026] [:error] [pid 23518:tid 140635541563136] [client 172.68.130.154:10554] [client 172.68.130.154] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhcFwOqbX7Z9ycSlCKIyQAAAQw"]
[Tue Jul 28 09:55:44.766683 2026] [:error] [pid 11209:tid 140635608704768] [client 104.23.217.117:12796] [client 104.23.217.117] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amhggJIwGwWJ8iALx6LoLAAAAUQ"]
[Tue Jul 28 09:55:44.767306 2026] [:error] [pid 11209:tid 140635608704768] [client 104.23.217.117:12796] [client 104.23.217.117] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amhggJIwGwWJ8iALx6LoLAAAAUQ"]
[Tue Jul 28 09:55:44.767735 2026] [:error] [pid 11209:tid 140635608704768] [client 104.23.217.117:12796] [client 104.23.217.117] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amhggJIwGwWJ8iALx6LoLAAAAUQ"]
[Tue Jul 28 09:57:15.596721 2026] [:error] [pid 14756:tid 140635698231040] [client 172.70.46.164:11091] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhg25QnCSs8VI2YeM8QyAAAAEI"]
[Tue Jul 28 09:57:15.597532 2026] [:error] [pid 14756:tid 140635698231040] [client 172.70.46.164:11091] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhg25QnCSs8VI2YeM8QyAAAAEI"]
[Tue Jul 28 09:57:15.598170 2026] [:error] [pid 14756:tid 140635698231040] [client 172.70.46.164:11091] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhg25QnCSs8VI2YeM8QyAAAAEI"]
[Tue Jul 28 09:57:17.642647 2026] [:error] [pid 23518:tid 140635499599616] [client 172.70.47.5:13370] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amhg3QOqbX7Z9ycSlCKofwAAARE"]
[Tue Jul 28 09:57:17.643767 2026] [:error] [pid 23518:tid 140635499599616] [client 172.70.47.5:13370] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amhg3QOqbX7Z9ycSlCKofwAAARE"]
[Tue Jul 28 09:57:17.644189 2026] [:error] [pid 23518:tid 140635499599616] [client 172.70.47.5:13370] [client 172.70.47.5] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amhg3QOqbX7Z9ycSlCKofwAAARE"]
[Tue Jul 28 09:57:17.644283 2026] [:error] [pid 23518:tid 140635499599616] [client 172.70.47.5:13370] [client 172.70.47.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amhg3QOqbX7Z9ycSlCKofwAAARE"]
[Tue Jul 28 09:57:17.644643 2026] [:error] [pid 23518:tid 140635499599616] [client 172.70.47.5:13370] [client 172.70.47.5] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amhg3QOqbX7Z9ycSlCKofwAAARE"]
[Tue Jul 28 09:57:19.617661 2026] [:error] [pid 23518:tid 140635698231040] [client 172.70.47.5:13370] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application.yml"] [unique_id "amhg3wOqbX7Z9ycSlCKojQAAAQI"]
[Tue Jul 28 09:57:19.618509 2026] [:error] [pid 23518:tid 140635698231040] [client 172.70.47.5:13370] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application.yml"] [unique_id "amhg3wOqbX7Z9ycSlCKojQAAAQI"]
[Tue Jul 28 09:57:19.618974 2026] [:error] [pid 23518:tid 140635698231040] [client 172.70.47.5:13370] [client 172.70.47.5] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/application.yml"] [unique_id "amhg3wOqbX7Z9ycSlCKojQAAAQI"]
[Tue Jul 28 09:57:19.619073 2026] [:error] [pid 23518:tid 140635698231040] [client 172.70.47.5:13370] [client 172.70.47.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application.yml"] [unique_id "amhg3wOqbX7Z9ycSlCKojQAAAQI"]
[Tue Jul 28 09:57:19.640754 2026] [:error] [pid 14756:tid 140635566741248] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amhg35QnCSs8VI2YeM8QzwAAAEk"]
[Tue Jul 28 09:57:19.641540 2026] [:error] [pid 14756:tid 140635566741248] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amhg35QnCSs8VI2YeM8QzwAAAEk"]
[Tue Jul 28 09:57:19.642005 2026] [:error] [pid 14756:tid 140635566741248] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amhg35QnCSs8VI2YeM8QzwAAAEk"]
[Tue Jul 28 09:57:21.679911 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/debug/pprof/cmdline"] [unique_id "amhg4ZQnCSs8VI2YeM8Q1AAAAEQ"]
[Tue Jul 28 09:57:21.680766 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/debug/pprof/cmdline"] [unique_id "amhg4ZQnCSs8VI2YeM8Q1AAAAEQ"]
[Tue Jul 28 09:57:21.681212 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/debug/pprof/cmdline"] [unique_id "amhg4ZQnCSs8VI2YeM8Q1AAAAEQ"]
[Tue Jul 28 09:57:21.681342 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/debug/pprof/cmdline"] [unique_id "amhg4ZQnCSs8VI2YeM8Q1AAAAEQ"]
[Tue Jul 28 09:57:21.695478 2026] [:error] [pid 11209:tid 140635466028800] [client 172.71.95.22:13660] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amhg4ZIwGwWJ8iALx6LqlgAAAVU"]
[Tue Jul 28 09:57:21.696136 2026] [:error] [pid 11209:tid 140635466028800] [client 172.71.95.22:13660] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amhg4ZIwGwWJ8iALx6LqlgAAAVU"]
[Tue Jul 28 09:57:21.696441 2026] [:error] [pid 11209:tid 140635466028800] [client 172.71.95.22:13660] [client 172.71.95.22] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amhg4ZIwGwWJ8iALx6LqlgAAAVU"]
[Tue Jul 28 09:57:21.696529 2026] [:error] [pid 11209:tid 140635466028800] [client 172.71.95.22:13660] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amhg4ZIwGwWJ8iALx6LqlgAAAVU"]
[Tue Jul 28 09:57:21.696692 2026] [:error] [pid 11209:tid 140635466028800] [client 172.71.95.22:13660] [client 172.71.95.22] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amhg4ZIwGwWJ8iALx6LqlgAAAVU"]
[Tue Jul 28 09:57:21.698901 2026] [:error] [pid 14757:tid 140635491206912] [client 172.71.183.40:10288] [client 172.71.183.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amhg4R8tpddNF-UrsIXJQwAAAJI"]
[Tue Jul 28 09:57:21.699584 2026] [:error] [pid 14757:tid 140635491206912] [client 172.71.183.40:10288] [client 172.71.183.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amhg4R8tpddNF-UrsIXJQwAAAJI"]
[Tue Jul 28 09:57:21.700115 2026] [:error] [pid 14757:tid 140635491206912] [client 172.71.183.40:10288] [client 172.71.183.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amhg4R8tpddNF-UrsIXJQwAAAJI"]
[Tue Jul 28 09:57:21.973619 2026] [:error] [pid 14859:tid 140635499599616] [client 104.23.166.131:12923] [client 104.23.166.131] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/storage/logs/laravel.log"] [unique_id "amhg4bBlXBlS8_TwuUYN0gAAANE"]
[Tue Jul 28 09:57:21.974443 2026] [:error] [pid 14859:tid 140635499599616] [client 104.23.166.131:12923] [client 104.23.166.131] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/storage/logs/laravel.log"] [unique_id "amhg4bBlXBlS8_TwuUYN0gAAANE"]
[Tue Jul 28 09:57:21.974952 2026] [:error] [pid 14859:tid 140635499599616] [client 104.23.166.131:12923] [client 104.23.166.131] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/storage/logs/laravel.log"] [unique_id "amhg4bBlXBlS8_TwuUYN0gAAANE"]
[Tue Jul 28 09:57:22.035674 2026] [:error] [pid 14859:tid 140635698231040] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application.properties"] [unique_id "amhg4rBlXBlS8_TwuUYN0wAAAMI"]
[Tue Jul 28 09:57:22.036484 2026] [:error] [pid 14859:tid 140635698231040] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application.properties"] [unique_id "amhg4rBlXBlS8_TwuUYN0wAAAMI"]
[Tue Jul 28 09:57:22.036932 2026] [:error] [pid 14859:tid 140635698231040] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/application.properties"] [unique_id "amhg4rBlXBlS8_TwuUYN0wAAAMI"]
[Tue Jul 28 09:57:22.037040 2026] [:error] [pid 14859:tid 140635698231040] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application.properties"] [unique_id "amhg4rBlXBlS8_TwuUYN0wAAAMI"]
[Tue Jul 28 09:57:24.578738 2026] [:error] [pid 14859:tid 140635440850688] [client 104.23.170.162:13032] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/secrets.yml"] [unique_id "amhg5LBlXBlS8_TwuUYN1gAAANg"]
[Tue Jul 28 09:57:24.579548 2026] [:error] [pid 14859:tid 140635440850688] [client 104.23.170.162:13032] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/secrets.yml"] [unique_id "amhg5LBlXBlS8_TwuUYN1gAAANg"]
[Tue Jul 28 09:57:24.580061 2026] [:error] [pid 14859:tid 140635440850688] [client 104.23.170.162:13032] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets.yml"] [unique_id "amhg5LBlXBlS8_TwuUYN1gAAANg"]
[Tue Jul 28 09:57:26.210026 2026] [:error] [pid 14756:tid 140635507992320] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhg5pQnCSs8VI2YeM8Q3AAAAFA"]
[Tue Jul 28 09:57:26.210617 2026] [:error] [pid 14756:tid 140635507992320] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhg5pQnCSs8VI2YeM8Q3AAAAFA"]
[Tue Jul 28 09:57:26.210940 2026] [:error] [pid 14756:tid 140635507992320] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhg5pQnCSs8VI2YeM8Q3AAAAFA"]
[Tue Jul 28 09:57:26.211009 2026] [:error] [pid 14756:tid 140635507992320] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhg5pQnCSs8VI2YeM8Q3AAAAFA"]
[Tue Jul 28 09:57:26.211224 2026] [:error] [pid 14756:tid 140635507992320] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhg5pQnCSs8VI2YeM8Q3AAAAFA"]
[Tue Jul 28 09:57:26.670713 2026] [:error] [pid 14859:tid 140635549955840] [client 104.23.170.124:12231] [client 104.23.170.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amhg5rBlXBlS8_TwuUYN1wAAAMs"]
[Tue Jul 28 09:57:26.671358 2026] [:error] [pid 14859:tid 140635549955840] [client 104.23.170.124:12231] [client 104.23.170.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amhg5rBlXBlS8_TwuUYN1wAAAMs"]
[Tue Jul 28 09:57:26.671803 2026] [:error] [pid 14859:tid 140635549955840] [client 104.23.170.124:12231] [client 104.23.170.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amhg5rBlXBlS8_TwuUYN1wAAAMs"]
[Tue Jul 28 09:57:26.672020 2026] [:error] [pid 14859:tid 140635549955840] [client 104.23.170.124:12231] [client 104.23.170.124] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amhg5rBlXBlS8_TwuUYN1wAAAMs"]
[Tue Jul 28 09:57:26.939948 2026] [:error] [pid 14859:tid 140635583526656] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amhg5rBlXBlS8_TwuUYN2QAAAMc"]
[Tue Jul 28 09:57:26.941049 2026] [:error] [pid 14859:tid 140635583526656] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amhg5rBlXBlS8_TwuUYN2QAAAMc"]
[Tue Jul 28 09:57:26.941547 2026] [:error] [pid 14859:tid 140635583526656] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amhg5rBlXBlS8_TwuUYN2QAAAMc"]
[Tue Jul 28 09:57:26.941686 2026] [:error] [pid 14859:tid 140635583526656] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amhg5rBlXBlS8_TwuUYN2QAAAMc"]
[Tue Jul 28 09:57:26.941953 2026] [:error] [pid 14859:tid 140635583526656] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amhg5rBlXBlS8_TwuUYN2QAAAMc"]
[Tue Jul 28 09:57:27.154896 2026] [:error] [pid 14756:tid 140635541563136] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amhg55QnCSs8VI2YeM8Q3wAAAEw"]
[Tue Jul 28 09:57:27.155700 2026] [:error] [pid 14756:tid 140635541563136] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amhg55QnCSs8VI2YeM8Q3wAAAEw"]
[Tue Jul 28 09:57:27.156063 2026] [:error] [pid 14756:tid 140635541563136] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amhg55QnCSs8VI2YeM8Q3wAAAEw"]
[Tue Jul 28 09:57:27.156177 2026] [:error] [pid 14756:tid 140635541563136] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amhg55QnCSs8VI2YeM8Q3wAAAEw"]
[Tue Jul 28 09:57:27.156380 2026] [:error] [pid 14756:tid 140635541563136] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amhg55QnCSs8VI2YeM8Q3wAAAEw"]
[Tue Jul 28 09:57:27.189612 2026] [:error] [pid 23518:tid 140635507992320] [client 172.71.95.146:10957] [client 172.71.95.146] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/application.properties"] [unique_id "amhg5wOqbX7Z9ycSlCKoyAAAARA"]
[Tue Jul 28 09:57:27.190362 2026] [:error] [pid 23518:tid 140635507992320] [client 172.71.95.146:10957] [client 172.71.95.146] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/application.properties"] [unique_id "amhg5wOqbX7Z9ycSlCKoyAAAARA"]
[Tue Jul 28 09:57:27.190861 2026] [:error] [pid 23518:tid 140635507992320] [client 172.71.95.146:10957] [client 172.71.95.146] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/application.properties"] [unique_id "amhg5wOqbX7Z9ycSlCKoyAAAARA"]
[Tue Jul 28 09:57:28.962791 2026] [:error] [pid 14859:tid 140635566741248] [client 104.23.170.162:13032] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amhg6LBlXBlS8_TwuUYN3AAAAMk"]
[Tue Jul 28 09:57:28.963658 2026] [:error] [pid 14859:tid 140635566741248] [client 104.23.170.162:13032] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amhg6LBlXBlS8_TwuUYN3AAAAMk"]
[Tue Jul 28 09:57:28.964141 2026] [:error] [pid 14859:tid 140635566741248] [client 104.23.170.162:13032] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amhg6LBlXBlS8_TwuUYN3AAAAMk"]
[Tue Jul 28 09:57:28.964370 2026] [:error] [pid 14859:tid 140635566741248] [client 104.23.170.162:13032] [client 104.23.170.162] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amhg6LBlXBlS8_TwuUYN3AAAAMk"]
[Tue Jul 28 09:57:29.766420 2026] [:error] [pid 23518:tid 140635608704768] [client 172.71.95.146:10957] [client 172.71.95.146] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amhg6QOqbX7Z9ycSlCKo3gAAAQQ"]
[Tue Jul 28 09:57:29.767305 2026] [:error] [pid 23518:tid 140635608704768] [client 172.71.95.146:10957] [client 172.71.95.146] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amhg6QOqbX7Z9ycSlCKo3gAAAQQ"]
[Tue Jul 28 09:57:29.767733 2026] [:error] [pid 23518:tid 140635608704768] [client 172.71.95.146:10957] [client 172.71.95.146] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amhg6QOqbX7Z9ycSlCKo3gAAAQQ"]
[Tue Jul 28 09:57:29.767852 2026] [:error] [pid 23518:tid 140635608704768] [client 172.71.95.146:10957] [client 172.71.95.146] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amhg6QOqbX7Z9ycSlCKo3gAAAQQ"]
[Tue Jul 28 09:57:29.768072 2026] [:error] [pid 23518:tid 140635608704768] [client 172.71.95.146:10957] [client 172.71.95.146] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amhg6QOqbX7Z9ycSlCKo3gAAAQQ"]
[Tue Jul 28 09:57:30.966910 2026] [:error] [pid 14859:tid 140635541563136] [client 104.23.170.124:12231] [client 104.23.170.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amhg6rBlXBlS8_TwuUYN3wAAAMw"]
[Tue Jul 28 09:57:30.967529 2026] [:error] [pid 14859:tid 140635541563136] [client 104.23.170.124:12231] [client 104.23.170.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amhg6rBlXBlS8_TwuUYN3wAAAMw"]
[Tue Jul 28 09:57:30.967929 2026] [:error] [pid 14859:tid 140635541563136] [client 104.23.170.124:12231] [client 104.23.170.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amhg6rBlXBlS8_TwuUYN3wAAAMw"]
[Tue Jul 28 09:57:30.968125 2026] [:error] [pid 14859:tid 140635541563136] [client 104.23.170.124:12231] [client 104.23.170.124] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amhg6rBlXBlS8_TwuUYN3wAAAMw"]
[Tue Jul 28 09:57:31.403785 2026] [:error] [pid 14756:tid 140635499599616] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amhg65QnCSs8VI2YeM8Q5QAAAFE"]
[Tue Jul 28 09:57:31.404765 2026] [:error] [pid 14756:tid 140635499599616] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amhg65QnCSs8VI2YeM8Q5QAAAFE"]
[Tue Jul 28 09:57:31.405325 2026] [:error] [pid 14756:tid 140635499599616] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amhg65QnCSs8VI2YeM8Q5QAAAFE"]
[Tue Jul 28 09:57:31.405709 2026] [:error] [pid 14756:tid 140635499599616] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amhg65QnCSs8VI2YeM8Q5QAAAFE"]
[Tue Jul 28 09:57:31.693298 2026] [:error] [pid 14859:tid 140635499599616] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amhg67BlXBlS8_TwuUYN4QAAANE"]
[Tue Jul 28 09:57:31.694351 2026] [:error] [pid 14859:tid 140635499599616] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amhg67BlXBlS8_TwuUYN4QAAANE"]
[Tue Jul 28 09:57:31.694818 2026] [:error] [pid 14859:tid 140635499599616] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amhg67BlXBlS8_TwuUYN4QAAANE"]
[Tue Jul 28 09:57:31.694925 2026] [:error] [pid 14859:tid 140635499599616] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amhg67BlXBlS8_TwuUYN4QAAANE"]
[Tue Jul 28 09:57:31.695140 2026] [:error] [pid 14859:tid 140635499599616] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amhg67BlXBlS8_TwuUYN4QAAANE"]
[Tue Jul 28 09:57:32.978395 2026] [:error] [pid 14756:tid 140635617097472] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amhg7JQnCSs8VI2YeM8Q5wAAAEM"]
[Tue Jul 28 09:57:32.979066 2026] [:error] [pid 14756:tid 140635617097472] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amhg7JQnCSs8VI2YeM8Q5wAAAEM"]
[Tue Jul 28 09:57:32.979391 2026] [:error] [pid 14756:tid 140635617097472] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amhg7JQnCSs8VI2YeM8Q5wAAAEM"]
[Tue Jul 28 09:57:32.979464 2026] [:error] [pid 14756:tid 140635617097472] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amhg7JQnCSs8VI2YeM8Q5wAAAEM"]
[Tue Jul 28 09:57:32.979655 2026] [:error] [pid 14756:tid 140635617097472] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amhg7JQnCSs8VI2YeM8Q5wAAAEM"]
[Tue Jul 28 09:57:33.299275 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.env"] [unique_id "amhg7ZQnCSs8VI2YeM8Q6AAAAEQ"]
[Tue Jul 28 09:57:33.300203 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.env"] [unique_id "amhg7ZQnCSs8VI2YeM8Q6AAAAEQ"]
[Tue Jul 28 09:57:33.300764 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/config.env"] [unique_id "amhg7ZQnCSs8VI2YeM8Q6AAAAEQ"]
[Tue Jul 28 09:57:33.300895 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.82:13936] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.env"] [unique_id "amhg7ZQnCSs8VI2YeM8Q6AAAAEQ"]
[Tue Jul 28 09:57:35.359208 2026] [:error] [pid 14859:tid 140635600312064] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/secrets.yml"] [unique_id "amhg77BlXBlS8_TwuUYN5AAAAMU"]
[Tue Jul 28 09:57:35.360028 2026] [:error] [pid 14859:tid 140635600312064] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/secrets.yml"] [unique_id "amhg77BlXBlS8_TwuUYN5AAAAMU"]
[Tue Jul 28 09:57:35.360487 2026] [:error] [pid 14859:tid 140635600312064] [client 172.70.46.164:11093] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/secrets.yml"] [unique_id "amhg77BlXBlS8_TwuUYN5AAAAMU"]
[Tue Jul 28 09:57:35.956975 2026] [:error] [pid 23518:tid 140635706623744] [client 172.71.95.22:11157] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhg7wOqbX7Z9ycSlCKo_AAAAQE"]
[Tue Jul 28 09:57:35.957723 2026] [:error] [pid 23518:tid 140635706623744] [client 172.71.95.22:11157] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhg7wOqbX7Z9ycSlCKo_AAAAQE"]
[Tue Jul 28 09:57:35.958095 2026] [:error] [pid 23518:tid 140635706623744] [client 172.71.95.22:11157] [client 172.71.95.22] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhg7wOqbX7Z9ycSlCKo_AAAAQE"]
[Tue Jul 28 09:57:35.958185 2026] [:error] [pid 23518:tid 140635706623744] [client 172.71.95.22:11157] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhg7wOqbX7Z9ycSlCKo_AAAAQE"]
[Tue Jul 28 09:57:35.958382 2026] [:error] [pid 23518:tid 140635706623744] [client 172.71.95.22:11157] [client 172.71.95.22] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhg7wOqbX7Z9ycSlCKo_AAAAQE"]
[Tue Jul 28 09:57:37.182910 2026] [:error] [pid 14757:tid 140635549955840] [client 104.23.170.163:10520] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhg8R8tpddNF-UrsIXJXgAAAIs"]
[Tue Jul 28 09:57:37.183634 2026] [:error] [pid 14757:tid 140635549955840] [client 104.23.170.163:10520] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhg8R8tpddNF-UrsIXJXgAAAIs"]
[Tue Jul 28 09:57:37.184035 2026] [:error] [pid 14757:tid 140635549955840] [client 104.23.170.163:10520] [client 104.23.170.163] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhg8R8tpddNF-UrsIXJXgAAAIs"]
[Tue Jul 28 09:57:37.184157 2026] [:error] [pid 14757:tid 140635549955840] [client 104.23.170.163:10520] [client 104.23.170.163] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhg8R8tpddNF-UrsIXJXgAAAIs"]
[Tue Jul 28 09:57:37.184385 2026] [:error] [pid 14757:tid 140635549955840] [client 104.23.170.163:10520] [client 104.23.170.163] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhg8R8tpddNF-UrsIXJXgAAAIs"]
[Tue Jul 28 09:57:41.389469 2026] [:error] [pid 23518:tid 140635482814208] [client 104.23.166.82:13408] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/loadable-stats.json"] [unique_id "amhg9QOqbX7Z9ycSlCKpGwAAARM"]
[Tue Jul 28 09:57:41.390312 2026] [:error] [pid 23518:tid 140635482814208] [client 104.23.166.82:13408] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/loadable-stats.json"] [unique_id "amhg9QOqbX7Z9ycSlCKpGwAAARM"]
[Tue Jul 28 09:57:41.390920 2026] [:error] [pid 23518:tid 140635482814208] [client 104.23.166.82:13408] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/loadable-stats.json"] [unique_id "amhg9QOqbX7Z9ycSlCKpGwAAARM"]
[Tue Jul 28 09:57:41.805055 2026] [:error] [pid 14859:tid 140635491206912] [client 172.71.183.36:10782] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/manifest.json"] [unique_id "amhg9bBlXBlS8_TwuUYN6QAAANI"]
[Tue Jul 28 09:57:41.806018 2026] [:error] [pid 14859:tid 140635491206912] [client 172.71.183.36:10782] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/manifest.json"] [unique_id "amhg9bBlXBlS8_TwuUYN6QAAANI"]
[Tue Jul 28 09:57:41.806784 2026] [:error] [pid 14859:tid 140635491206912] [client 172.71.183.36:10782] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/manifest.json"] [unique_id "amhg9bBlXBlS8_TwuUYN6QAAANI"]
[Tue Jul 28 09:57:44.728181 2026] [:error] [pid 11209:tid 140635507992320] [client 104.23.170.162:11504] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/asset-manifest.json"] [unique_id "amhg-JIwGwWJ8iALx6Lq-wAAAVA"]
[Tue Jul 28 09:57:44.729274 2026] [:error] [pid 11209:tid 140635507992320] [client 104.23.170.162:11504] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/asset-manifest.json"] [unique_id "amhg-JIwGwWJ8iALx6Lq-wAAAVA"]
[Tue Jul 28 09:57:44.729970 2026] [:error] [pid 11209:tid 140635507992320] [client 104.23.170.162:11504] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/asset-manifest.json"] [unique_id "amhg-JIwGwWJ8iALx6Lq-wAAAVA"]
[Tue Jul 28 09:58:00.266703 2026] [:error] [pid 14859:tid 140635533170432] [client 104.23.170.162:13851] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/v1/graphql"] [unique_id "amhhCLBlXBlS8_TwuUYN8AAAAM0"]
[Tue Jul 28 09:58:00.267515 2026] [:error] [pid 14859:tid 140635533170432] [client 104.23.170.162:13851] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/v1/graphql"] [unique_id "amhhCLBlXBlS8_TwuUYN8AAAAM0"]
[Tue Jul 28 09:58:00.267861 2026] [:error] [pid 14859:tid 140635533170432] [client 104.23.170.162:13851] [client 104.23.170.162] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/v1/graphql"] [unique_id "amhhCLBlXBlS8_TwuUYN8AAAAM0"]
[Tue Jul 28 09:58:00.267929 2026] [:error] [pid 14859:tid 140635533170432] [client 104.23.170.162:13851] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/v1/graphql"] [unique_id "amhhCLBlXBlS8_TwuUYN8AAAAM0"]
[Tue Jul 28 09:58:00.469310 2026] [:error] [pid 11209:tid 140635617097472] [client 104.23.166.82:9612] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amhhCJIwGwWJ8iALx6LrTwAAAUM"]
[Tue Jul 28 09:58:00.470223 2026] [:error] [pid 11209:tid 140635617097472] [client 104.23.166.82:9612] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amhhCJIwGwWJ8iALx6LrTwAAAUM"]
[Tue Jul 28 09:58:00.470797 2026] [:error] [pid 11209:tid 140635617097472] [client 104.23.166.82:9612] [client 104.23.166.82] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amhhCJIwGwWJ8iALx6LrTwAAAUM"]
[Tue Jul 28 09:58:00.470949 2026] [:error] [pid 11209:tid 140635617097472] [client 104.23.166.82:9612] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amhhCJIwGwWJ8iALx6LrTwAAAUM"]
[Tue Jul 28 09:58:01.658284 2026] [:error] [pid 14756:tid 140635549955840] [client 162.159.113.44:10891] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amhhCZQnCSs8VI2YeM8Q6wAAAEs"]
[Tue Jul 28 09:58:01.658962 2026] [:error] [pid 14756:tid 140635549955840] [client 162.159.113.44:10891] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amhhCZQnCSs8VI2YeM8Q6wAAAEs"]
[Tue Jul 28 09:58:01.659400 2026] [:error] [pid 14756:tid 140635549955840] [client 162.159.113.44:10891] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amhhCZQnCSs8VI2YeM8Q6wAAAEs"]
[Tue Jul 28 09:58:01.863256 2026] [:error] [pid 23518:tid 140635617097472] [client 172.71.183.36:13422] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/__/firebase/init.json"] [unique_id "amhhCQOqbX7Z9ycSlCKqKgAAAQM"]
[Tue Jul 28 09:58:01.864322 2026] [:error] [pid 23518:tid 140635617097472] [client 172.71.183.36:13422] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/__/firebase/init.json"] [unique_id "amhhCQOqbX7Z9ycSlCKqKgAAAQM"]
[Tue Jul 28 09:58:01.864854 2026] [:error] [pid 23518:tid 140635617097472] [client 172.71.183.36:13422] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/__/firebase/init.json"] [unique_id "amhhCQOqbX7Z9ycSlCKqKgAAAQM"]
[Tue Jul 28 09:58:01.966852 2026] [:error] [pid 11209:tid 140635507992320] [client 104.23.166.82:9612] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v1/settings"] [unique_id "amhhCZIwGwWJ8iALx6LrVwAAAVA"]
[Tue Jul 28 09:58:01.968277 2026] [:error] [pid 11209:tid 140635507992320] [client 104.23.166.82:9612] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v1/settings"] [unique_id "amhhCZIwGwWJ8iALx6LrVwAAAVA"]
[Tue Jul 28 09:58:01.968824 2026] [:error] [pid 11209:tid 140635507992320] [client 104.23.166.82:9612] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v1/settings"] [unique_id "amhhCZIwGwWJ8iALx6LrVwAAAVA"]
[Tue Jul 28 09:58:03.074504 2026] [:error] [pid 14859:tid 140635617097472] [client 172.71.99.40:14033] [client 172.71.99.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amhhC7BlXBlS8_TwuUYN8gAAAMM"]
[Tue Jul 28 09:58:03.082949 2026] [:error] [pid 14859:tid 140635617097472] [client 172.71.99.40:14033] [client 172.71.99.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amhhC7BlXBlS8_TwuUYN8gAAAMM"]
[Tue Jul 28 09:58:03.083419 2026] [:error] [pid 14859:tid 140635617097472] [client 172.71.99.40:14033] [client 172.71.99.40] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amhhC7BlXBlS8_TwuUYN8gAAAMM"]
[Tue Jul 28 09:58:03.083571 2026] [:error] [pid 14859:tid 140635617097472] [client 172.71.99.40:14033] [client 172.71.99.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amhhC7BlXBlS8_TwuUYN8gAAAMM"]
[Tue Jul 28 09:58:03.199408 2026] [:error] [pid 14756:tid 140635541563136] [client 162.159.113.44:10891] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/settings"] [unique_id "amhhC5QnCSs8VI2YeM8Q7AAAAEw"]
[Tue Jul 28 09:58:03.200161 2026] [:error] [pid 14756:tid 140635541563136] [client 162.159.113.44:10891] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/settings"] [unique_id "amhhC5QnCSs8VI2YeM8Q7AAAAEw"]
[Tue Jul 28 09:58:03.200515 2026] [:error] [pid 14756:tid 140635541563136] [client 162.159.113.44:10891] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/settings"] [unique_id "amhhC5QnCSs8VI2YeM8Q7AAAAEw"]
[Tue Jul 28 09:58:03.581597 2026] [:error] [pid 23518:tid 140635482814208] [client 172.71.183.36:13422] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "amhhCwOqbX7Z9ycSlCKqNgAAARM"]
[Tue Jul 28 09:58:03.582591 2026] [:error] [pid 23518:tid 140635482814208] [client 172.71.183.36:13422] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "amhhCwOqbX7Z9ycSlCKqNgAAARM"]
[Tue Jul 28 09:58:03.583129 2026] [:error] [pid 23518:tid 140635482814208] [client 172.71.183.36:13422] [client 172.71.183.36] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "amhhCwOqbX7Z9ycSlCKqNgAAARM"]
[Tue Jul 28 09:58:03.583258 2026] [:error] [pid 23518:tid 140635482814208] [client 172.71.183.36:13422] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "amhhCwOqbX7Z9ycSlCKqNgAAARM"]
[Tue Jul 28 09:58:03.611326 2026] [:error] [pid 23518:tid 140635608704768] [client 162.159.113.160:13596] [client 162.159.113.160] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env.js"] [unique_id "amhhCwOqbX7Z9ycSlCKqNwAAAQQ"]
[Tue Jul 28 09:58:03.612071 2026] [:error] [pid 23518:tid 140635608704768] [client 162.159.113.160:13596] [client 162.159.113.160] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env.js"] [unique_id "amhhCwOqbX7Z9ycSlCKqNwAAAQQ"]
[Tue Jul 28 09:58:03.612493 2026] [:error] [pid 23518:tid 140635608704768] [client 162.159.113.160:13596] [client 162.159.113.160] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/env.js"] [unique_id "amhhCwOqbX7Z9ycSlCKqNwAAAQQ"]
[Tue Jul 28 09:58:03.668149 2026] [:error] [pid 11209:tid 140635566741248] [client 104.23.166.82:9612] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/firebase-config.json"] [unique_id "amhhC5IwGwWJ8iALx6LrXgAAAUk"]
[Tue Jul 28 09:58:03.668776 2026] [:error] [pid 11209:tid 140635566741248] [client 104.23.166.82:9612] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/firebase-config.json"] [unique_id "amhhC5IwGwWJ8iALx6LrXgAAAUk"]
[Tue Jul 28 09:58:03.669186 2026] [:error] [pid 11209:tid 140635566741248] [client 104.23.166.82:9612] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/firebase-config.json"] [unique_id "amhhC5IwGwWJ8iALx6LrXgAAAUk"]
[Tue Jul 28 09:58:04.611732 2026] [:error] [pid 14859:tid 140635575133952] [client 104.23.170.162:13851] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env.json"] [unique_id "amhhDLBlXBlS8_TwuUYN9AAAAMg"]
[Tue Jul 28 09:58:04.612687 2026] [:error] [pid 14859:tid 140635575133952] [client 104.23.170.162:13851] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env.json"] [unique_id "amhhDLBlXBlS8_TwuUYN9AAAAMg"]
[Tue Jul 28 09:58:04.613124 2026] [:error] [pid 14859:tid 140635575133952] [client 104.23.170.162:13851] [client 104.23.170.162] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/env.json"] [unique_id "amhhDLBlXBlS8_TwuUYN9AAAAMg"]
[Tue Jul 28 09:58:04.613244 2026] [:error] [pid 14859:tid 140635575133952] [client 104.23.170.162:13851] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/env.json"] [unique_id "amhhDLBlXBlS8_TwuUYN9AAAAMg"]
[Tue Jul 28 09:58:05.402851 2026] [:error] [pid 23518:tid 140635617097472] [client 172.71.183.36:13422] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v1/config"] [unique_id "amhhDQOqbX7Z9ycSlCKqSQAAAQM"]
[Tue Jul 28 09:58:05.404064 2026] [:error] [pid 23518:tid 140635617097472] [client 172.71.183.36:13422] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v1/config"] [unique_id "amhhDQOqbX7Z9ycSlCKqSQAAAQM"]
[Tue Jul 28 09:58:05.404629 2026] [:error] [pid 23518:tid 140635617097472] [client 172.71.183.36:13422] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v1/config"] [unique_id "amhhDQOqbX7Z9ycSlCKqSQAAAQM"]
[Tue Jul 28 09:58:07.242661 2026] [:error] [pid 23518:tid 140635549955840] [client 104.23.172.125:11460] [client 104.23.172.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v2/config"] [unique_id "amhhDwOqbX7Z9ycSlCKqWQAAAQs"]
[Tue Jul 28 09:58:07.243459 2026] [:error] [pid 23518:tid 140635549955840] [client 104.23.172.125:11460] [client 104.23.172.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v2/config"] [unique_id "amhhDwOqbX7Z9ycSlCKqWQAAAQs"]
[Tue Jul 28 09:58:07.243878 2026] [:error] [pid 23518:tid 140635549955840] [client 104.23.172.125:11460] [client 104.23.172.125] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/api/v2/config"] [unique_id "amhhDwOqbX7Z9ycSlCKqWQAAAQs"]
[Tue Jul 28 09:58:07.243979 2026] [:error] [pid 23518:tid 140635549955840] [client 104.23.172.125:11460] [client 104.23.172.125] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v2/config"] [unique_id "amhhDwOqbX7Z9ycSlCKqWQAAAQs"]
[Tue Jul 28 10:00:38.473344 2026] [:error] [pid 14756:tid 140635698231040] [client 104.23.175.172:10034] [client 104.23.175.172] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/license.txt"] [unique_id "amhhppQnCSs8VI2YeM8RUQAAAEI"]
[Tue Jul 28 10:00:38.474517 2026] [:error] [pid 14756:tid 140635698231040] [client 104.23.175.172:10034] [client 104.23.175.172] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/license.txt"] [unique_id "amhhppQnCSs8VI2YeM8RUQAAAEI"]
[Tue Jul 28 10:00:38.474697 2026] [:error] [pid 14756:tid 140635698231040] [client 104.23.175.172:10034] [client 104.23.175.172] ModSecurity: Warning. Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "142"] [id "913101"] [msg "Found User-Agent associated with scripting/generic HTTP client"] [data "Matched Data: python-requests found within REQUEST_HEADERS:User-Agent: python-requests/2.27.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scripting"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/license.txt"] [unique_id "amhhppQnCSs8VI2YeM8RUQAAAEI"]
[Tue Jul 28 10:00:38.475032 2026] [:error] [pid 14756:tid 140635698231040] [client 104.23.175.172:10034] [client 104.23.175.172] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/license.txt"] [unique_id "amhhppQnCSs8VI2YeM8RUQAAAEI"]
[Tue Jul 28 10:01:11.626344 2026] [:error] [pid 23518:tid 140635549955840] [client 104.23.166.83:12882] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amhhxwOqbX7Z9ycSlCKvPAAAAQs"]
[Tue Jul 28 10:01:11.627056 2026] [:error] [pid 23518:tid 140635549955840] [client 104.23.166.83:12882] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amhhxwOqbX7Z9ycSlCKvPAAAAQs"]
[Tue Jul 28 10:01:11.627441 2026] [:error] [pid 23518:tid 140635549955840] [client 104.23.166.83:12882] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amhhxwOqbX7Z9ycSlCKvPAAAAQs"]
[Tue Jul 28 10:01:11.627712 2026] [:error] [pid 23518:tid 140635549955840] [client 104.23.166.83:12882] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amhhxwOqbX7Z9ycSlCKvPAAAAQs"]
[Tue Jul 28 10:01:11.694770 2026] [:error] [pid 14756:tid 140635516385024] [client 104.23.166.83:12887] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhhx5QnCSs8VI2YeM8RgwAAAE8"]
[Tue Jul 28 10:01:11.695640 2026] [:error] [pid 14756:tid 140635516385024] [client 104.23.166.83:12887] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhhx5QnCSs8VI2YeM8RgwAAAE8"]
[Tue Jul 28 10:01:11.696350 2026] [:error] [pid 14756:tid 140635516385024] [client 104.23.166.83:12887] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhhx5QnCSs8VI2YeM8RgwAAAE8"]
[Tue Jul 28 10:01:11.696688 2026] [:error] [pid 14756:tid 140635516385024] [client 104.23.166.83:12887] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhhx5QnCSs8VI2YeM8RgwAAAE8"]
[Tue Jul 28 10:01:11.757842 2026] [:error] [pid 11209:tid 140635482814208] [client 104.23.166.82:9883] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhhx5IwGwWJ8iALx6LuuwAAAVM"]
[Tue Jul 28 10:01:11.758635 2026] [:error] [pid 11209:tid 140635482814208] [client 104.23.166.82:9883] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhhx5IwGwWJ8iALx6LuuwAAAVM"]
[Tue Jul 28 10:01:11.759107 2026] [:error] [pid 11209:tid 140635482814208] [client 104.23.166.82:9883] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhhx5IwGwWJ8iALx6LuuwAAAVM"]
[Tue Jul 28 10:01:11.759337 2026] [:error] [pid 11209:tid 140635482814208] [client 104.23.166.82:9883] [client 104.23.166.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhhx5IwGwWJ8iALx6LuuwAAAVM"]
[Tue Jul 28 10:01:11.827833 2026] [:error] [pid 23518:tid 140635591919360] [client 104.23.166.83:12889] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amhhxwOqbX7Z9ycSlCKvPgAAAQY"]
[Tue Jul 28 10:01:11.828950 2026] [:error] [pid 23518:tid 140635591919360] [client 104.23.166.83:12889] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amhhxwOqbX7Z9ycSlCKvPgAAAQY"]
[Tue Jul 28 10:01:11.829588 2026] [:error] [pid 23518:tid 140635591919360] [client 104.23.166.83:12889] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amhhxwOqbX7Z9ycSlCKvPgAAAQY"]
[Tue Jul 28 10:01:11.889731 2026] [:error] [pid 14859:tid 140635466028800] [client 104.23.166.82:9888] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amhhx7BlXBlS8_TwuUYQMgAAANU"]
[Tue Jul 28 10:01:11.897840 2026] [:error] [pid 14859:tid 140635466028800] [client 104.23.166.82:9888] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amhhx7BlXBlS8_TwuUYQMgAAANU"]
[Tue Jul 28 10:01:11.898481 2026] [:error] [pid 14859:tid 140635466028800] [client 104.23.166.82:9888] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amhhx7BlXBlS8_TwuUYQMgAAANU"]
[Tue Jul 28 10:01:11.898850 2026] [:error] [pid 14859:tid 140635466028800] [client 104.23.166.82:9888] [client 104.23.166.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amhhx7BlXBlS8_TwuUYQMgAAANU"]
[Tue Jul 28 10:01:11.961581 2026] [:error] [pid 23518:tid 140635558348544] [client 104.23.166.82:9896] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo/"] [unique_id "amhhxwOqbX7Z9ycSlCKvQAAAAQo"]
[Tue Jul 28 10:01:11.962297 2026] [:error] [pid 23518:tid 140635558348544] [client 104.23.166.82:9896] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo/"] [unique_id "amhhxwOqbX7Z9ycSlCKvQAAAAQo"]
[Tue Jul 28 10:01:11.962801 2026] [:error] [pid 23518:tid 140635558348544] [client 104.23.166.82:9896] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo/"] [unique_id "amhhxwOqbX7Z9ycSlCKvQAAAAQo"]
[Tue Jul 28 10:01:12.021815 2026] [:error] [pid 23518:tid 140635524777728] [client 104.23.166.82:9897] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amhhyAOqbX7Z9ycSlCKvQQAAAQ4"]
[Tue Jul 28 10:01:12.022636 2026] [:error] [pid 23518:tid 140635524777728] [client 104.23.166.82:9897] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amhhyAOqbX7Z9ycSlCKvQQAAAQ4"]
[Tue Jul 28 10:01:12.023164 2026] [:error] [pid 23518:tid 140635524777728] [client 104.23.166.82:9897] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amhhyAOqbX7Z9ycSlCKvQQAAAQ4"]
[Tue Jul 28 10:01:12.023411 2026] [:error] [pid 23518:tid 140635524777728] [client 104.23.166.82:9897] [client 104.23.166.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amhhyAOqbX7Z9ycSlCKvQQAAAQ4"]
[Tue Jul 28 10:01:12.092428 2026] [:error] [pid 14859:tid 140635608704768] [client 104.23.166.82:9905] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amhhyLBlXBlS8_TwuUYQNAAAAMQ"]
[Tue Jul 28 10:01:12.093400 2026] [:error] [pid 14859:tid 140635608704768] [client 104.23.166.82:9905] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amhhyLBlXBlS8_TwuUYQNAAAAMQ"]
[Tue Jul 28 10:01:12.094092 2026] [:error] [pid 14859:tid 140635608704768] [client 104.23.166.82:9905] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amhhyLBlXBlS8_TwuUYQNAAAAMQ"]
[Tue Jul 28 10:01:12.094324 2026] [:error] [pid 14859:tid 140635608704768] [client 104.23.166.82:9905] [client 104.23.166.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amhhyLBlXBlS8_TwuUYQNAAAAMQ"]
[Tue Jul 28 10:01:12.160252 2026] [:error] [pid 11209:tid 140635608704768] [client 104.23.166.83:12892] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/test"] [unique_id "amhhyJIwGwWJ8iALx6LuvwAAAUQ"]
[Tue Jul 28 10:01:12.160888 2026] [:error] [pid 11209:tid 140635608704768] [client 104.23.166.83:12892] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/test"] [unique_id "amhhyJIwGwWJ8iALx6LuvwAAAUQ"]
[Tue Jul 28 10:01:12.178593 2026] [:error] [pid 11209:tid 140635608704768] [client 104.23.166.83:12892] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/test"] [unique_id "amhhyJIwGwWJ8iALx6LuvwAAAUQ"]
[Tue Jul 28 10:01:12.238020 2026] [:error] [pid 23518:tid 140635533170432] [client 104.23.166.82:9912] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhhyAOqbX7Z9ycSlCKvQgAAAQ0"]
[Tue Jul 28 10:01:12.238939 2026] [:error] [pid 23518:tid 140635533170432] [client 104.23.166.82:9912] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhhyAOqbX7Z9ycSlCKvQgAAAQ0"]
[Tue Jul 28 10:01:12.239380 2026] [:error] [pid 23518:tid 140635533170432] [client 104.23.166.82:9912] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhhyAOqbX7Z9ycSlCKvQgAAAQ0"]
[Tue Jul 28 10:01:12.239606 2026] [:error] [pid 23518:tid 140635533170432] [client 104.23.166.82:9912] [client 104.23.166.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhhyAOqbX7Z9ycSlCKvQgAAAQ0"]
[Tue Jul 28 10:01:12.297011 2026] [:error] [pid 23518:tid 140635449243392] [client 104.23.166.82:9916] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amhhyAOqbX7Z9ycSlCKvQwAAARc"]
[Tue Jul 28 10:01:12.297834 2026] [:error] [pid 23518:tid 140635449243392] [client 104.23.166.82:9916] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amhhyAOqbX7Z9ycSlCKvQwAAARc"]
[Tue Jul 28 10:01:12.298377 2026] [:error] [pid 23518:tid 140635449243392] [client 104.23.166.82:9916] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amhhyAOqbX7Z9ycSlCKvQwAAARc"]
[Tue Jul 28 10:01:12.298652 2026] [:error] [pid 23518:tid 140635449243392] [client 104.23.166.82:9916] [client 104.23.166.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amhhyAOqbX7Z9ycSlCKvQwAAARc"]
[Tue Jul 28 10:01:12.357100 2026] [:error] [pid 23518:tid 140635591919360] [client 104.23.166.83:12898] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amhhyAOqbX7Z9ycSlCKvRAAAAQY"]
[Tue Jul 28 10:01:12.357801 2026] [:error] [pid 23518:tid 140635591919360] [client 104.23.166.83:12898] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amhhyAOqbX7Z9ycSlCKvRAAAAQY"]
[Tue Jul 28 10:01:12.358164 2026] [:error] [pid 23518:tid 140635591919360] [client 104.23.166.83:12898] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amhhyAOqbX7Z9ycSlCKvRAAAAQY"]
[Tue Jul 28 10:01:12.358343 2026] [:error] [pid 23518:tid 140635591919360] [client 104.23.166.83:12898] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /dev/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amhhyAOqbX7Z9ycSlCKvRAAAAQY"]
[Tue Jul 28 10:01:12.425521 2026] [:error] [pid 11209:tid 140635591919360] [client 104.23.166.82:9922] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhhyJIwGwWJ8iALx6LuwQAAAUY"]
[Tue Jul 28 10:01:12.426321 2026] [:error] [pid 11209:tid 140635591919360] [client 104.23.166.82:9922] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhhyJIwGwWJ8iALx6LuwQAAAUY"]
[Tue Jul 28 10:01:12.426844 2026] [:error] [pid 11209:tid 140635591919360] [client 104.23.166.82:9922] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhhyJIwGwWJ8iALx6LuwQAAAUY"]
[Tue Jul 28 10:01:12.489540 2026] [:error] [pid 14756:tid 140635617097472] [client 104.23.166.82:9925] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amhhyJQnCSs8VI2YeM8RhgAAAEM"]
[Tue Jul 28 10:01:12.490455 2026] [:error] [pid 14756:tid 140635617097472] [client 104.23.166.82:9925] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amhhyJQnCSs8VI2YeM8RhgAAAEM"]
[Tue Jul 28 10:01:12.491066 2026] [:error] [pid 14756:tid 140635617097472] [client 104.23.166.82:9925] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amhhyJQnCSs8VI2YeM8RhgAAAEM"]
[Tue Jul 28 10:01:12.491309 2026] [:error] [pid 14756:tid 140635617097472] [client 104.23.166.82:9925] [client 104.23.166.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amhhyJQnCSs8VI2YeM8RhgAAAEM"]
[Tue Jul 28 10:01:12.575133 2026] [:error] [pid 11209:tid 140635499599616] [client 104.23.166.82:9931] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amhhyJIwGwWJ8iALx6LuxAAAAVE"]
[Tue Jul 28 10:01:12.575949 2026] [:error] [pid 11209:tid 140635499599616] [client 104.23.166.82:9931] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amhhyJIwGwWJ8iALx6LuxAAAAVE"]
[Tue Jul 28 10:01:12.576400 2026] [:error] [pid 11209:tid 140635499599616] [client 104.23.166.82:9931] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amhhyJIwGwWJ8iALx6LuxAAAAVE"]
[Tue Jul 28 10:01:12.576577 2026] [:error] [pid 11209:tid 140635499599616] [client 104.23.166.82:9931] [client 104.23.166.82] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amhhyJIwGwWJ8iALx6LuxAAAAVE"]
[Tue Jul 28 10:01:12.637248 2026] [:error] [pid 23518:tid 140635524777728] [client 104.23.166.82:9932] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/info/"] [unique_id "amhhyAOqbX7Z9ycSlCKvRgAAAQ4"]
[Tue Jul 28 10:01:12.638172 2026] [:error] [pid 23518:tid 140635524777728] [client 104.23.166.82:9932] [client 104.23.166.82] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/info/"] [unique_id "amhhyAOqbX7Z9ycSlCKvRgAAAQ4"]
[Tue Jul 28 10:01:12.638706 2026] [:error] [pid 23518:tid 140635524777728] [client 104.23.166.82:9932] [client 104.23.166.82] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/info/"] [unique_id "amhhyAOqbX7Z9ycSlCKvRgAAAQ4"]
[Tue Jul 28 10:01:12.699721 2026] [:error] [pid 11209:tid 140635474421504] [client 104.23.166.83:12900] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amhhyJIwGwWJ8iALx6LuxQAAAVQ"]
[Tue Jul 28 10:01:12.700391 2026] [:error] [pid 11209:tid 140635474421504] [client 104.23.166.83:12900] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amhhyJIwGwWJ8iALx6LuxQAAAVQ"]
[Tue Jul 28 10:01:12.700800 2026] [:error] [pid 11209:tid 140635474421504] [client 104.23.166.83:12900] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amhhyJIwGwWJ8iALx6LuxQAAAVQ"]
[Tue Jul 28 10:01:12.700975 2026] [:error] [pid 11209:tid 140635474421504] [client 104.23.166.83:12900] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /staging/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amhhyJIwGwWJ8iALx6LuxQAAAVQ"]
[Tue Jul 28 10:01:19.325233 2026] [:error] [pid 23518:tid 140635449243392] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvXQAAARc"]
[Tue Jul 28 10:01:19.326000 2026] [:error] [pid 23518:tid 140635449243392] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvXQAAARc"]
[Tue Jul 28 10:01:19.326466 2026] [:error] [pid 23518:tid 140635449243392] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvXQAAARc"]
[Tue Jul 28 10:01:19.326737 2026] [:error] [pid 23518:tid 140635449243392] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvXQAAARc"]
[Tue Jul 28 10:01:19.362571 2026] [:error] [pid 23518:tid 140635583526656] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvXgAAAQc"]
[Tue Jul 28 10:01:19.363341 2026] [:error] [pid 23518:tid 140635583526656] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvXgAAAQc"]
[Tue Jul 28 10:01:19.363935 2026] [:error] [pid 23518:tid 140635583526656] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvXgAAAQc"]
[Tue Jul 28 10:01:19.364156 2026] [:error] [pid 23518:tid 140635583526656] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvXgAAAQc"]
[Tue Jul 28 10:01:19.387255 2026] [:error] [pid 23518:tid 140635516385024] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvXwAAAQ8"]
[Tue Jul 28 10:01:19.388037 2026] [:error] [pid 23518:tid 140635516385024] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvXwAAAQ8"]
[Tue Jul 28 10:01:19.388540 2026] [:error] [pid 23518:tid 140635516385024] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvXwAAAQ8"]
[Tue Jul 28 10:01:19.388817 2026] [:error] [pid 23518:tid 140635516385024] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvXwAAAQ8"]
[Tue Jul 28 10:01:19.410586 2026] [:error] [pid 23518:tid 140635507992320] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amhhzwOqbX7Z9ycSlCKvYAAAARA"]
[Tue Jul 28 10:01:19.411295 2026] [:error] [pid 23518:tid 140635507992320] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amhhzwOqbX7Z9ycSlCKvYAAAARA"]
[Tue Jul 28 10:01:19.411824 2026] [:error] [pid 23518:tid 140635507992320] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amhhzwOqbX7Z9ycSlCKvYAAAARA"]
[Tue Jul 28 10:01:19.436301 2026] [:error] [pid 23518:tid 140635482814208] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvYQAAARM"]
[Tue Jul 28 10:01:19.437133 2026] [:error] [pid 23518:tid 140635482814208] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvYQAAARM"]
[Tue Jul 28 10:01:19.437689 2026] [:error] [pid 23518:tid 140635482814208] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvYQAAARM"]
[Tue Jul 28 10:01:19.437944 2026] [:error] [pid 23518:tid 140635482814208] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvYQAAARM"]
[Tue Jul 28 10:01:19.459590 2026] [:error] [pid 23518:tid 140635558348544] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo/"] [unique_id "amhhzwOqbX7Z9ycSlCKvYgAAAQo"]
[Tue Jul 28 10:01:19.460528 2026] [:error] [pid 23518:tid 140635558348544] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo/"] [unique_id "amhhzwOqbX7Z9ycSlCKvYgAAAQo"]
[Tue Jul 28 10:01:19.460997 2026] [:error] [pid 23518:tid 140635558348544] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo/"] [unique_id "amhhzwOqbX7Z9ycSlCKvYgAAAQo"]
[Tue Jul 28 10:01:19.481666 2026] [:error] [pid 23518:tid 140635524777728] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvYwAAAQ4"]
[Tue Jul 28 10:01:19.482444 2026] [:error] [pid 23518:tid 140635524777728] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvYwAAAQ4"]
[Tue Jul 28 10:01:19.483030 2026] [:error] [pid 23518:tid 140635524777728] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvYwAAAQ4"]
[Tue Jul 28 10:01:19.483283 2026] [:error] [pid 23518:tid 140635524777728] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvYwAAAQ4"]
[Tue Jul 28 10:01:19.505455 2026] [:error] [pid 23518:tid 140635706623744] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvZAAAAQE"]
[Tue Jul 28 10:01:19.506320 2026] [:error] [pid 23518:tid 140635706623744] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvZAAAAQE"]
[Tue Jul 28 10:01:19.506892 2026] [:error] [pid 23518:tid 140635706623744] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvZAAAAQE"]
[Tue Jul 28 10:01:19.507139 2026] [:error] [pid 23518:tid 140635706623744] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvZAAAAQE"]
[Tue Jul 28 10:01:19.528630 2026] [:error] [pid 23518:tid 140635549955840] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/test"] [unique_id "amhhzwOqbX7Z9ycSlCKvZQAAAQs"]
[Tue Jul 28 10:01:19.529355 2026] [:error] [pid 23518:tid 140635549955840] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/test"] [unique_id "amhhzwOqbX7Z9ycSlCKvZQAAAQs"]
[Tue Jul 28 10:01:19.529889 2026] [:error] [pid 23518:tid 140635549955840] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/test"] [unique_id "amhhzwOqbX7Z9ycSlCKvZQAAAQs"]
[Tue Jul 28 10:01:19.551426 2026] [:error] [pid 23518:tid 140635591919360] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhhzwOqbX7Z9ycSlCKvZgAAAQY"]
[Tue Jul 28 10:01:19.552033 2026] [:error] [pid 23518:tid 140635591919360] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhhzwOqbX7Z9ycSlCKvZgAAAQY"]
[Tue Jul 28 10:01:19.552390 2026] [:error] [pid 23518:tid 140635591919360] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhhzwOqbX7Z9ycSlCKvZgAAAQY"]
[Tue Jul 28 10:01:19.552536 2026] [:error] [pid 23518:tid 140635591919360] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amhhzwOqbX7Z9ycSlCKvZgAAAQY"]
[Tue Jul 28 10:01:19.573895 2026] [:error] [pid 23518:tid 140635566741248] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvZwAAAQk"]
[Tue Jul 28 10:01:19.574840 2026] [:error] [pid 23518:tid 140635566741248] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvZwAAAQk"]
[Tue Jul 28 10:01:19.575465 2026] [:error] [pid 23518:tid 140635566741248] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvZwAAAQk"]
[Tue Jul 28 10:01:19.575852 2026] [:error] [pid 23518:tid 140635566741248] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvZwAAAQk"]
[Tue Jul 28 10:01:19.596922 2026] [:error] [pid 23518:tid 140635533170432] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvaAAAAQ0"]
[Tue Jul 28 10:01:19.597732 2026] [:error] [pid 23518:tid 140635533170432] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvaAAAAQ0"]
[Tue Jul 28 10:01:19.598290 2026] [:error] [pid 23518:tid 140635533170432] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvaAAAAQ0"]
[Tue Jul 28 10:01:19.598597 2026] [:error] [pid 23518:tid 140635533170432] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /dev/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvaAAAAQ0"]
[Tue Jul 28 10:01:19.620013 2026] [:error] [pid 23518:tid 140635499599616] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhhzwOqbX7Z9ycSlCKvaQAAARE"]
[Tue Jul 28 10:01:19.620807 2026] [:error] [pid 23518:tid 140635499599616] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhhzwOqbX7Z9ycSlCKvaQAAARE"]
[Tue Jul 28 10:01:19.621330 2026] [:error] [pid 23518:tid 140635499599616] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhhzwOqbX7Z9ycSlCKvaQAAARE"]
[Tue Jul 28 10:01:19.642563 2026] [:error] [pid 23518:tid 140635449243392] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvagAAARc"]
[Tue Jul 28 10:01:19.643076 2026] [:error] [pid 23518:tid 140635449243392] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvagAAARc"]
[Tue Jul 28 10:01:19.643487 2026] [:error] [pid 23518:tid 140635449243392] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvagAAARc"]
[Tue Jul 28 10:01:19.643731 2026] [:error] [pid 23518:tid 140635449243392] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvagAAARc"]
[Tue Jul 28 10:01:19.664187 2026] [:error] [pid 23518:tid 140635583526656] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amhhzwOqbX7Z9ycSlCKvawAAAQc"]
[Tue Jul 28 10:01:19.664895 2026] [:error] [pid 23518:tid 140635583526656] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amhhzwOqbX7Z9ycSlCKvawAAAQc"]
[Tue Jul 28 10:01:19.665409 2026] [:error] [pid 23518:tid 140635583526656] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amhhzwOqbX7Z9ycSlCKvawAAAQc"]
[Tue Jul 28 10:01:19.665676 2026] [:error] [pid 23518:tid 140635583526656] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amhhzwOqbX7Z9ycSlCKvawAAAQc"]
[Tue Jul 28 10:01:19.685843 2026] [:error] [pid 23518:tid 140635516385024] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/info/"] [unique_id "amhhzwOqbX7Z9ycSlCKvbAAAAQ8"]
[Tue Jul 28 10:01:19.686409 2026] [:error] [pid 23518:tid 140635516385024] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/info/"] [unique_id "amhhzwOqbX7Z9ycSlCKvbAAAAQ8"]
[Tue Jul 28 10:01:19.686878 2026] [:error] [pid 23518:tid 140635516385024] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/info/"] [unique_id "amhhzwOqbX7Z9ycSlCKvbAAAAQ8"]
[Tue Jul 28 10:01:19.707280 2026] [:error] [pid 23518:tid 140635575133952] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvbgAAAQg"]
[Tue Jul 28 10:01:19.708030 2026] [:error] [pid 23518:tid 140635575133952] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvbgAAAQg"]
[Tue Jul 28 10:01:19.708534 2026] [:error] [pid 23518:tid 140635575133952] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvbgAAAQg"]
[Tue Jul 28 10:01:19.708835 2026] [:error] [pid 23518:tid 140635575133952] [client 172.70.46.165:12904] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /staging/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amhhzwOqbX7Z9ycSlCKvbgAAAQg"]
[Tue Jul 28 10:04:52.993784 2026] [:error] [pid 11209:tid 140635600312064] [client 141.101.98.192:13930] [client 141.101.98.192] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhipJIwGwWJ8iALx6LyrgAAAUU"]
[Tue Jul 28 10:04:52.994695 2026] [:error] [pid 11209:tid 140635600312064] [client 141.101.98.192:13930] [client 141.101.98.192] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhipJIwGwWJ8iALx6LyrgAAAUU"]
[Tue Jul 28 10:04:52.995241 2026] [:error] [pid 11209:tid 140635600312064] [client 141.101.98.192:13930] [client 141.101.98.192] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhipJIwGwWJ8iALx6LyrgAAAUU"]
[Tue Jul 28 10:04:53.007324 2026] [:error] [pid 11209:tid 140635600312064] [client 141.101.98.192:13930] [client 141.101.98.192] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:handl_original_ref. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: ://premierpoolservice.com/pool-service/california/central- found within REQUEST_COOKIES:handl_original_ref: https://premierpoolservice.com/pool-service/california/central-valley"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhipJIwGwWJ8iALx6LyrgAAAUU"]
[Tue Jul 28 10:04:53.007475 2026] [:error] [pid 11209:tid 140635600312064] [client 141.101.98.192:13930] [client 141.101.98.192] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:handl_ref. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: ://premierpoolservice.com/pool-service/california/central- found within REQUEST_COOKIES:handl_ref: https://premierpoolservice.com/pool-service/california/central-valley"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhipJIwGwWJ8iALx6LyrgAAAUU"]
[Tue Jul 28 10:04:53.007592 2026] [:error] [pid 11209:tid 140635600312064] [client 141.101.98.192:13930] [client 141.101.98.192] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:organic_source. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: ://premierpoolservice.com/pool-service/california/central- found within REQUEST_COOKIES:organic_source: https://premierpoolservice.com/pool-service/california/central-valley"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhipJIwGwWJ8iALx6LyrgAAAUU"]
[Tue Jul 28 10:04:53.478023 2026] [:error] [pid 23518:tid 140635440850688] [client 172.64.192.180:10144] [client 172.64.192.180] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhipQOqbX7Z9ycSlCK1hQAAARg"]
[Tue Jul 28 10:04:53.478857 2026] [:error] [pid 23518:tid 140635440850688] [client 172.64.192.180:10144] [client 172.64.192.180] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhipQOqbX7Z9ycSlCK1hQAAARg"]
[Tue Jul 28 10:04:53.479325 2026] [:error] [pid 23518:tid 140635440850688] [client 172.64.192.180:10144] [client 172.64.192.180] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amhipQOqbX7Z9ycSlCK1hQAAARg"]
[Tue Jul 28 10:39:08.490274 2026] [:error] [pid 11209:tid 140635457636096] [client 104.23.243.18:10719] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amhqrJIwGwWJ8iALx6IUmwAAAVY"]
[Tue Jul 28 10:39:08.501661 2026] [:error] [pid 11209:tid 140635457636096] [client 104.23.243.18:10719] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amhqrJIwGwWJ8iALx6IUmwAAAVY"]
[Tue Jul 28 10:39:08.502170 2026] [:error] [pid 11209:tid 140635457636096] [client 104.23.243.18:10719] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amhqrJIwGwWJ8iALx6IUmwAAAVY"]
[Tue Jul 28 11:24:36.111684 2026] [:error] [pid 14755:tid 140635457636096] [client 104.23.197.76:11175] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amh1VKf64wRy3HlU5UPXVQAAABY"]
[Tue Jul 28 11:24:36.113071 2026] [:error] [pid 14755:tid 140635457636096] [client 104.23.197.76:11175] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amh1VKf64wRy3HlU5UPXVQAAABY"]
[Tue Jul 28 11:24:36.113595 2026] [:error] [pid 14755:tid 140635457636096] [client 104.23.197.76:11175] [client 104.23.197.76] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amh1VKf64wRy3HlU5UPXVQAAABY"]
[Tue Jul 28 11:37:10.095185 2026] [:error] [pid 11209:tid 140635457636096] [client 172.68.225.10:13080] [client 172.68.225.10] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh4RpIwGwWJ8iALx6JwOAAAAVY"]
[Tue Jul 28 11:37:10.100144 2026] [:error] [pid 11209:tid 140635457636096] [client 172.68.225.10:13080] [client 172.68.225.10] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh4RpIwGwWJ8iALx6JwOAAAAVY"]
[Tue Jul 28 11:37:10.100797 2026] [:error] [pid 11209:tid 140635457636096] [client 172.68.225.10:13080] [client 172.68.225.10] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh4RpIwGwWJ8iALx6JwOAAAAVY"]
[Tue Jul 28 11:40:52.635130 2026] [:error] [pid 11209:tid 140635482814208] [client 172.71.144.54:10509] [client 172.71.144.54] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amh5JJIwGwWJ8iALx6J3zgAAAVM"]
[Tue Jul 28 11:40:52.636131 2026] [:error] [pid 11209:tid 140635482814208] [client 172.71.144.54:10509] [client 172.71.144.54] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amh5JJIwGwWJ8iALx6J3zgAAAVM"]
[Tue Jul 28 11:40:52.636748 2026] [:error] [pid 11209:tid 140635482814208] [client 172.71.144.54:10509] [client 172.71.144.54] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amh5JJIwGwWJ8iALx6J3zgAAAVM"]
[Tue Jul 28 11:57:06.908333 2026] [:error] [pid 11209:tid 140635549955840] [client 172.70.143.207:10949] [client 172.70.143.207] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh88pIwGwWJ8iALx6KP6gAAAUs"]
[Tue Jul 28 11:57:06.908862 2026] [:error] [pid 11209:tid 140635549955840] [client 172.70.143.207:10949] [client 172.70.143.207] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh88pIwGwWJ8iALx6KP6gAAAUs"]
[Tue Jul 28 11:57:06.909269 2026] [:error] [pid 11209:tid 140635549955840] [client 172.70.143.207:10949] [client 172.70.143.207] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh88pIwGwWJ8iALx6KP6gAAAUs"]
[Tue Jul 28 11:57:08.862869 2026] [:error] [pid 14757:tid 140635516385024] [client 172.68.134.8:12062] [client 172.68.134.8] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh89B8tpddNF-UrsIXyowAAAI8"]
[Tue Jul 28 11:57:08.863705 2026] [:error] [pid 14757:tid 140635516385024] [client 172.68.134.8:12062] [client 172.68.134.8] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh89B8tpddNF-UrsIXyowAAAI8"]
[Tue Jul 28 11:57:08.864172 2026] [:error] [pid 14757:tid 140635516385024] [client 172.68.134.8:12062] [client 172.68.134.8] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh89B8tpddNF-UrsIXyowAAAI8"]
[Tue Jul 28 12:04:50.215268 2026] [:error] [pid 14859:tid 140635706623744] [client 104.23.166.93:13460] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh-wrBlXBlS8_TwuUZGoAAAAME"]
[Tue Jul 28 12:04:50.216041 2026] [:error] [pid 14859:tid 140635706623744] [client 104.23.166.93:13460] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh-wrBlXBlS8_TwuUZGoAAAAME"]
[Tue Jul 28 12:04:50.216707 2026] [:error] [pid 14859:tid 140635706623744] [client 104.23.166.93:13460] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh-wrBlXBlS8_TwuUZGoAAAAME"]
[Tue Jul 28 12:04:50.346802 2026] [:error] [pid 11209:tid 140635533170432] [client 172.71.183.40:11761] [client 172.71.183.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amh-wpIwGwWJ8iALx6KYywAAAU0"]
[Tue Jul 28 12:04:50.347737 2026] [:error] [pid 11209:tid 140635533170432] [client 172.71.183.40:11761] [client 172.71.183.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amh-wpIwGwWJ8iALx6KYywAAAU0"]
[Tue Jul 28 12:04:50.348325 2026] [:error] [pid 11209:tid 140635533170432] [client 172.71.183.40:11761] [client 172.71.183.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amh-wpIwGwWJ8iALx6KYywAAAU0"]
[Tue Jul 28 12:04:50.440856 2026] [:error] [pid 14859:tid 140635558348544] [client 104.23.166.93:13460] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application.yml"] [unique_id "amh-wrBlXBlS8_TwuUZGogAAAMo"]
[Tue Jul 28 12:04:50.441770 2026] [:error] [pid 14859:tid 140635558348544] [client 104.23.166.93:13460] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application.yml"] [unique_id "amh-wrBlXBlS8_TwuUZGogAAAMo"]
[Tue Jul 28 12:04:50.442197 2026] [:error] [pid 14859:tid 140635558348544] [client 104.23.166.93:13460] [client 104.23.166.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/application.yml"] [unique_id "amh-wrBlXBlS8_TwuUZGogAAAMo"]
[Tue Jul 28 12:04:50.442298 2026] [:error] [pid 14859:tid 140635558348544] [client 104.23.166.93:13460] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application.yml"] [unique_id "amh-wrBlXBlS8_TwuUZGogAAAMo"]
[Tue Jul 28 12:04:50.484891 2026] [:error] [pid 17371:tid 140635499599616] [client 104.23.166.90:12765] [client 104.23.166.90] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amh-wm6-l8v9r5wWdfChFgAAAZE"]
[Tue Jul 28 12:04:50.485756 2026] [:error] [pid 17371:tid 140635499599616] [client 104.23.166.90:12765] [client 104.23.166.90] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amh-wm6-l8v9r5wWdfChFgAAAZE"]
[Tue Jul 28 12:04:50.486145 2026] [:error] [pid 17371:tid 140635499599616] [client 104.23.166.90:12765] [client 104.23.166.90] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amh-wm6-l8v9r5wWdfChFgAAAZE"]
[Tue Jul 28 12:04:50.486266 2026] [:error] [pid 17371:tid 140635499599616] [client 104.23.166.90:12765] [client 104.23.166.90] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amh-wm6-l8v9r5wWdfChFgAAAZE"]
[Tue Jul 28 12:04:50.486504 2026] [:error] [pid 17371:tid 140635499599616] [client 104.23.166.90:12765] [client 104.23.166.90] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amh-wm6-l8v9r5wWdfChFgAAAZE"]
[Tue Jul 28 12:04:50.488941 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.90:12760] [client 104.23.166.90] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amh-wpQnCSs8VI2YeM8w8AAAAEQ"]
[Tue Jul 28 12:04:50.489654 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.90:12760] [client 104.23.166.90] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amh-wpQnCSs8VI2YeM8w8AAAAEQ"]
[Tue Jul 28 12:04:50.490086 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.90:12760] [client 104.23.166.90] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amh-wpQnCSs8VI2YeM8w8AAAAEQ"]
[Tue Jul 28 12:04:50.490189 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.90:12760] [client 104.23.166.90] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amh-wpQnCSs8VI2YeM8w8AAAAEQ"]
[Tue Jul 28 12:04:50.490436 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.90:12760] [client 104.23.166.90] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amh-wpQnCSs8VI2YeM8w8AAAAEQ"]
[Tue Jul 28 12:04:50.493597 2026] [:error] [pid 17371:tid 140635507992320] [client 104.23.166.91:10489] [client 104.23.166.91] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/debug/pprof/cmdline"] [unique_id "amh-wm6-l8v9r5wWdfChFwAAAZA"]
[Tue Jul 28 12:04:50.494327 2026] [:error] [pid 17371:tid 140635507992320] [client 104.23.166.91:10489] [client 104.23.166.91] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/debug/pprof/cmdline"] [unique_id "amh-wm6-l8v9r5wWdfChFwAAAZA"]
[Tue Jul 28 12:04:50.494757 2026] [:error] [pid 17371:tid 140635507992320] [client 104.23.166.91:10489] [client 104.23.166.91] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/debug/pprof/cmdline"] [unique_id "amh-wm6-l8v9r5wWdfChFwAAAZA"]
[Tue Jul 28 12:04:50.494853 2026] [:error] [pid 17371:tid 140635507992320] [client 104.23.166.91:10489] [client 104.23.166.91] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/debug/pprof/cmdline"] [unique_id "amh-wm6-l8v9r5wWdfChFwAAAZA"]
[Tue Jul 28 12:04:52.383634 2026] [:error] [pid 17371:tid 140635566741248] [client 104.23.166.90:12765] [client 104.23.166.90] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amh-xG6-l8v9r5wWdfChIAAAAYk"]
[Tue Jul 28 12:04:52.384467 2026] [:error] [pid 17371:tid 140635566741248] [client 104.23.166.90:12765] [client 104.23.166.90] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amh-xG6-l8v9r5wWdfChIAAAAYk"]
[Tue Jul 28 12:04:52.385070 2026] [:error] [pid 17371:tid 140635566741248] [client 104.23.166.90:12765] [client 104.23.166.90] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amh-xG6-l8v9r5wWdfChIAAAAYk"]
[Tue Jul 28 12:04:57.658199 2026] [:error] [pid 14757:tid 140635482814208] [client 104.23.166.91:12737] [client 104.23.166.91] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/storage/logs/laravel.log"] [unique_id "amh-yR8tpddNF-UrsIX1XgAAAJM"]
[Tue Jul 28 12:04:57.659079 2026] [:error] [pid 14757:tid 140635482814208] [client 104.23.166.91:12737] [client 104.23.166.91] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/storage/logs/laravel.log"] [unique_id "amh-yR8tpddNF-UrsIX1XgAAAJM"]
[Tue Jul 28 12:04:57.659627 2026] [:error] [pid 14757:tid 140635482814208] [client 104.23.166.91:12737] [client 104.23.166.91] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/storage/logs/laravel.log"] [unique_id "amh-yR8tpddNF-UrsIX1XgAAAJM"]
[Tue Jul 28 12:04:57.661428 2026] [:error] [pid 11209:tid 140635533170432] [client 104.23.166.92:13583] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/secrets.yml"] [unique_id "amh-yZIwGwWJ8iALx6KY2AAAAU0"]
[Tue Jul 28 12:04:57.661807 2026] [:error] [pid 11209:tid 140635449243392] [client 104.23.166.93:12589] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application.properties"] [unique_id "amh-yZIwGwWJ8iALx6KY2QAAAVc"]
[Tue Jul 28 12:04:57.662186 2026] [:error] [pid 11209:tid 140635533170432] [client 104.23.166.92:13583] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/secrets.yml"] [unique_id "amh-yZIwGwWJ8iALx6KY2AAAAU0"]
[Tue Jul 28 12:04:57.662305 2026] [:error] [pid 11209:tid 140635449243392] [client 104.23.166.93:12589] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application.properties"] [unique_id "amh-yZIwGwWJ8iALx6KY2QAAAVc"]
[Tue Jul 28 12:04:57.662666 2026] [:error] [pid 11209:tid 140635533170432] [client 104.23.166.92:13583] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/secrets.yml"] [unique_id "amh-yZIwGwWJ8iALx6KY2AAAAU0"]
[Tue Jul 28 12:04:57.662695 2026] [:error] [pid 11209:tid 140635449243392] [client 104.23.166.93:12589] [client 104.23.166.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/application.properties"] [unique_id "amh-yZIwGwWJ8iALx6KY2QAAAVc"]
[Tue Jul 28 12:04:57.662804 2026] [:error] [pid 11209:tid 140635449243392] [client 104.23.166.93:12589] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application.properties"] [unique_id "amh-yZIwGwWJ8iALx6KY2QAAAVc"]
[Tue Jul 28 12:04:57.664453 2026] [:error] [pid 14757:tid 140635698231040] [client 104.23.166.90:12932] [client 104.23.166.90] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amh-yR8tpddNF-UrsIX1XwAAAII"]
[Tue Jul 28 12:04:57.665122 2026] [:error] [pid 14757:tid 140635698231040] [client 104.23.166.90:12932] [client 104.23.166.90] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amh-yR8tpddNF-UrsIX1XwAAAII"]
[Tue Jul 28 12:04:57.665600 2026] [:error] [pid 14757:tid 140635698231040] [client 104.23.166.90:12932] [client 104.23.166.90] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "amh-yR8tpddNF-UrsIX1XwAAAII"]
[Tue Jul 28 12:04:57.686470 2026] [:error] [pid 14756:tid 140635558348544] [client 104.23.166.93:12590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/secrets.yml"] [unique_id "amh-yZQnCSs8VI2YeM8w9gAAAEo"]
[Tue Jul 28 12:04:57.687339 2026] [:error] [pid 14756:tid 140635558348544] [client 104.23.166.93:12590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/secrets.yml"] [unique_id "amh-yZQnCSs8VI2YeM8w9gAAAEo"]
[Tue Jul 28 12:04:57.687891 2026] [:error] [pid 14756:tid 140635558348544] [client 104.23.166.93:12590] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets.yml"] [unique_id "amh-yZQnCSs8VI2YeM8w9gAAAEo"]
[Tue Jul 28 12:04:57.690315 2026] [:error] [pid 23518:tid 140635706623744] [client 104.23.166.90:12938] [client 104.23.166.90] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/application.properties"] [unique_id "amh-yQOqbX7Z9ycSlCIaMgAAAQE"]
[Tue Jul 28 12:04:57.691159 2026] [:error] [pid 23518:tid 140635706623744] [client 104.23.166.90:12938] [client 104.23.166.90] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/application.properties"] [unique_id "amh-yQOqbX7Z9ycSlCIaMgAAAQE"]
[Tue Jul 28 12:04:57.691637 2026] [:error] [pid 23518:tid 140635706623744] [client 104.23.166.90:12938] [client 104.23.166.90] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/config/application.properties"] [unique_id "amh-yQOqbX7Z9ycSlCIaMgAAAQE"]
[Tue Jul 28 12:04:57.691770 2026] [:error] [pid 23518:tid 140635706623744] [client 104.23.166.90:12938] [client 104.23.166.90] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/application.properties"] [unique_id "amh-yQOqbX7Z9ycSlCIaMgAAAQE"]
[Tue Jul 28 12:05:00.853627 2026] [:error] [pid 14757:tid 140635706623744] [client 104.23.166.91:12737] [client 104.23.166.91] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amh-zB8tpddNF-UrsIX1YwAAAIE"]
[Tue Jul 28 12:05:00.854247 2026] [:error] [pid 14757:tid 140635706623744] [client 104.23.166.91:12737] [client 104.23.166.91] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amh-zB8tpddNF-UrsIX1YwAAAIE"]
[Tue Jul 28 12:05:00.854643 2026] [:error] [pid 14757:tid 140635706623744] [client 104.23.166.91:12737] [client 104.23.166.91] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amh-zB8tpddNF-UrsIX1YwAAAIE"]
[Tue Jul 28 12:05:00.854751 2026] [:error] [pid 14757:tid 140635706623744] [client 104.23.166.91:12737] [client 104.23.166.91] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amh-zB8tpddNF-UrsIX1YwAAAIE"]
[Tue Jul 28 12:05:00.855017 2026] [:error] [pid 14757:tid 140635706623744] [client 104.23.166.91:12737] [client 104.23.166.91] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amh-zB8tpddNF-UrsIX1YwAAAIE"]
[Tue Jul 28 12:05:00.857190 2026] [:error] [pid 14757:tid 140635566741248] [client 104.23.166.90:12932] [client 104.23.166.90] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amh-zB8tpddNF-UrsIX1ZAAAAIk"]
[Tue Jul 28 12:05:00.857891 2026] [:error] [pid 14757:tid 140635566741248] [client 104.23.166.90:12932] [client 104.23.166.90] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amh-zB8tpddNF-UrsIX1ZAAAAIk"]
[Tue Jul 28 12:05:00.858297 2026] [:error] [pid 14757:tid 140635566741248] [client 104.23.166.90:12932] [client 104.23.166.90] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amh-zB8tpddNF-UrsIX1ZAAAAIk"]
[Tue Jul 28 12:05:00.858393 2026] [:error] [pid 14757:tid 140635566741248] [client 104.23.166.90:12932] [client 104.23.166.90] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amh-zB8tpddNF-UrsIX1ZAAAAIk"]
[Tue Jul 28 12:05:00.858659 2026] [:error] [pid 14757:tid 140635566741248] [client 104.23.166.90:12932] [client 104.23.166.90] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amh-zB8tpddNF-UrsIX1ZAAAAIk"]
[Tue Jul 28 12:05:00.868176 2026] [:error] [pid 11209:tid 140635474421504] [client 104.23.166.93:12589] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amh-zJIwGwWJ8iALx6KY3wAAAVQ"]
[Tue Jul 28 12:05:00.868834 2026] [:error] [pid 11209:tid 140635474421504] [client 104.23.166.93:12589] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amh-zJIwGwWJ8iALx6KY3wAAAVQ"]
[Tue Jul 28 12:05:00.869253 2026] [:error] [pid 11209:tid 140635474421504] [client 104.23.166.93:12589] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amh-zJIwGwWJ8iALx6KY3wAAAVQ"]
[Tue Jul 28 12:05:00.869400 2026] [:error] [pid 11209:tid 140635474421504] [client 104.23.166.93:12589] [client 104.23.166.93] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amh-zJIwGwWJ8iALx6KY3wAAAVQ"]
[Tue Jul 28 12:05:00.925369 2026] [:error] [pid 11209:tid 140635524777728] [client 104.23.166.92:13583] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amh-zJIwGwWJ8iALx6KY4AAAAU4"]
[Tue Jul 28 12:05:00.925491 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.166.90:12938] [client 104.23.166.90] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amh-zAOqbX7Z9ycSlCIaOgAAAQQ"]
[Tue Jul 28 12:05:00.926230 2026] [:error] [pid 11209:tid 140635524777728] [client 104.23.166.92:13583] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amh-zJIwGwWJ8iALx6KY4AAAAU4"]
[Tue Jul 28 12:05:00.926245 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.166.90:12938] [client 104.23.166.90] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amh-zAOqbX7Z9ycSlCIaOgAAAQQ"]
[Tue Jul 28 12:05:00.926670 2026] [:error] [pid 11209:tid 140635524777728] [client 104.23.166.92:13583] [client 104.23.166.92] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amh-zJIwGwWJ8iALx6KY4AAAAU4"]
[Tue Jul 28 12:05:00.926696 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.166.90:12938] [client 104.23.166.90] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amh-zAOqbX7Z9ycSlCIaOgAAAQQ"]
[Tue Jul 28 12:05:00.926777 2026] [:error] [pid 11209:tid 140635524777728] [client 104.23.166.92:13583] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amh-zJIwGwWJ8iALx6KY4AAAAU4"]
[Tue Jul 28 12:05:00.926799 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.166.90:12938] [client 104.23.166.90] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amh-zAOqbX7Z9ycSlCIaOgAAAQQ"]
[Tue Jul 28 12:05:00.926983 2026] [:error] [pid 23518:tid 140635608704768] [client 104.23.166.90:12938] [client 104.23.166.90] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amh-zAOqbX7Z9ycSlCIaOgAAAQQ"]
[Tue Jul 28 12:05:00.926992 2026] [:error] [pid 11209:tid 140635524777728] [client 104.23.166.92:13583] [client 104.23.166.92] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amh-zJIwGwWJ8iALx6KY4AAAAU4"]
[Tue Jul 28 12:05:00.930843 2026] [:error] [pid 14756:tid 140635516385024] [client 104.23.166.93:12590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amh-zJQnCSs8VI2YeM8w-wAAAE8"]
[Tue Jul 28 12:05:00.931713 2026] [:error] [pid 14756:tid 140635516385024] [client 104.23.166.93:12590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amh-zJQnCSs8VI2YeM8w-wAAAE8"]
[Tue Jul 28 12:05:00.932144 2026] [:error] [pid 14756:tid 140635516385024] [client 104.23.166.93:12590] [client 104.23.166.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amh-zJQnCSs8VI2YeM8w-wAAAE8"]
[Tue Jul 28 12:05:00.932252 2026] [:error] [pid 14756:tid 140635516385024] [client 104.23.166.93:12590] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amh-zJQnCSs8VI2YeM8w-wAAAE8"]
[Tue Jul 28 12:05:00.932481 2026] [:error] [pid 14756:tid 140635516385024] [client 104.23.166.93:12590] [client 104.23.166.93] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amh-zJQnCSs8VI2YeM8w-wAAAE8"]
[Tue Jul 28 12:05:10.458499 2026] [:error] [pid 11209:tid 140635558348544] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin/credentials.json"] [unique_id "amh-1pIwGwWJ8iALx6KY7wAAAUo"]
[Tue Jul 28 12:05:10.459335 2026] [:error] [pid 11209:tid 140635558348544] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin/credentials.json"] [unique_id "amh-1pIwGwWJ8iALx6KY7wAAAUo"]
[Tue Jul 28 12:05:10.459849 2026] [:error] [pid 11209:tid 140635558348544] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin/credentials.json"] [unique_id "amh-1pIwGwWJ8iALx6KY7wAAAUo"]
[Tue Jul 28 12:05:10.510695 2026] [:error] [pid 11209:tid 140635566741248] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/loadable-stats.json"] [unique_id "amh-1pIwGwWJ8iALx6KY8AAAAUk"]
[Tue Jul 28 12:05:10.511490 2026] [:error] [pid 11209:tid 140635566741248] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/loadable-stats.json"] [unique_id "amh-1pIwGwWJ8iALx6KY8AAAAUk"]
[Tue Jul 28 12:05:10.523847 2026] [:error] [pid 11209:tid 140635566741248] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/loadable-stats.json"] [unique_id "amh-1pIwGwWJ8iALx6KY8AAAAUk"]
[Tue Jul 28 12:05:10.547578 2026] [:error] [pid 11209:tid 140635449243392] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/asset-manifest.json"] [unique_id "amh-1pIwGwWJ8iALx6KY8QAAAVc"]
[Tue Jul 28 12:05:10.548429 2026] [:error] [pid 11209:tid 140635449243392] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/asset-manifest.json"] [unique_id "amh-1pIwGwWJ8iALx6KY8QAAAVc"]
[Tue Jul 28 12:05:10.549092 2026] [:error] [pid 11209:tid 140635449243392] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/asset-manifest.json"] [unique_id "amh-1pIwGwWJ8iALx6KY8QAAAVc"]
[Tue Jul 28 12:05:10.552508 2026] [:error] [pid 17371:tid 140635516385024] [client 104.23.166.93:11597] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/manifest.json"] [unique_id "amh-1m6-l8v9r5wWdfChYgAAAY8"]
[Tue Jul 28 12:05:10.553327 2026] [:error] [pid 17371:tid 140635516385024] [client 104.23.166.93:11597] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/manifest.json"] [unique_id "amh-1m6-l8v9r5wWdfChYgAAAY8"]
[Tue Jul 28 12:05:10.553973 2026] [:error] [pid 17371:tid 140635516385024] [client 104.23.166.93:11597] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/manifest.json"] [unique_id "amh-1m6-l8v9r5wWdfChYgAAAY8"]
[Tue Jul 28 12:05:11.341651 2026] [:error] [pid 11209:tid 140635440850688] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/build-manifest.json"] [unique_id "amh-15IwGwWJ8iALx6KY9wAAAVg"]
[Tue Jul 28 12:05:11.342447 2026] [:error] [pid 11209:tid 140635440850688] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/build-manifest.json"] [unique_id "amh-15IwGwWJ8iALx6KY9wAAAVg"]
[Tue Jul 28 12:05:11.343100 2026] [:error] [pid 11209:tid 140635440850688] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/build-manifest.json"] [unique_id "amh-15IwGwWJ8iALx6KY9wAAAVg"]
[Tue Jul 28 12:05:11.425271 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_next/build-manifest.json"] [unique_id "amh-15IwGwWJ8iALx6KY-AAAAUA"]
[Tue Jul 28 12:05:11.426124 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_next/build-manifest.json"] [unique_id "amh-15IwGwWJ8iALx6KY-AAAAUA"]
[Tue Jul 28 12:05:11.426776 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_next/build-manifest.json"] [unique_id "amh-15IwGwWJ8iALx6KY-AAAAUA"]
[Tue Jul 28 12:05:11.468245 2026] [:error] [pid 14755:tid 140635482814208] [client 141.101.76.31:13562] [client 141.101.76.31] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_next/static/buildManifest.js"] [unique_id "amh-16f64wRy3HlU5UP-tAAAABM"]
[Tue Jul 28 12:05:11.468851 2026] [:error] [pid 14755:tid 140635482814208] [client 141.101.76.31:13562] [client 141.101.76.31] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_next/static/buildManifest.js"] [unique_id "amh-16f64wRy3HlU5UP-tAAAABM"]
[Tue Jul 28 12:05:11.469423 2026] [:error] [pid 14755:tid 140635482814208] [client 141.101.76.31:13562] [client 141.101.76.31] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_next/static/buildManifest.js"] [unique_id "amh-16f64wRy3HlU5UP-tAAAABM"]
[Tue Jul 28 12:05:16.077363 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/__/firebase/init.json"] [unique_id "amh-3JIwGwWJ8iALx6KY_AAAAUA"]
[Tue Jul 28 12:05:16.078000 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/__/firebase/init.json"] [unique_id "amh-3JIwGwWJ8iALx6KY_AAAAUA"]
[Tue Jul 28 12:05:16.078340 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/__/firebase/init.json"] [unique_id "amh-3JIwGwWJ8iALx6KY_AAAAUA"]
[Tue Jul 28 12:05:16.080080 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/settings"] [unique_id "amh-3JIwGwWJ8iALx6KY_QAAAUA"]
[Tue Jul 28 12:05:16.080487 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/settings"] [unique_id "amh-3JIwGwWJ8iALx6KY_QAAAUA"]
[Tue Jul 28 12:05:16.080776 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/api/settings"] [unique_id "amh-3JIwGwWJ8iALx6KY_QAAAUA"]
[Tue Jul 28 12:05:16.080845 2026] [:error] [pid 11209:tid 140635715016448] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/settings"] [unique_id "amh-3JIwGwWJ8iALx6KY_QAAAUA"]
[Tue Jul 28 12:05:16.112071 2026] [:error] [pid 14756:tid 140635558348544] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amh-3JQnCSs8VI2YeM8xDwAAAEo"]
[Tue Jul 28 12:05:16.112975 2026] [:error] [pid 14756:tid 140635558348544] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amh-3JQnCSs8VI2YeM8xDwAAAEo"]
[Tue Jul 28 12:05:16.113510 2026] [:error] [pid 14756:tid 140635558348544] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amh-3JQnCSs8VI2YeM8xDwAAAEo"]
[Tue Jul 28 12:05:16.113668 2026] [:error] [pid 14756:tid 140635558348544] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amh-3JQnCSs8VI2YeM8xDwAAAEo"]
[Tue Jul 28 12:05:16.116079 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/v1/graphql"] [unique_id "amh-3JQnCSs8VI2YeM8xEAAAAEQ"]
[Tue Jul 28 12:05:16.116722 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/v1/graphql"] [unique_id "amh-3JQnCSs8VI2YeM8xEAAAAEQ"]
[Tue Jul 28 12:05:16.117050 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/v1/graphql"] [unique_id "amh-3JQnCSs8VI2YeM8xEAAAAEQ"]
[Tue Jul 28 12:05:16.117127 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/v1/graphql"] [unique_id "amh-3JQnCSs8VI2YeM8xEAAAAEQ"]
[Tue Jul 28 12:05:16.129287 2026] [:error] [pid 14756:tid 140635617097472] [client 172.71.99.40:12840] [client 172.71.99.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amh-3JQnCSs8VI2YeM8xEQAAAEM"]
[Tue Jul 28 12:05:16.130111 2026] [:error] [pid 14756:tid 140635617097472] [client 172.71.99.40:12840] [client 172.71.99.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amh-3JQnCSs8VI2YeM8xEQAAAEM"]
[Tue Jul 28 12:05:16.130526 2026] [:error] [pid 14756:tid 140635617097472] [client 172.71.99.40:12840] [client 172.71.99.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amh-3JQnCSs8VI2YeM8xEQAAAEM"]
[Tue Jul 28 12:05:16.132066 2026] [:error] [pid 14756:tid 140635575133952] [client 104.23.166.92:11579] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amh-3JQnCSs8VI2YeM8xEgAAAEg"]
[Tue Jul 28 12:05:16.132678 2026] [:error] [pid 14756:tid 140635575133952] [client 104.23.166.92:11579] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amh-3JQnCSs8VI2YeM8xEgAAAEg"]
[Tue Jul 28 12:05:16.133206 2026] [:error] [pid 14756:tid 140635575133952] [client 104.23.166.92:11579] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "amh-3JQnCSs8VI2YeM8xEgAAAEg"]
[Tue Jul 28 12:05:17.350008 2026] [:error] [pid 11209:tid 140635698231040] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/jwks.json"] [unique_id "amh-3ZIwGwWJ8iALx6KZAgAAAUI"]
[Tue Jul 28 12:05:17.350817 2026] [:error] [pid 11209:tid 140635698231040] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/jwks.json"] [unique_id "amh-3ZIwGwWJ8iALx6KZAgAAAUI"]
[Tue Jul 28 12:05:17.351264 2026] [:error] [pid 11209:tid 140635698231040] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.well-known/jwks.json"] [unique_id "amh-3ZIwGwWJ8iALx6KZAgAAAUI"]
[Tue Jul 28 12:05:17.351422 2026] [:error] [pid 11209:tid 140635698231040] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/jwks.json"] [unique_id "amh-3ZIwGwWJ8iALx6KZAgAAAUI"]
[Tue Jul 28 12:05:17.397906 2026] [:error] [pid 11209:tid 140635575133952] [client 162.159.113.161:12789] [client 162.159.113.161] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env.js"] [unique_id "amh-3ZIwGwWJ8iALx6KZBAAAAUg"]
[Tue Jul 28 12:05:17.398817 2026] [:error] [pid 11209:tid 140635575133952] [client 162.159.113.161:12789] [client 162.159.113.161] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env.js"] [unique_id "amh-3ZIwGwWJ8iALx6KZBAAAAUg"]
[Tue Jul 28 12:05:17.399312 2026] [:error] [pid 11209:tid 140635575133952] [client 162.159.113.161:12789] [client 162.159.113.161] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/env.js"] [unique_id "amh-3ZIwGwWJ8iALx6KZBAAAAUg"]
[Tue Jul 28 12:05:17.424380 2026] [:error] [pid 11209:tid 140635566741248] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env.json"] [unique_id "amh-3ZIwGwWJ8iALx6KZBQAAAUk"]
[Tue Jul 28 12:05:17.425178 2026] [:error] [pid 11209:tid 140635566741248] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env.json"] [unique_id "amh-3ZIwGwWJ8iALx6KZBQAAAUk"]
[Tue Jul 28 12:05:17.425653 2026] [:error] [pid 11209:tid 140635566741248] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/env.json"] [unique_id "amh-3ZIwGwWJ8iALx6KZBQAAAUk"]
[Tue Jul 28 12:05:17.429387 2026] [:error] [pid 14756:tid 140635491206912] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "amh-3ZQnCSs8VI2YeM8xFAAAAFI"]
[Tue Jul 28 12:05:17.430112 2026] [:error] [pid 14756:tid 140635491206912] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "amh-3ZQnCSs8VI2YeM8xFAAAAFI"]
[Tue Jul 28 12:05:17.430607 2026] [:error] [pid 14756:tid 140635491206912] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "amh-3ZQnCSs8VI2YeM8xFAAAAFI"]
[Tue Jul 28 12:05:17.430744 2026] [:error] [pid 14756:tid 140635491206912] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "amh-3ZQnCSs8VI2YeM8xFAAAAFI"]
[Tue Jul 28 12:05:17.481930 2026] [:error] [pid 14756:tid 140635516385024] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/firebase-config.json"] [unique_id "amh-3ZQnCSs8VI2YeM8xFgAAAE8"]
[Tue Jul 28 12:05:17.482875 2026] [:error] [pid 14756:tid 140635516385024] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/firebase-config.json"] [unique_id "amh-3ZQnCSs8VI2YeM8xFgAAAE8"]
[Tue Jul 28 12:05:17.483356 2026] [:error] [pid 14756:tid 140635516385024] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/firebase-config.json"] [unique_id "amh-3ZQnCSs8VI2YeM8xFgAAAE8"]
[Tue Jul 28 12:05:18.981927 2026] [:error] [pid 11209:tid 140635549955840] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v2/config"] [unique_id "amh-3pIwGwWJ8iALx6KZDgAAAUs"]
[Tue Jul 28 12:05:18.982814 2026] [:error] [pid 11209:tid 140635549955840] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v2/config"] [unique_id "amh-3pIwGwWJ8iALx6KZDgAAAUs"]
[Tue Jul 28 12:05:18.983259 2026] [:error] [pid 11209:tid 140635549955840] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v2/config"] [unique_id "amh-3pIwGwWJ8iALx6KZDgAAAUs"]
[Tue Jul 28 12:05:18.983265 2026] [:error] [pid 14756:tid 140635566741248] [client 104.23.166.92:11579] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/env"] [unique_id "amh-3pQnCSs8VI2YeM8xGAAAAEk"]
[Tue Jul 28 12:05:18.983809 2026] [:error] [pid 14756:tid 140635566741248] [client 104.23.166.92:11579] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/env"] [unique_id "amh-3pQnCSs8VI2YeM8xGAAAAEk"]
[Tue Jul 28 12:05:18.984208 2026] [:error] [pid 14756:tid 140635566741248] [client 104.23.166.92:11579] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/env"] [unique_id "amh-3pQnCSs8VI2YeM8xGAAAAEk"]
[Tue Jul 28 12:05:19.035677 2026] [:error] [pid 17371:tid 140635533170432] [client 104.23.168.17:13432] [client 104.23.168.17] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/runtime-config.js"] [unique_id "amh-326-l8v9r5wWdfChewAAAY0"]
[Tue Jul 28 12:05:19.036598 2026] [:error] [pid 17371:tid 140635533170432] [client 104.23.168.17:13432] [client 104.23.168.17] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/runtime-config.js"] [unique_id "amh-326-l8v9r5wWdfChewAAAY0"]
[Tue Jul 28 12:05:19.037124 2026] [:error] [pid 17371:tid 140635533170432] [client 104.23.168.17:13432] [client 104.23.168.17] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/runtime-config.js"] [unique_id "amh-326-l8v9r5wWdfChewAAAY0"]
[Tue Jul 28 12:05:20.459058 2026] [:error] [pid 11209:tid 140635575133952] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v2/settings"] [unique_id "amh-4JIwGwWJ8iALx6KZEAAAAUg"]
[Tue Jul 28 12:05:20.459073 2026] [:error] [pid 14756:tid 140635583526656] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v1/config"] [unique_id "amh-4JQnCSs8VI2YeM8xGQAAAEc"]
[Tue Jul 28 12:05:20.459673 2026] [:error] [pid 14756:tid 140635583526656] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v1/config"] [unique_id "amh-4JQnCSs8VI2YeM8xGQAAAEc"]
[Tue Jul 28 12:05:20.459691 2026] [:error] [pid 11209:tid 140635575133952] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v2/settings"] [unique_id "amh-4JIwGwWJ8iALx6KZEAAAAUg"]
[Tue Jul 28 12:05:20.460027 2026] [:error] [pid 11209:tid 140635575133952] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/api/v2/settings"] [unique_id "amh-4JIwGwWJ8iALx6KZEAAAAUg"]
[Tue Jul 28 12:05:20.460049 2026] [:error] [pid 14756:tid 140635583526656] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v1/config"] [unique_id "amh-4JQnCSs8VI2YeM8xGQAAAEc"]
[Tue Jul 28 12:05:20.460159 2026] [:error] [pid 11209:tid 140635575133952] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v2/settings"] [unique_id "amh-4JIwGwWJ8iALx6KZEAAAAUg"]
[Tue Jul 28 12:05:20.679950 2026] [:error] [pid 14756:tid 140635466028800] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v1/settings"] [unique_id "amh-4JQnCSs8VI2YeM8xGwAAAFU"]
[Tue Jul 28 12:05:20.680591 2026] [:error] [pid 14756:tid 140635466028800] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v1/settings"] [unique_id "amh-4JQnCSs8VI2YeM8xGwAAAFU"]
[Tue Jul 28 12:05:20.680941 2026] [:error] [pid 14756:tid 140635466028800] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v1/settings"] [unique_id "amh-4JQnCSs8VI2YeM8xGwAAAFU"]
[Tue Jul 28 12:05:21.391580 2026] [:error] [pid 14756:tid 140635541563136] [client 162.158.167.47:10880] [client 162.158.167.47] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh-4ZQnCSs8VI2YeM8xHAAAAEw"]
[Tue Jul 28 12:05:21.392406 2026] [:error] [pid 14756:tid 140635541563136] [client 162.158.167.47:10880] [client 162.158.167.47] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh-4ZQnCSs8VI2YeM8xHAAAAEw"]
[Tue Jul 28 12:05:21.392882 2026] [:error] [pid 14756:tid 140635541563136] [client 162.158.167.47:10880] [client 162.158.167.47] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amh-4ZQnCSs8VI2YeM8xHAAAAEw"]
[Tue Jul 28 12:05:21.738487 2026] [:error] [pid 14756:tid 140635558348544] [client 162.158.167.47:10880] [client 162.158.167.47] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_next/webpack-hmr"] [unique_id "amh-4ZQnCSs8VI2YeM8xHQAAAEo"]
[Tue Jul 28 12:05:21.739227 2026] [:error] [pid 14756:tid 140635558348544] [client 162.158.167.47:10880] [client 162.158.167.47] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_next/webpack-hmr"] [unique_id "amh-4ZQnCSs8VI2YeM8xHQAAAEo"]
[Tue Jul 28 12:05:21.739661 2026] [:error] [pid 14756:tid 140635558348544] [client 162.158.167.47:10880] [client 162.158.167.47] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/_next/webpack-hmr"] [unique_id "amh-4ZQnCSs8VI2YeM8xHQAAAEo"]
[Tue Jul 28 12:05:21.739774 2026] [:error] [pid 14756:tid 140635558348544] [client 162.158.167.47:10880] [client 162.158.167.47] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_next/webpack-hmr"] [unique_id "amh-4ZQnCSs8VI2YeM8xHQAAAEo"]
[Tue Jul 28 12:05:21.859092 2026] [:error] [pid 11209:tid 140635440850688] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/health"] [unique_id "amh-4ZIwGwWJ8iALx6KZEwAAAVg"]
[Tue Jul 28 12:05:21.859884 2026] [:error] [pid 11209:tid 140635440850688] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/health"] [unique_id "amh-4ZIwGwWJ8iALx6KZEwAAAVg"]
[Tue Jul 28 12:05:21.860295 2026] [:error] [pid 11209:tid 140635440850688] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/api/health"] [unique_id "amh-4ZIwGwWJ8iALx6KZEwAAAVg"]
[Tue Jul 28 12:05:21.860393 2026] [:error] [pid 11209:tid 140635440850688] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/health"] [unique_id "amh-4ZIwGwWJ8iALx6KZEwAAAVg"]
[Tue Jul 28 12:05:21.864816 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.92:11579] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/manifest.webmanifest"] [unique_id "amh-4ZQnCSs8VI2YeM8xHgAAAEQ"]
[Tue Jul 28 12:05:21.865508 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.92:11579] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/manifest.webmanifest"] [unique_id "amh-4ZQnCSs8VI2YeM8xHgAAAEQ"]
[Tue Jul 28 12:05:21.865915 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.92:11579] [client 104.23.166.92] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/manifest.webmanifest"] [unique_id "amh-4ZQnCSs8VI2YeM8xHgAAAEQ"]
[Tue Jul 28 12:05:21.866027 2026] [:error] [pid 14756:tid 140635608704768] [client 104.23.166.92:11579] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/manifest.webmanifest"] [unique_id "amh-4ZQnCSs8VI2YeM8xHgAAAEQ"]
[Tue Jul 28 12:05:21.909347 2026] [:error] [pid 11209:tid 140635449243392] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/openapi.json"] [unique_id "amh-4ZIwGwWJ8iALx6KZFAAAAVc"]
[Tue Jul 28 12:05:21.909670 2026] [:error] [pid 14756:tid 140635617097472] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/app-config.json"] [unique_id "amh-4ZQnCSs8VI2YeM8xHwAAAEM"]
[Tue Jul 28 12:05:21.910152 2026] [:error] [pid 11209:tid 140635449243392] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/openapi.json"] [unique_id "amh-4ZIwGwWJ8iALx6KZFAAAAVc"]
[Tue Jul 28 12:05:21.910158 2026] [:error] [pid 14756:tid 140635617097472] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/app-config.json"] [unique_id "amh-4ZQnCSs8VI2YeM8xHwAAAEM"]
[Tue Jul 28 12:05:21.910527 2026] [:error] [pid 14756:tid 140635617097472] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/app-config.json"] [unique_id "amh-4ZQnCSs8VI2YeM8xHwAAAEM"]
[Tue Jul 28 12:05:21.910532 2026] [:error] [pid 11209:tid 140635449243392] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/api/openapi.json"] [unique_id "amh-4ZIwGwWJ8iALx6KZFAAAAVc"]
[Tue Jul 28 12:05:21.910677 2026] [:error] [pid 14756:tid 140635617097472] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app-config.json"] [unique_id "amh-4ZQnCSs8VI2YeM8xHwAAAEM"]
[Tue Jul 28 12:05:21.910680 2026] [:error] [pid 11209:tid 140635449243392] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/openapi.json"] [unique_id "amh-4ZIwGwWJ8iALx6KZFAAAAVc"]
[Tue Jul 28 12:05:21.911919 2026] [:error] [pid 14756:tid 140635575133952] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/account"] [unique_id "amh-4ZQnCSs8VI2YeM8xIAAAAEg"]
[Tue Jul 28 12:05:21.912384 2026] [:error] [pid 14756:tid 140635575133952] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/account"] [unique_id "amh-4ZQnCSs8VI2YeM8xIAAAAEg"]
[Tue Jul 28 12:05:21.912733 2026] [:error] [pid 14756:tid 140635575133952] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/api/account"] [unique_id "amh-4ZQnCSs8VI2YeM8xIAAAAEg"]
[Tue Jul 28 12:05:21.912819 2026] [:error] [pid 14756:tid 140635575133952] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/account"] [unique_id "amh-4ZQnCSs8VI2YeM8xIAAAAEg"]
[Tue Jul 28 12:05:21.957783 2026] [:error] [pid 11209:tid 140635608704768] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/openapi.json"] [unique_id "amh-4ZIwGwWJ8iALx6KZFQAAAUQ"]
[Tue Jul 28 12:05:21.958533 2026] [:error] [pid 11209:tid 140635608704768] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/openapi.json"] [unique_id "amh-4ZIwGwWJ8iALx6KZFQAAAUQ"]
[Tue Jul 28 12:05:21.958967 2026] [:error] [pid 11209:tid 140635608704768] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/openapi.json"] [unique_id "amh-4ZIwGwWJ8iALx6KZFQAAAUQ"]
[Tue Jul 28 12:05:21.959095 2026] [:error] [pid 11209:tid 140635608704768] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/openapi.json"] [unique_id "amh-4ZIwGwWJ8iALx6KZFQAAAUQ"]
[Tue Jul 28 12:05:22.201271 2026] [:error] [pid 11209:tid 140635466028800] [client 104.22.17.233:11936] [client 104.22.17.233] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/components/"] [unique_id "amh-4pIwGwWJ8iALx6KZFwAAAVU"]
[Tue Jul 28 12:05:22.202139 2026] [:error] [pid 11209:tid 140635466028800] [client 104.22.17.233:11936] [client 104.22.17.233] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/components/"] [unique_id "amh-4pIwGwWJ8iALx6KZFwAAAVU"]
[Tue Jul 28 12:05:22.202506 2026] [:error] [pid 11209:tid 140635466028800] [client 104.22.17.233:11936] [client 104.22.17.233] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/components/"] [unique_id "amh-4pIwGwWJ8iALx6KZFwAAAVU"]
[Tue Jul 28 12:05:22.202612 2026] [:error] [pid 11209:tid 140635466028800] [client 104.22.17.233:11936] [client 104.22.17.233] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/components/"] [unique_id "amh-4pIwGwWJ8iALx6KZFwAAAVU"]
[Tue Jul 28 12:05:22.210807 2026] [:error] [pid 14755:tid 140635583526656] [client 104.22.17.232:9590] [client 104.22.17.232] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/register"] [unique_id "amh-4qf64wRy3HlU5UP-ygAAAAc"]
[Tue Jul 28 12:05:22.211432 2026] [:error] [pid 14755:tid 140635583526656] [client 104.22.17.232:9590] [client 104.22.17.232] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/register"] [unique_id "amh-4qf64wRy3HlU5UP-ygAAAAc"]
[Tue Jul 28 12:05:22.211746 2026] [:error] [pid 14755:tid 140635583526656] [client 104.22.17.232:9590] [client 104.22.17.232] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/register"] [unique_id "amh-4qf64wRy3HlU5UP-ygAAAAc"]
[Tue Jul 28 12:05:22.211813 2026] [:error] [pid 14755:tid 140635583526656] [client 104.22.17.232:9590] [client 104.22.17.232] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/register"] [unique_id "amh-4qf64wRy3HlU5UP-ygAAAAc"]
[Tue Jul 28 12:05:22.219354 2026] [:error] [pid 14859:tid 140635591919360] [client 104.22.17.232:9597] [client 104.22.17.232] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_next/static/"] [unique_id "amh-4rBlXBlS8_TwuUZHIwAAAMY"]
[Tue Jul 28 12:05:22.220038 2026] [:error] [pid 14859:tid 140635591919360] [client 104.22.17.232:9597] [client 104.22.17.232] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_next/static/"] [unique_id "amh-4rBlXBlS8_TwuUZHIwAAAMY"]
[Tue Jul 28 12:05:22.220412 2026] [:error] [pid 14859:tid 140635591919360] [client 104.22.17.232:9597] [client 104.22.17.232] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/_next/static/"] [unique_id "amh-4rBlXBlS8_TwuUZHIwAAAMY"]
[Tue Jul 28 12:05:22.220522 2026] [:error] [pid 14859:tid 140635591919360] [client 104.22.17.232:9597] [client 104.22.17.232] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_next/static/"] [unique_id "amh-4rBlXBlS8_TwuUZHIwAAAMY"]
[Tue Jul 28 12:05:22.222427 2026] [:error] [pid 14755:tid 140635533170432] [client 104.22.20.127:13331] [client 104.22.20.127] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/administrator/"] [unique_id "amh-4qf64wRy3HlU5UP-ywAAAA0"]
[Tue Jul 28 12:05:22.222985 2026] [:error] [pid 14755:tid 140635533170432] [client 104.22.20.127:13331] [client 104.22.20.127] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/administrator/"] [unique_id "amh-4qf64wRy3HlU5UP-ywAAAA0"]
[Tue Jul 28 12:05:22.223253 2026] [:error] [pid 14755:tid 140635533170432] [client 104.22.20.127:13331] [client 104.22.20.127] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/administrator/"] [unique_id "amh-4qf64wRy3HlU5UP-ywAAAA0"]
[Tue Jul 28 12:05:22.223379 2026] [:error] [pid 14755:tid 140635533170432] [client 104.22.20.127:13331] [client 104.22.20.127] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/administrator/"] [unique_id "amh-4qf64wRy3HlU5UP-ywAAAA0"]
[Tue Jul 28 12:05:22.235788 2026] [:error] [pid 11209:tid 140635549955840] [client 172.71.158.54:9859] [client 172.71.158.54] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/login"] [unique_id "amh-4pIwGwWJ8iALx6KZGAAAAUs"]
[Tue Jul 28 12:05:22.236872 2026] [:error] [pid 11209:tid 140635549955840] [client 172.71.158.54:9859] [client 172.71.158.54] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/login"] [unique_id "amh-4pIwGwWJ8iALx6KZGAAAAUs"]
[Tue Jul 28 12:05:22.237430 2026] [:error] [pid 11209:tid 140635549955840] [client 172.71.158.54:9859] [client 172.71.158.54] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/login"] [unique_id "amh-4pIwGwWJ8iALx6KZGAAAAUs"]
[Tue Jul 28 12:05:22.237584 2026] [:error] [pid 11209:tid 140635549955840] [client 172.71.158.54:9859] [client 172.71.158.54] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/login"] [unique_id "amh-4pIwGwWJ8iALx6KZGAAAAUs"]
[Tue Jul 28 12:05:22.268303 2026] [:error] [pid 17371:tid 140635499599616] [client 172.71.154.26:13698] [client 172.71.154.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_ignition/health-check"] [unique_id "amh-4m6-l8v9r5wWdfChiwAAAZE"]
[Tue Jul 28 12:05:22.268325 2026] [:error] [pid 17371:tid 140635524777728] [client 104.22.20.149:12375] [client 104.22.20.149] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/media/jui/js/jquery.min.js"] [unique_id "amh-4m6-l8v9r5wWdfChigAAAY4"]
[Tue Jul 28 12:05:22.268858 2026] [:error] [pid 17371:tid 140635541563136] [client 104.22.20.126:11135] [client 104.22.20.126] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amh-4m6-l8v9r5wWdfChjAAAAYw"]
[Tue Jul 28 12:05:22.269642 2026] [:error] [pid 17371:tid 140635541563136] [client 104.22.20.126:11135] [client 104.22.20.126] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amh-4m6-l8v9r5wWdfChjAAAAYw"]
[Tue Jul 28 12:05:22.269661 2026] [:error] [pid 17371:tid 140635499599616] [client 172.71.154.26:13698] [client 172.71.154.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_ignition/health-check"] [unique_id "amh-4m6-l8v9r5wWdfChiwAAAZE"]
[Tue Jul 28 12:05:22.269681 2026] [:error] [pid 17371:tid 140635524777728] [client 104.22.20.149:12375] [client 104.22.20.149] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/media/jui/js/jquery.min.js"] [unique_id "amh-4m6-l8v9r5wWdfChigAAAY4"]
[Tue Jul 28 12:05:22.270184 2026] [:error] [pid 17371:tid 140635499599616] [client 172.71.154.26:13698] [client 172.71.154.26] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/_ignition/health-check"] [unique_id "amh-4m6-l8v9r5wWdfChiwAAAZE"]
[Tue Jul 28 12:05:22.270198 2026] [:error] [pid 17371:tid 140635541563136] [client 104.22.20.126:11135] [client 104.22.20.126] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amh-4m6-l8v9r5wWdfChjAAAAYw"]
[Tue Jul 28 12:05:22.270213 2026] [:error] [pid 17371:tid 140635524777728] [client 104.22.20.149:12375] [client 104.22.20.149] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/media/jui/js/jquery.min.js"] [unique_id "amh-4m6-l8v9r5wWdfChigAAAY4"]
[Tue Jul 28 12:05:22.270296 2026] [:error] [pid 17371:tid 140635499599616] [client 172.71.154.26:13698] [client 172.71.154.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_ignition/health-check"] [unique_id "amh-4m6-l8v9r5wWdfChiwAAAZE"]
[Tue Jul 28 12:05:22.270318 2026] [:error] [pid 17371:tid 140635541563136] [client 104.22.20.126:11135] [client 104.22.20.126] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amh-4m6-l8v9r5wWdfChjAAAAYw"]
[Tue Jul 28 12:05:22.270331 2026] [:error] [pid 17371:tid 140635524777728] [client 104.22.20.149:12375] [client 104.22.20.149] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/media/jui/js/jquery.min.js"] [unique_id "amh-4m6-l8v9r5wWdfChigAAAY4"]
[Tue Jul 28 12:05:22.272282 2026] [:error] [pid 11209:tid 140635474421504] [client 172.69.22.73:14039] [client 172.69.22.73] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/js/wp-emoji.js"] [unique_id "amh-4pIwGwWJ8iALx6KZGQAAAVQ"]
[Tue Jul 28 12:05:22.272946 2026] [:error] [pid 11209:tid 140635474421504] [client 172.69.22.73:14039] [client 172.69.22.73] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/js/wp-emoji.js"] [unique_id "amh-4pIwGwWJ8iALx6KZGQAAAVQ"]
[Tue Jul 28 12:05:22.273379 2026] [:error] [pid 11209:tid 140635474421504] [client 172.69.22.73:14039] [client 172.69.22.73] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/js/wp-emoji.js"] [unique_id "amh-4pIwGwWJ8iALx6KZGQAAAVQ"]
[Tue Jul 28 12:05:22.273476 2026] [:error] [pid 11209:tid 140635474421504] [client 172.69.22.73:14039] [client 172.69.22.73] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/js/wp-emoji.js"] [unique_id "amh-4pIwGwWJ8iALx6KZGQAAAVQ"]
[Tue Jul 28 12:05:22.275672 2026] [:error] [pid 11209:tid 140635583526656] [client 104.22.20.126:11143] [client 104.22.20.126] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/"] [unique_id "amh-4pIwGwWJ8iALx6KZGgAAAUc"]
[Tue Jul 28 12:05:22.276158 2026] [:error] [pid 11209:tid 140635583526656] [client 104.22.20.126:11143] [client 104.22.20.126] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/"] [unique_id "amh-4pIwGwWJ8iALx6KZGgAAAUc"]
[Tue Jul 28 12:05:22.276604 2026] [:error] [pid 11209:tid 140635583526656] [client 104.22.20.126:11143] [client 104.22.20.126] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/"] [unique_id "amh-4pIwGwWJ8iALx6KZGgAAAUc"]
[Tue Jul 28 12:05:22.276720 2026] [:error] [pid 11209:tid 140635583526656] [client 104.22.20.126:11143] [client 104.22.20.126] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/"] [unique_id "amh-4pIwGwWJ8iALx6KZGgAAAUc"]
[Tue Jul 28 12:05:23.543442 2026] [:error] [pid 14756:tid 140635474421504] [client 104.23.166.92:11579] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v1/env"] [unique_id "amh-45QnCSs8VI2YeM8xIQAAAFQ"]
[Tue Jul 28 12:05:23.543458 2026] [:error] [pid 14756:tid 140635591919360] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/health"] [unique_id "amh-45QnCSs8VI2YeM8xIgAAAEY"]
[Tue Jul 28 12:05:23.544020 2026] [:error] [pid 14756:tid 140635474421504] [client 104.23.166.92:11579] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v1/env"] [unique_id "amh-45QnCSs8VI2YeM8xIQAAAFQ"]
[Tue Jul 28 12:05:23.544032 2026] [:error] [pid 14756:tid 140635591919360] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/health"] [unique_id "amh-45QnCSs8VI2YeM8xIgAAAEY"]
[Tue Jul 28 12:05:23.544302 2026] [:error] [pid 14756:tid 140635591919360] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/health"] [unique_id "amh-45QnCSs8VI2YeM8xIgAAAEY"]
[Tue Jul 28 12:05:23.544365 2026] [:error] [pid 14756:tid 140635591919360] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/health"] [unique_id "amh-45QnCSs8VI2YeM8xIgAAAEY"]
[Tue Jul 28 12:05:23.544372 2026] [:error] [pid 14756:tid 140635474421504] [client 104.23.166.92:11579] [client 104.23.166.92] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/api/v1/env"] [unique_id "amh-45QnCSs8VI2YeM8xIQAAAFQ"]
[Tue Jul 28 12:05:23.544474 2026] [:error] [pid 14756:tid 140635474421504] [client 104.23.166.92:11579] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v1/env"] [unique_id "amh-45QnCSs8VI2YeM8xIQAAAFQ"]
[Tue Jul 28 12:05:23.546732 2026] [:error] [pid 11209:tid 140635549955840] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/swagger.json"] [unique_id "amh-45IwGwWJ8iALx6KZIwAAAUs"]
[Tue Jul 28 12:05:23.547305 2026] [:error] [pid 11209:tid 140635549955840] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/swagger.json"] [unique_id "amh-45IwGwWJ8iALx6KZIwAAAUs"]
[Tue Jul 28 12:05:23.547657 2026] [:error] [pid 11209:tid 140635549955840] [client 104.23.166.93:11585] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/swagger.json"] [unique_id "amh-45IwGwWJ8iALx6KZIwAAAUs"]
[Tue Jul 28 12:05:23.599465 2026] [:error] [pid 11209:tid 140635474421504] [client 172.71.103.199:10299] [client 172.71.103.199] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/__env.js"] [unique_id "amh-45IwGwWJ8iALx6KZJAAAAVQ"]
[Tue Jul 28 12:05:23.600275 2026] [:error] [pid 11209:tid 140635474421504] [client 172.71.103.199:10299] [client 172.71.103.199] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/__env.js"] [unique_id "amh-45IwGwWJ8iALx6KZJAAAAVQ"]
[Tue Jul 28 12:05:23.600729 2026] [:error] [pid 11209:tid 140635474421504] [client 172.71.103.199:10299] [client 172.71.103.199] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/__env.js"] [unique_id "amh-45IwGwWJ8iALx6KZJAAAAVQ"]
[Tue Jul 28 12:05:23.600859 2026] [:error] [pid 11209:tid 140635474421504] [client 172.71.103.199:10299] [client 172.71.103.199] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/__env.js"] [unique_id "amh-45IwGwWJ8iALx6KZJAAAAVQ"]
[Tue Jul 28 12:05:23.645183 2026] [:error] [pid 14859:tid 140635440850688] [client 104.23.172.57:9513] [client 104.23.172.57] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sw.js"] [unique_id "amh-47BlXBlS8_TwuUZHKgAAANg"]
[Tue Jul 28 12:05:23.645938 2026] [:error] [pid 14859:tid 140635440850688] [client 104.23.172.57:9513] [client 104.23.172.57] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sw.js"] [unique_id "amh-47BlXBlS8_TwuUZHKgAAANg"]
[Tue Jul 28 12:05:23.646257 2026] [:error] [pid 14859:tid 140635440850688] [client 104.23.172.57:9513] [client 104.23.172.57] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sw.js"] [unique_id "amh-47BlXBlS8_TwuUZHKgAAANg"]
[Tue Jul 28 12:05:23.646331 2026] [:error] [pid 14859:tid 140635440850688] [client 104.23.172.57:9513] [client 104.23.172.57] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sw.js"] [unique_id "amh-47BlXBlS8_TwuUZHKgAAANg"]
[Tue Jul 28 12:05:23.700905 2026] [:error] [pid 11209:tid 140635706623744] [client 172.71.99.145:12356] [client 172.71.99.145] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/service-worker.js"] [unique_id "amh-45IwGwWJ8iALx6KZJQAAAUE"]
[Tue Jul 28 12:05:23.701505 2026] [:error] [pid 11209:tid 140635706623744] [client 172.71.99.145:12356] [client 172.71.99.145] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/service-worker.js"] [unique_id "amh-45IwGwWJ8iALx6KZJQAAAUE"]
[Tue Jul 28 12:05:23.701889 2026] [:error] [pid 11209:tid 140635706623744] [client 172.71.99.145:12356] [client 172.71.99.145] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/service-worker.js"] [unique_id "amh-45IwGwWJ8iALx6KZJQAAAUE"]
[Tue Jul 28 12:05:23.701975 2026] [:error] [pid 11209:tid 140635706623744] [client 172.71.99.145:12356] [client 172.71.99.145] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/service-worker.js"] [unique_id "amh-45IwGwWJ8iALx6KZJQAAAUE"]
[Tue Jul 28 12:05:25.927649 2026] [:error] [pid 14756:tid 140635600312064] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amh-5ZQnCSs8VI2YeM8xJQAAAEU"]
[Tue Jul 28 12:05:25.928449 2026] [:error] [pid 14756:tid 140635600312064] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amh-5ZQnCSs8VI2YeM8xJQAAAEU"]
[Tue Jul 28 12:05:25.928909 2026] [:error] [pid 14756:tid 140635600312064] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amh-5ZQnCSs8VI2YeM8xJQAAAEU"]
[Tue Jul 28 12:05:25.929023 2026] [:error] [pid 14756:tid 140635600312064] [client 104.23.166.92:11569] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/graphql"] [unique_id "amh-5ZQnCSs8VI2YeM8xJQAAAEU"]
[Tue Jul 28 12:05:25.955978 2026] [:error] [pid 11209:tid 140635591919360] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/graphql"] [unique_id "amh-5ZIwGwWJ8iALx6KZKgAAAUY"]
[Tue Jul 28 12:05:25.956813 2026] [:error] [pid 11209:tid 140635591919360] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/graphql"] [unique_id "amh-5ZIwGwWJ8iALx6KZKgAAAUY"]
[Tue Jul 28 12:05:25.957228 2026] [:error] [pid 11209:tid 140635591919360] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/graphql"] [unique_id "amh-5ZIwGwWJ8iALx6KZKgAAAUY"]
[Tue Jul 28 12:05:25.957326 2026] [:error] [pid 11209:tid 140635591919360] [client 104.23.166.93:11590] [client 104.23.166.93] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/graphql"] [unique_id "amh-5ZIwGwWJ8iALx6KZKgAAAUY"]
[Tue Jul 28 12:05:25.989689 2026] [:error] [pid 14859:tid 140635583526656] [client 104.23.170.140:13139] [client 104.23.170.140] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/firebase-messaging-sw.js"] [unique_id "amh-5bBlXBlS8_TwuUZHMQAAAMc"]
[Tue Jul 28 12:05:25.990456 2026] [:error] [pid 14859:tid 140635583526656] [client 104.23.170.140:13139] [client 104.23.170.140] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/firebase-messaging-sw.js"] [unique_id "amh-5bBlXBlS8_TwuUZHMQAAAMc"]
[Tue Jul 28 12:05:25.990891 2026] [:error] [pid 14859:tid 140635583526656] [client 104.23.170.140:13139] [client 104.23.170.140] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:user-agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/firebase-messaging-sw.js"] [unique_id "amh-5bBlXBlS8_TwuUZHMQAAAMc"]
[Tue Jul 28 12:05:25.990999 2026] [:error] [pid 14859:tid 140635583526656] [client 104.23.170.140:13139] [client 104.23.170.140] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/firebase-messaging-sw.js"] [unique_id "amh-5bBlXBlS8_TwuUZHMQAAAMc"]
[Tue Jul 28 12:05:28.105276 2026] [:error] [pid 14756:tid 140635440850688] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/graphql/console"] [unique_id "amh-6JQnCSs8VI2YeM8xJgAAAFg"]
[Tue Jul 28 12:05:28.105843 2026] [:error] [pid 14756:tid 140635440850688] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/graphql/console"] [unique_id "amh-6JQnCSs8VI2YeM8xJgAAAFg"]
[Tue Jul 28 12:05:28.106186 2026] [:error] [pid 14756:tid 140635440850688] [client 104.23.166.92:11573] [client 104.23.166.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/graphql/console"] [unique_id "amh-6JQnCSs8VI2YeM8xJgAAAFg"]
[Tue Jul 28 12:25:56.302363 2026] [:error] [pid 31471:tid 140534112610048] [client 172.68.245.95:11907] [client 172.68.245.95] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amiDtMbo_8Uj3iOaYH7I6AAAAQQ"]
[Tue Jul 28 12:25:56.303262 2026] [:error] [pid 31471:tid 140534112610048] [client 172.68.245.95:11907] [client 172.68.245.95] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amiDtMbo_8Uj3iOaYH7I6AAAAQQ"]
[Tue Jul 28 12:25:56.303872 2026] [:error] [pid 31471:tid 140534112610048] [client 172.68.245.95:11907] [client 172.68.245.95] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amiDtMbo_8Uj3iOaYH7I6AAAAQQ"]
[Tue Jul 28 12:34:15.911395 2026] [:error] [pid 31087:tid 140534121002752] [client 104.23.243.18:10264] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amiFp8map6NoEp6N8uC-ewAAAAM"]
[Tue Jul 28 12:34:15.916438 2026] [:error] [pid 31087:tid 140534121002752] [client 104.23.243.18:10264] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amiFp8map6NoEp6N8uC-ewAAAAM"]
[Tue Jul 28 12:34:15.916954 2026] [:error] [pid 31087:tid 140534121002752] [client 104.23.243.18:10264] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amiFp8map6NoEp6N8uC-ewAAAAM"]
[Tue Jul 28 13:07:46.086641 2026] [:error] [pid 31356:tid 140533963921152] [client 104.23.197.76:10748] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amiNgsz37IgzFQUBXwRT8gAAAM0"]
[Tue Jul 28 13:07:46.087648 2026] [:error] [pid 31356:tid 140533963921152] [client 104.23.197.76:10748] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amiNgsz37IgzFQUBXwRT8gAAAM0"]
[Tue Jul 28 13:07:46.088155 2026] [:error] [pid 31356:tid 140533963921152] [client 104.23.197.76:10748] [client 104.23.197.76] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amiNgsz37IgzFQUBXwRT8gAAAM0"]
[Tue Jul 28 13:22:12.907121 2026] [:error] [pid 31473:tid 140533989099264] [client 172.69.95.103:14214] [client 172.69.95.103] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiQ5AiTq2daiUZjsUFwGAAAAUo"]
[Tue Jul 28 13:22:12.908080 2026] [:error] [pid 31473:tid 140533989099264] [client 172.69.95.103:14214] [client 172.69.95.103] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiQ5AiTq2daiUZjsUFwGAAAAUo"]
[Tue Jul 28 13:22:12.908508 2026] [:error] [pid 31473:tid 140533989099264] [client 172.69.95.103:14214] [client 172.69.95.103] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiQ5AiTq2daiUZjsUFwGAAAAUo"]
[Tue Jul 28 13:22:12.908630 2026] [:error] [pid 31473:tid 140533989099264] [client 172.69.95.103:14214] [client 172.69.95.103] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiQ5AiTq2daiUZjsUFwGAAAAUo"]
[Tue Jul 28 13:22:13.819737 2026] [:error] [pid 31473:tid 140533972313856] [client 172.69.94.14:10903] [client 172.69.94.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amiQ5QiTq2daiUZjsUFwHAAAAUw"]
[Tue Jul 28 13:22:13.820673 2026] [:error] [pid 31473:tid 140533972313856] [client 172.69.94.14:10903] [client 172.69.94.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amiQ5QiTq2daiUZjsUFwHAAAAUw"]
[Tue Jul 28 13:22:13.821050 2026] [:error] [pid 31473:tid 140533972313856] [client 172.69.94.14:10903] [client 172.69.94.14] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amiQ5QiTq2daiUZjsUFwHAAAAUw"]
[Tue Jul 28 13:22:13.821144 2026] [:error] [pid 31473:tid 140533972313856] [client 172.69.94.14:10903] [client 172.69.94.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amiQ5QiTq2daiUZjsUFwHAAAAUw"]
[Tue Jul 28 13:22:14.729545 2026] [:error] [pid 31473:tid 140534121002752] [client 172.69.95.29:9449] [client 172.69.95.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/media/system/js/core.js"] [unique_id "amiQ5giTq2daiUZjsUFwIwAAAUM"]
[Tue Jul 28 13:22:14.730318 2026] [:error] [pid 31473:tid 140534121002752] [client 172.69.95.29:9449] [client 172.69.95.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/media/system/js/core.js"] [unique_id "amiQ5giTq2daiUZjsUFwIwAAAUM"]
[Tue Jul 28 13:22:14.730664 2026] [:error] [pid 31473:tid 140534121002752] [client 172.69.95.29:9449] [client 172.69.95.29] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/media/system/js/core.js"] [unique_id "amiQ5giTq2daiUZjsUFwIwAAAUM"]
[Tue Jul 28 13:22:14.730743 2026] [:error] [pid 31473:tid 140534121002752] [client 172.69.95.29:9449] [client 172.69.95.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/media/system/js/core.js"] [unique_id "amiQ5giTq2daiUZjsUFwIwAAAUM"]
[Tue Jul 28 13:29:09.478708 2026] [:error] [pid 31089:tid 140534137788160] [client 172.70.242.203:11221] [client 172.70.242.203] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amiShaBvmOssEcIc7vpWAgAAAIE"]
[Tue Jul 28 13:29:09.479734 2026] [:error] [pid 31089:tid 140534137788160] [client 172.70.242.203:11221] [client 172.70.242.203] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amiShaBvmOssEcIc7vpWAgAAAIE"]
[Tue Jul 28 13:29:09.480333 2026] [:error] [pid 31089:tid 140534137788160] [client 172.70.242.203:11221] [client 172.70.242.203] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amiShaBvmOssEcIc7vpWAgAAAIE"]
[Tue Jul 28 13:30:15.936563 2026] [:error] [pid 31089:tid 140533972313856] [client 198.235.24.39:63970] [client 198.235.24.39] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiSx6BvmOssEcIc7vpWSAAAAIw"]
[Tue Jul 28 13:30:15.937269 2026] [:error] [pid 31089:tid 140533972313856] [client 198.235.24.39:63970] [client 198.235.24.39] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiSx6BvmOssEcIc7vpWSAAAAIw"]
[Tue Jul 28 13:30:15.937490 2026] [:error] [pid 31089:tid 140533972313856] [client 198.235.24.39:63970] [client 198.235.24.39] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiSx6BvmOssEcIc7vpWSAAAAIw"]
[Tue Jul 28 13:35:22.542604 2026] [:error] [pid 31471:tid 140534104217344] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiT-sbo_8Uj3iOaYH4LSAAAAQU"]
[Tue Jul 28 13:35:22.547341 2026] [:error] [pid 31471:tid 140534104217344] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiT-sbo_8Uj3iOaYH4LSAAAAQU"]
[Tue Jul 28 13:35:22.547865 2026] [:error] [pid 31471:tid 140534104217344] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiT-sbo_8Uj3iOaYH4LSAAAAQU"]
[Tue Jul 28 13:35:23.171398 2026] [:error] [pid 31473:tid 140534095824640] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amiT-wiTq2daiUZjsUGFqAAAAUY"]
[Tue Jul 28 13:35:23.172193 2026] [:error] [pid 31473:tid 140534095824640] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amiT-wiTq2daiUZjsUGFqAAAAUY"]
[Tue Jul 28 13:35:23.172721 2026] [:error] [pid 31473:tid 140534095824640] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amiT-wiTq2daiUZjsUGFqAAAAUY"]
[Tue Jul 28 13:35:23.172968 2026] [:error] [pid 31473:tid 140534095824640] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amiT-wiTq2daiUZjsUGFqAAAAUY"]
[Tue Jul 28 13:35:23.524605 2026] [:error] [pid 31471:tid 140533879994112] [client 104.23.166.57:13986] [client 104.23.166.57] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.min.js"] [unique_id "amiT-8bo_8Uj3iOaYH4LVQAAARc"]
[Tue Jul 28 13:35:23.525396 2026] [:error] [pid 31471:tid 140533879994112] [client 104.23.166.57:13986] [client 104.23.166.57] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.min.js"] [unique_id "amiT-8bo_8Uj3iOaYH4LVQAAARc"]
[Tue Jul 28 13:35:23.525839 2026] [:error] [pid 31471:tid 140533879994112] [client 104.23.166.57:13986] [client 104.23.166.57] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.min.js"] [unique_id "amiT-8bo_8Uj3iOaYH4LVQAAARc"]
[Tue Jul 28 13:35:23.572174 2026] [:error] [pid 31471:tid 140533888386816] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/%2eenv"] [unique_id "amiT-8bo_8Uj3iOaYH4LVgAAARY"]
[Tue Jul 28 13:35:23.572975 2026] [:error] [pid 31471:tid 140533888386816] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amiT-8bo_8Uj3iOaYH4LVgAAARY"]
[Tue Jul 28 13:35:23.573452 2026] [:error] [pid 31471:tid 140533888386816] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amiT-8bo_8Uj3iOaYH4LVgAAARY"]
[Tue Jul 28 13:35:23.573716 2026] [:error] [pid 31471:tid 140533888386816] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amiT-8bo_8Uj3iOaYH4LVgAAARY"]
[Tue Jul 28 13:35:24.081177 2026] [:error] [pid 31473:tid 140533896779520] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/%2f%2eenv"] [unique_id "amiT_AiTq2daiUZjsUGFsAAAAVU"]
[Tue Jul 28 13:35:24.130790 2026] [:error] [pid 31471:tid 140534137788160] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiT_Mbo_8Uj3iOaYH4LWwAAAQE"]
[Tue Jul 28 13:35:24.132051 2026] [:error] [pid 31471:tid 140534137788160] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiT_Mbo_8Uj3iOaYH4LWwAAAQE"]
[Tue Jul 28 13:35:24.132695 2026] [:error] [pid 31471:tid 140534137788160] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiT_Mbo_8Uj3iOaYH4LWwAAAQE"]
[Tue Jul 28 13:35:24.520833 2026] [:error] [pid 31473:tid 140533972313856] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amiT_AiTq2daiUZjsUGFtQAAAUw"]
[Tue Jul 28 13:35:24.521762 2026] [:error] [pid 31473:tid 140533972313856] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amiT_AiTq2daiUZjsUGFtQAAAUw"]
[Tue Jul 28 13:35:24.522165 2026] [:error] [pid 31473:tid 140533972313856] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amiT_AiTq2daiUZjsUGFtQAAAUw"]
[Tue Jul 28 13:35:24.522349 2026] [:error] [pid 31473:tid 140533972313856] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amiT_AiTq2daiUZjsUGFtQAAAUw"]
[Tue Jul 28 13:35:25.087228 2026] [:error] [pid 31471:tid 140533871601408] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amiT_cbo_8Uj3iOaYH4LZgAAARg"]
[Tue Jul 28 13:35:25.088995 2026] [:error] [pid 31471:tid 140533871601408] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amiT_cbo_8Uj3iOaYH4LZgAAARg"]
[Tue Jul 28 13:35:25.089523 2026] [:error] [pid 31471:tid 140533871601408] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amiT_cbo_8Uj3iOaYH4LZgAAARg"]
[Tue Jul 28 13:35:25.089768 2026] [:error] [pid 31471:tid 140533871601408] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amiT_cbo_8Uj3iOaYH4LZgAAARg"]
[Tue Jul 28 13:35:25.333383 2026] [:error] [pid 31473:tid 140534146180864] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amiT_QiTq2daiUZjsUGFvgAAAUA"]
[Tue Jul 28 13:35:25.334199 2026] [:error] [pid 31473:tid 140534146180864] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amiT_QiTq2daiUZjsUGFvgAAAUA"]
[Tue Jul 28 13:35:25.334668 2026] [:error] [pid 31473:tid 140534146180864] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amiT_QiTq2daiUZjsUGFvgAAAUA"]
[Tue Jul 28 13:35:25.334905 2026] [:error] [pid 31473:tid 140534146180864] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amiT_QiTq2daiUZjsUGFvgAAAUA"]
[Tue Jul 28 13:35:25.922517 2026] [:error] [pid 31471:tid 140534137788160] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aws-ses.json"] [unique_id "amiT_cbo_8Uj3iOaYH4LbwAAAQE"]
[Tue Jul 28 13:35:25.923292 2026] [:error] [pid 31471:tid 140534137788160] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aws-ses.json"] [unique_id "amiT_cbo_8Uj3iOaYH4LbwAAAQE"]
[Tue Jul 28 13:35:25.923745 2026] [:error] [pid 31471:tid 140534137788160] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/aws-ses.json"] [unique_id "amiT_cbo_8Uj3iOaYH4LbwAAAQE"]
[Tue Jul 28 13:35:26.852995 2026] [:error] [pid 31473:tid 140533963921152] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.stripe/"] [unique_id "amiT_giTq2daiUZjsUGFzgAAAU0"]
[Tue Jul 28 13:35:26.854024 2026] [:error] [pid 31473:tid 140533963921152] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.stripe/"] [unique_id "amiT_giTq2daiUZjsUGFzgAAAU0"]
[Tue Jul 28 13:35:26.854538 2026] [:error] [pid 31473:tid 140533963921152] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.stripe/"] [unique_id "amiT_giTq2daiUZjsUGFzgAAAU0"]
[Tue Jul 28 13:35:27.295602 2026] [:error] [pid 31471:tid 140534095824640] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/stripe/.env"] [unique_id "amiT_8bo_8Uj3iOaYH4LegAAAQY"]
[Tue Jul 28 13:35:27.296415 2026] [:error] [pid 31471:tid 140534095824640] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/stripe/.env"] [unique_id "amiT_8bo_8Uj3iOaYH4LegAAAQY"]
[Tue Jul 28 13:35:27.296838 2026] [:error] [pid 31471:tid 140534095824640] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/stripe/.env"] [unique_id "amiT_8bo_8Uj3iOaYH4LegAAAQY"]
[Tue Jul 28 13:35:27.296988 2026] [:error] [pid 31471:tid 140534095824640] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /stripe/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/stripe/.env"] [unique_id "amiT_8bo_8Uj3iOaYH4LegAAAQY"]
[Tue Jul 28 13:35:27.966437 2026] [:error] [pid 31473:tid 140534112610048] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.aws"] [unique_id "amiT_wiTq2daiUZjsUGF1QAAAUQ"]
[Tue Jul 28 13:35:27.967627 2026] [:error] [pid 31473:tid 140534112610048] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.aws"] [unique_id "amiT_wiTq2daiUZjsUGF1QAAAUQ"]
[Tue Jul 28 13:35:27.968103 2026] [:error] [pid 31473:tid 140534112610048] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.aws"] [unique_id "amiT_wiTq2daiUZjsUGF1QAAAUQ"]
[Tue Jul 28 13:35:27.968331 2026] [:error] [pid 31473:tid 140534112610048] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.aws"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.aws"] [unique_id "amiT_wiTq2daiUZjsUGF1QAAAUQ"]
[Tue Jul 28 13:35:28.893391 2026] [:error] [pid 31473:tid 140534129395456] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amiUAAiTq2daiUZjsUGF3AAAAUI"]
[Tue Jul 28 13:35:28.894310 2026] [:error] [pid 31473:tid 140534129395456] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amiUAAiTq2daiUZjsUGF3AAAAUI"]
[Tue Jul 28 13:35:28.894804 2026] [:error] [pid 31473:tid 140534129395456] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amiUAAiTq2daiUZjsUGF3AAAAUI"]
[Tue Jul 28 13:35:28.895025 2026] [:error] [pid 31473:tid 140534129395456] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amiUAAiTq2daiUZjsUGF3AAAAUI"]
[Tue Jul 28 13:35:30.306509 2026] [:error] [pid 31471:tid 140533921957632] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amiUAsbo_8Uj3iOaYH4LjQAAARI"]
[Tue Jul 28 13:35:30.307295 2026] [:error] [pid 31471:tid 140533921957632] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amiUAsbo_8Uj3iOaYH4LjQAAARI"]
[Tue Jul 28 13:35:30.307789 2026] [:error] [pid 31471:tid 140533921957632] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amiUAsbo_8Uj3iOaYH4LjQAAARI"]
[Tue Jul 28 13:35:30.308013 2026] [:error] [pid 31471:tid 140533921957632] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amiUAsbo_8Uj3iOaYH4LjQAAARI"]
[Tue Jul 28 13:35:30.987209 2026] [:error] [pid 31473:tid 140533972313856] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amiUAgiTq2daiUZjsUGF5gAAAUw"]
[Tue Jul 28 13:35:30.988044 2026] [:error] [pid 31473:tid 140533972313856] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amiUAgiTq2daiUZjsUGF5gAAAUw"]
[Tue Jul 28 13:35:30.988535 2026] [:error] [pid 31473:tid 140533972313856] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amiUAgiTq2daiUZjsUGF5gAAAUw"]
[Tue Jul 28 13:35:30.988782 2026] [:error] [pid 31473:tid 140533972313856] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amiUAgiTq2daiUZjsUGF5gAAAUw"]
[Tue Jul 28 13:35:32.043640 2026] [:error] [pid 31471:tid 140533997491968] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/test.php"] [unique_id "amiUBMbo_8Uj3iOaYH4LmgAAAQk"]
[Tue Jul 28 13:35:32.044256 2026] [:error] [pid 31471:tid 140533997491968] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/test.php"] [unique_id "amiUBMbo_8Uj3iOaYH4LmgAAAQk"]
[Tue Jul 28 13:35:32.044536 2026] [:error] [pid 31471:tid 140533997491968] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/test.php"] [unique_id "amiUBMbo_8Uj3iOaYH4LmgAAAQk"]
[Tue Jul 28 13:35:32.044647 2026] [:error] [pid 31471:tid 140533997491968] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/test.php"] [unique_id "amiUBMbo_8Uj3iOaYH4LmgAAAQk"]
[Tue Jul 28 13:35:33.964673 2026] [:error] [pid 31473:tid 140533955528448] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amiUBQiTq2daiUZjsUGF-wAAAU4"]
[Tue Jul 28 13:35:33.965611 2026] [:error] [pid 31473:tid 140533955528448] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amiUBQiTq2daiUZjsUGF-wAAAU4"]
[Tue Jul 28 13:35:33.966012 2026] [:error] [pid 31473:tid 140533955528448] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amiUBQiTq2daiUZjsUGF-wAAAU4"]
[Tue Jul 28 13:35:33.966108 2026] [:error] [pid 31473:tid 140533955528448] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amiUBQiTq2daiUZjsUGF-wAAAU4"]
[Tue Jul 28 13:35:33.966327 2026] [:error] [pid 31473:tid 140533955528448] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amiUBQiTq2daiUZjsUGF-wAAAU4"]
[Tue Jul 28 13:35:36.696647 2026] [:error] [pid 31471:tid 140533913564928] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amiUCMbo_8Uj3iOaYH4LvAAAARM"]
[Tue Jul 28 13:35:36.697465 2026] [:error] [pid 31471:tid 140533913564928] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amiUCMbo_8Uj3iOaYH4LvAAAARM"]
[Tue Jul 28 13:35:36.697993 2026] [:error] [pid 31471:tid 140533913564928] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amiUCMbo_8Uj3iOaYH4LvAAAARM"]
[Tue Jul 28 13:35:36.698219 2026] [:error] [pid 31471:tid 140533913564928] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amiUCMbo_8Uj3iOaYH4LvAAAARM"]
[Tue Jul 28 13:35:38.360337 2026] [:error] [pid 31473:tid 140533930350336] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amiUCgiTq2daiUZjsUGGGgAAAVE"]
[Tue Jul 28 13:35:38.360965 2026] [:error] [pid 31473:tid 140533930350336] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amiUCgiTq2daiUZjsUGGGgAAAVE"]
[Tue Jul 28 13:35:38.361314 2026] [:error] [pid 31473:tid 140533930350336] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amiUCgiTq2daiUZjsUGGGgAAAVE"]
[Tue Jul 28 13:35:38.361467 2026] [:error] [pid 31473:tid 140533930350336] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.tmp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.tmp"] [unique_id "amiUCgiTq2daiUZjsUGGGgAAAVE"]
[Tue Jul 28 13:35:38.996518 2026] [:error] [pid 31471:tid 140533955528448] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.php.bak"] [unique_id "amiUCsbo_8Uj3iOaYH4LygAAAQ4"]
[Tue Jul 28 13:35:38.997255 2026] [:error] [pid 31471:tid 140533955528448] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.php.bak"] [unique_id "amiUCsbo_8Uj3iOaYH4LygAAAQ4"]
[Tue Jul 28 13:35:38.997625 2026] [:error] [pid 31471:tid 140533955528448] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env.php.bak"] [unique_id "amiUCsbo_8Uj3iOaYH4LygAAAQ4"]
[Tue Jul 28 13:35:38.997724 2026] [:error] [pid 31471:tid 140533955528448] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.php.bak"] [unique_id "amiUCsbo_8Uj3iOaYH4LygAAAQ4"]
[Tue Jul 28 13:35:38.997951 2026] [:error] [pid 31471:tid 140533955528448] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.php.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.php.bak"] [unique_id "amiUCsbo_8Uj3iOaYH4LygAAAQ4"]
[Tue Jul 28 13:35:39.508529 2026] [:error] [pid 31473:tid 140534095824640] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.php"] [unique_id "amiUCwiTq2daiUZjsUGGIgAAAUY"]
[Tue Jul 28 13:35:39.509337 2026] [:error] [pid 31473:tid 140534095824640] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.php"] [unique_id "amiUCwiTq2daiUZjsUGGIgAAAUY"]
[Tue Jul 28 13:35:39.509717 2026] [:error] [pid 31473:tid 140534095824640] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env.php"] [unique_id "amiUCwiTq2daiUZjsUGGIgAAAUY"]
[Tue Jul 28 13:35:39.509814 2026] [:error] [pid 31473:tid 140534095824640] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.php"] [unique_id "amiUCwiTq2daiUZjsUGGIgAAAUY"]
[Tue Jul 28 13:35:39.510005 2026] [:error] [pid 31473:tid 140534095824640] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.php"] [unique_id "amiUCwiTq2daiUZjsUGGIgAAAUY"]
[Tue Jul 28 13:35:40.290678 2026] [:error] [pid 31471:tid 140534005884672] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amiUDMbo_8Uj3iOaYH4L2AAAAQg"]
[Tue Jul 28 13:35:40.291444 2026] [:error] [pid 31471:tid 140534005884672] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amiUDMbo_8Uj3iOaYH4L2AAAAQg"]
[Tue Jul 28 13:35:40.291860 2026] [:error] [pid 31471:tid 140534005884672] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amiUDMbo_8Uj3iOaYH4L2AAAAQg"]
[Tue Jul 28 13:35:40.292007 2026] [:error] [pid 31471:tid 140534005884672] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.txt"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amiUDMbo_8Uj3iOaYH4L2AAAAQg"]
[Tue Jul 28 13:35:40.561168 2026] [:error] [pid 31473:tid 140533871601408] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amiUDAiTq2daiUZjsUGGKwAAAVg"]
[Tue Jul 28 13:35:40.561996 2026] [:error] [pid 31473:tid 140533871601408] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amiUDAiTq2daiUZjsUGGKwAAAVg"]
[Tue Jul 28 13:35:40.562504 2026] [:error] [pid 31473:tid 140533871601408] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amiUDAiTq2daiUZjsUGGKwAAAVg"]
[Tue Jul 28 13:35:40.562675 2026] [:error] [pid 31473:tid 140533871601408] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amiUDAiTq2daiUZjsUGGKwAAAVg"]
[Tue Jul 28 13:35:41.555297 2026] [:error] [pid 31471:tid 140533888386816] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amiUDcbo_8Uj3iOaYH4L4AAAARY"]
[Tue Jul 28 13:35:41.556170 2026] [:error] [pid 31471:tid 140533888386816] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amiUDcbo_8Uj3iOaYH4L4AAAARY"]
[Tue Jul 28 13:35:41.556606 2026] [:error] [pid 31471:tid 140533888386816] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amiUDcbo_8Uj3iOaYH4L4AAAARY"]
[Tue Jul 28 13:35:41.556734 2026] [:error] [pid 31471:tid 140533888386816] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amiUDcbo_8Uj3iOaYH4L4AAAARY"]
[Tue Jul 28 13:35:41.556946 2026] [:error] [pid 31471:tid 140533888386816] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amiUDcbo_8Uj3iOaYH4L4AAAARY"]
[Tue Jul 28 13:35:42.353932 2026] [:error] [pid 31473:tid 140534121002752] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.json.save"] [unique_id "amiUDgiTq2daiUZjsUGGNwAAAUM"]
[Tue Jul 28 13:35:42.365290 2026] [:error] [pid 31473:tid 140534121002752] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.json.save"] [unique_id "amiUDgiTq2daiUZjsUGGNwAAAUM"]
[Tue Jul 28 13:35:42.365797 2026] [:error] [pid 31473:tid 140534121002752] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/config.json.save"] [unique_id "amiUDgiTq2daiUZjsUGGNwAAAUM"]
[Tue Jul 28 13:35:42.365941 2026] [:error] [pid 31473:tid 140534121002752] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.json.save"] [unique_id "amiUDgiTq2daiUZjsUGGNwAAAUM"]
[Tue Jul 28 13:35:42.564463 2026] [:error] [pid 31471:tid 140533879994112] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amiUDsbo_8Uj3iOaYH4L4wAAARc"]
[Tue Jul 28 13:35:42.565190 2026] [:error] [pid 31471:tid 140533879994112] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amiUDsbo_8Uj3iOaYH4L4wAAARc"]
[Tue Jul 28 13:35:42.565664 2026] [:error] [pid 31471:tid 140533879994112] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amiUDsbo_8Uj3iOaYH4L4wAAARc"]
[Tue Jul 28 13:35:42.565884 2026] [:error] [pid 31471:tid 140533879994112] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amiUDsbo_8Uj3iOaYH4L4wAAARc"]
[Tue Jul 28 13:35:43.528496 2026] [:error] [pid 31473:tid 140534112610048] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.php"] [unique_id "amiUDwiTq2daiUZjsUGGPwAAAUQ"]
[Tue Jul 28 13:35:43.529509 2026] [:error] [pid 31473:tid 140534112610048] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.php"] [unique_id "amiUDwiTq2daiUZjsUGGPwAAAUQ"]
[Tue Jul 28 13:35:43.529846 2026] [:error] [pid 31473:tid 140534112610048] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.php"] [unique_id "amiUDwiTq2daiUZjsUGGPwAAAUQ"]
[Tue Jul 28 13:35:43.983951 2026] [:error] [pid 31471:tid 140533871601408] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.php.bak"] [unique_id "amiUD8bo_8Uj3iOaYH4L6AAAARg"]
[Tue Jul 28 13:35:43.984961 2026] [:error] [pid 31471:tid 140533871601408] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.php.bak"] [unique_id "amiUD8bo_8Uj3iOaYH4L6AAAARg"]
[Tue Jul 28 13:35:43.985534 2026] [:error] [pid 31471:tid 140533871601408] [client 172.71.183.36:12750] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.php.bak"] [unique_id "amiUD8bo_8Uj3iOaYH4L6AAAARg"]
[Tue Jul 28 13:35:44.344513 2026] [:error] [pid 31471:tid 140534095824640] [client 172.71.99.40:12580] [client 172.71.99.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amiUEMbo_8Uj3iOaYH4L7AAAAQY"]
[Tue Jul 28 13:35:44.345432 2026] [:error] [pid 31471:tid 140534095824640] [client 172.71.99.40:12580] [client 172.71.99.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amiUEMbo_8Uj3iOaYH4L7AAAAQY"]
[Tue Jul 28 13:35:44.345850 2026] [:error] [pid 31471:tid 140534095824640] [client 172.71.99.40:12580] [client 172.71.99.40] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amiUEMbo_8Uj3iOaYH4L7AAAAQY"]
[Tue Jul 28 13:35:44.345982 2026] [:error] [pid 31471:tid 140534095824640] [client 172.71.99.40:12580] [client 172.71.99.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "amiUEMbo_8Uj3iOaYH4L7AAAAQY"]
[Tue Jul 28 13:35:45.240459 2026] [:error] [pid 31089:tid 140533972313856] [client 104.23.172.23:10553] [client 104.23.172.23] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aws-config.js"] [unique_id "amiUEaBvmOssEcIc7vpXxgAAAIw"]
[Tue Jul 28 13:35:45.241175 2026] [:error] [pid 31089:tid 140533972313856] [client 104.23.172.23:10553] [client 104.23.172.23] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aws-config.js"] [unique_id "amiUEaBvmOssEcIc7vpXxgAAAIw"]
[Tue Jul 28 13:35:45.241531 2026] [:error] [pid 31089:tid 140533972313856] [client 104.23.172.23:10553] [client 104.23.172.23] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/aws-config.js"] [unique_id "amiUEaBvmOssEcIc7vpXxgAAAIw"]
[Tue Jul 28 13:35:45.685594 2026] [:error] [pid 31356:tid 140533989099264] [client 104.23.166.65:11530] [client 104.23.166.65] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aws.config.js"] [unique_id "amiUEcz37IgzFQUBXwRlzgAAAMo"]
[Tue Jul 28 13:35:45.686975 2026] [:error] [pid 31356:tid 140533989099264] [client 104.23.166.65:11530] [client 104.23.166.65] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aws.config.js"] [unique_id "amiUEcz37IgzFQUBXwRlzgAAAMo"]
[Tue Jul 28 13:35:45.687499 2026] [:error] [pid 31356:tid 140533989099264] [client 104.23.166.65:11530] [client 104.23.166.65] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/aws.config.js"] [unique_id "amiUEcz37IgzFQUBXwRlzgAAAMo"]
[Tue Jul 28 13:35:46.068118 2026] [:error] [pid 31473:tid 140533963921152] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amiUEgiTq2daiUZjsUGGUgAAAU0"]
[Tue Jul 28 13:35:46.069077 2026] [:error] [pid 31473:tid 140533963921152] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amiUEgiTq2daiUZjsUGGUgAAAU0"]
[Tue Jul 28 13:35:46.069513 2026] [:error] [pid 31473:tid 140533963921152] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amiUEgiTq2daiUZjsUGGUgAAAU0"]
[Tue Jul 28 13:35:46.069655 2026] [:error] [pid 31473:tid 140533963921152] [client 172.71.182.50:10260] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amiUEgiTq2daiUZjsUGGUgAAAU0"]
[Tue Jul 28 13:57:35.306409 2026] [:error] [pid 31088:tid 140533888386816] [client 104.22.104.209:12352] [client 104.22.104.209] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiZL_dDbqUNvvZoMq8IRwAAAFY"]
[Tue Jul 28 13:57:35.307049 2026] [:error] [pid 31088:tid 140533888386816] [client 104.22.104.209:12352] [client 104.22.104.209] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiZL_dDbqUNvvZoMq8IRwAAAFY"]
[Tue Jul 28 13:57:35.307449 2026] [:error] [pid 31088:tid 140533888386816] [client 104.22.104.209:12352] [client 104.22.104.209] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiZL_dDbqUNvvZoMq8IRwAAAFY"]
[Tue Jul 28 13:57:51.624422 2026] [:error] [pid 31473:tid 140534146180864] [client 198.41.227.73:13539] [client 198.41.227.73] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiZPwiTq2daiUZjsUGszgAAAUA"]
[Tue Jul 28 13:57:51.625302 2026] [:error] [pid 31473:tid 140534146180864] [client 198.41.227.73:13539] [client 198.41.227.73] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiZPwiTq2daiUZjsUGszgAAAUA"]
[Tue Jul 28 13:57:51.625765 2026] [:error] [pid 31473:tid 140534146180864] [client 198.41.227.73:13539] [client 198.41.227.73] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiZPwiTq2daiUZjsUGszgAAAUA"]
[Tue Jul 28 14:17:16.930833 2026] [:error] [pid 31088:tid 140533905172224] [client 108.162.237.147:9953] [client 108.162.237.147] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amidzPdDbqUNvvZoMq8L2wAAAFQ"]
[Tue Jul 28 14:17:16.931801 2026] [:error] [pid 31088:tid 140533905172224] [client 108.162.237.147:9953] [client 108.162.237.147] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amidzPdDbqUNvvZoMq8L2wAAAFQ"]
[Tue Jul 28 14:17:16.932332 2026] [:error] [pid 31088:tid 140533905172224] [client 108.162.237.147:9953] [client 108.162.237.147] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amidzPdDbqUNvvZoMq8L2wAAAFQ"]
[Tue Jul 28 14:28:47.905834 2026] [:error] [pid 31471:tid 140533879994112] [client 104.22.104.209:11086] [client 104.22.104.209] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amigf8bo_8Uj3iOaYH5C-wAAARc"]
[Tue Jul 28 14:28:47.906972 2026] [:error] [pid 31471:tid 140533879994112] [client 104.22.104.209:11086] [client 104.22.104.209] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amigf8bo_8Uj3iOaYH5C-wAAARc"]
[Tue Jul 28 14:28:47.907641 2026] [:error] [pid 31471:tid 140533879994112] [client 104.22.104.209:11086] [client 104.22.104.209] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amigf8bo_8Uj3iOaYH5C-wAAARc"]
[Tue Jul 28 14:29:27.134668 2026] [:error] [pid 31089:tid 140533980706560] [client 172.71.95.22:13722] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amigp6BvmOssEcIc7vptwgAAAIs"]
[Tue Jul 28 14:29:27.135507 2026] [:error] [pid 31089:tid 140533980706560] [client 172.71.95.22:13722] [client 172.71.95.22] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amigp6BvmOssEcIc7vptwgAAAIs"]
[Tue Jul 28 14:29:27.136068 2026] [:error] [pid 31089:tid 140533980706560] [client 172.71.95.22:13722] [client 172.71.95.22] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amigp6BvmOssEcIc7vptwgAAAIs"]
[Tue Jul 28 14:34:43.349451 2026] [:error] [pid 31471:tid 140533930350336] [client 104.23.243.19:13747] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amih48bo_8Uj3iOaYH5JygAAARE"]
[Tue Jul 28 14:34:43.354676 2026] [:error] [pid 31471:tid 140533930350336] [client 104.23.243.19:13747] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amih48bo_8Uj3iOaYH5JygAAARE"]
[Tue Jul 28 14:34:43.355118 2026] [:error] [pid 31471:tid 140533930350336] [client 104.23.243.19:13747] [client 104.23.243.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amih48bo_8Uj3iOaYH5JygAAARE"]
[Tue Jul 28 14:40:25.116250 2026] [:error] [pid 31473:tid 140533947135744] [client 162.159.110.99:10570] [client 162.159.110.99] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amijOQiTq2daiUZjsUH2egAAAU8"], referer: https://www.sbf-consultancy.com/
[Tue Jul 28 14:40:25.117077 2026] [:error] [pid 31473:tid 140533947135744] [client 162.159.110.99:10570] [client 162.159.110.99] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amijOQiTq2daiUZjsUH2egAAAU8"], referer: https://www.sbf-consultancy.com/
[Tue Jul 28 14:40:25.117516 2026] [:error] [pid 31473:tid 140533947135744] [client 162.159.110.99:10570] [client 162.159.110.99] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amijOQiTq2daiUZjsUH2egAAAU8"], referer: https://www.sbf-consultancy.com/
[Tue Jul 28 14:40:25.136059 2026] [:error] [pid 31473:tid 140533972313856] [client 162.159.110.91:10525] [client 162.159.110.91] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amijOQiTq2daiUZjsUH2fAAAAUw"], referer: https://sbf-consultancy.com/
[Tue Jul 28 14:40:25.137129 2026] [:error] [pid 31473:tid 140533972313856] [client 162.159.110.91:10525] [client 162.159.110.91] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amijOQiTq2daiUZjsUH2fAAAAUw"], referer: https://sbf-consultancy.com/
[Tue Jul 28 14:40:25.137751 2026] [:error] [pid 31473:tid 140533972313856] [client 162.159.110.91:10525] [client 162.159.110.91] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amijOQiTq2daiUZjsUH2fAAAAUw"], referer: https://sbf-consultancy.com/
[Tue Jul 28 14:48:47.441372 2026] [:error] [pid 31089:tid 140533913564928] [client 172.68.23.228:13407] [client 172.68.23.228] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amilL6BvmOssEcIc7vp2OwAAAJM"]
[Tue Jul 28 14:48:47.442151 2026] [:error] [pid 31089:tid 140533913564928] [client 172.68.23.228:13407] [client 172.68.23.228] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amilL6BvmOssEcIc7vp2OwAAAJM"]
[Tue Jul 28 14:48:47.442447 2026] [:error] [pid 31089:tid 140533913564928] [client 172.68.23.228:13407] [client 172.68.23.228] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amilL6BvmOssEcIc7vp2OwAAAJM"]
[Tue Jul 28 14:48:47.442547 2026] [:error] [pid 31089:tid 140533913564928] [client 172.68.23.228:13407] [client 172.68.23.228] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amilL6BvmOssEcIc7vp2OwAAAJM"]
[Tue Jul 28 14:49:00.310411 2026] [:error] [pid 31088:tid 140533997491968] [client 104.23.170.162:10419] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amilPPdDbqUNvvZoMq8TJwAAAEk"]
[Tue Jul 28 14:49:00.311112 2026] [:error] [pid 31088:tid 140533997491968] [client 104.23.170.162:10419] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amilPPdDbqUNvvZoMq8TJwAAAEk"]
[Tue Jul 28 14:49:00.311625 2026] [:error] [pid 31088:tid 140533997491968] [client 104.23.170.162:10419] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amilPPdDbqUNvvZoMq8TJwAAAEk"]
[Tue Jul 28 14:49:14.412741 2026] [:error] [pid 31471:tid 140534104217344] [client 104.23.243.181:12018] [client 104.23.243.181] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amilSsbo_8Uj3iOaYH5Y0QAAAQU"]
[Tue Jul 28 14:49:14.413828 2026] [:error] [pid 31471:tid 140534104217344] [client 104.23.243.181:12018] [client 104.23.243.181] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amilSsbo_8Uj3iOaYH5Y0QAAAQU"]
[Tue Jul 28 14:49:14.414371 2026] [:error] [pid 31471:tid 140534104217344] [client 104.23.243.181:12018] [client 104.23.243.181] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amilSsbo_8Uj3iOaYH5Y0QAAAQU"]
[Tue Jul 28 14:53:58.905582 2026] [:error] [pid 31471:tid 140533930350336] [client 172.71.151.133:13810] [client 172.71.151.133] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amimZsbo_8Uj3iOaYH5dwQAAARE"]
[Tue Jul 28 14:53:58.906473 2026] [:error] [pid 31471:tid 140533930350336] [client 172.71.151.133:13810] [client 172.71.151.133] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amimZsbo_8Uj3iOaYH5dwQAAARE"]
[Tue Jul 28 14:53:58.906987 2026] [:error] [pid 31471:tid 140533930350336] [client 172.71.151.133:13810] [client 172.71.151.133] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amimZsbo_8Uj3iOaYH5dwQAAARE"]
[Tue Jul 28 14:53:58.907081 2026] [:error] [pid 31471:tid 140533930350336] [client 172.71.151.133:13810] [client 172.71.151.133] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amimZsbo_8Uj3iOaYH5dwQAAARE"]
[Tue Jul 28 15:13:17.233111 2026] [:error] [pid 31473:tid 140534121002752] [client 172.68.238.78:10780] [client 172.68.238.78] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiq7QiTq2daiUZjsUEwbQAAAUM"]
[Tue Jul 28 15:13:17.234161 2026] [:error] [pid 31473:tid 140534121002752] [client 172.68.238.78:10780] [client 172.68.238.78] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiq7QiTq2daiUZjsUEwbQAAAUM"]
[Tue Jul 28 15:13:17.234682 2026] [:error] [pid 31473:tid 140534121002752] [client 172.68.238.78:10780] [client 172.68.238.78] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiq7QiTq2daiUZjsUEwbQAAAUM"]
[Tue Jul 28 15:16:38.225876 2026] [:error] [pid 31087:tid 140534129395456] [client 108.162.241.6:9972] [client 108.162.241.6] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amirtsmap6NoEp6N8uDk4AAAAAI"]
[Tue Jul 28 15:16:38.226560 2026] [:error] [pid 31087:tid 140534129395456] [client 108.162.241.6:9972] [client 108.162.241.6] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amirtsmap6NoEp6N8uDk4AAAAAI"]
[Tue Jul 28 15:16:38.227079 2026] [:error] [pid 31087:tid 140534129395456] [client 108.162.241.6:9972] [client 108.162.241.6] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amirtsmap6NoEp6N8uDk4AAAAAI"]
[Tue Jul 28 15:17:16.562482 2026] [:error] [pid 31088:tid 140533888386816] [client 104.23.223.54:11102] [client 104.23.223.54] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amir3PdDbqUNvvZoMq8dYAAAAFY"]
[Tue Jul 28 15:17:16.563568 2026] [:error] [pid 31088:tid 140533888386816] [client 104.23.223.54:11102] [client 104.23.223.54] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amir3PdDbqUNvvZoMq8dYAAAAFY"]
[Tue Jul 28 15:17:16.564217 2026] [:error] [pid 31088:tid 140533888386816] [client 104.23.223.54:11102] [client 104.23.223.54] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amir3PdDbqUNvvZoMq8dYAAAAFY"]
[Tue Jul 28 15:25:41.771885 2026] [:error] [pid 31087:tid 140534104217344] [client 104.23.211.16:9916] [client 104.23.211.16] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amit1cmap6NoEp6N8uDnngAAAAU"]
[Tue Jul 28 15:25:41.772565 2026] [:error] [pid 31087:tid 140534104217344] [client 104.23.211.16:9916] [client 104.23.211.16] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amit1cmap6NoEp6N8uDnngAAAAU"]
[Tue Jul 28 15:25:41.772965 2026] [:error] [pid 31087:tid 140534104217344] [client 104.23.211.16:9916] [client 104.23.211.16] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amit1cmap6NoEp6N8uDnngAAAAU"]
[Tue Jul 28 15:38:56.515448 2026] [:error] [pid 31473:tid 140533921957632] [client 172.68.245.5:10835] [client 172.68.245.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiw8AiTq2daiUZjsUFccwAAAVI"]
[Tue Jul 28 15:38:56.520203 2026] [:error] [pid 31473:tid 140533921957632] [client 172.68.245.5:10835] [client 172.68.245.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiw8AiTq2daiUZjsUFccwAAAVI"]
[Tue Jul 28 15:38:56.520768 2026] [:error] [pid 31473:tid 140533921957632] [client 172.68.245.5:10835] [client 172.68.245.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amiw8AiTq2daiUZjsUFccwAAAVI"]
[Tue Jul 28 15:39:37.849279 2026] [:error] [pid 31473:tid 140533963921152] [client 104.22.93.88:13714] [client 104.22.93.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amixGQiTq2daiUZjsUFd0AAAAU0"]
[Tue Jul 28 15:39:37.850211 2026] [:error] [pid 31473:tid 140533963921152] [client 104.22.93.88:13714] [client 104.22.93.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amixGQiTq2daiUZjsUFd0AAAAU0"]
[Tue Jul 28 15:39:37.850991 2026] [:error] [pid 31473:tid 140533963921152] [client 104.22.93.88:13714] [client 104.22.93.88] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua=\\x22Not)A;Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22138\\x22, \\x22HeadlessChrome\\x22;v=\\x22138\\x22"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amixGQiTq2daiUZjsUFd0AAAAU0"]
[Tue Jul 28 15:39:37.851047 2026] [:error] [pid 31473:tid 140533963921152] [client 104.22.93.88:13714] [client 104.22.93.88] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amixGQiTq2daiUZjsUFd0AAAAU0"]
[Tue Jul 28 15:39:37.851099 2026] [:error] [pid 31473:tid 140533963921152] [client 104.22.93.88:13714] [client 104.22.93.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amixGQiTq2daiUZjsUFd0AAAAU0"]
[Tue Jul 28 15:53:02.197659 2026] [:error] [pid 31473:tid 140533888386816] [client 162.158.244.153:11279] [client 162.158.244.153] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "ami0PgiTq2daiUZjsUF23QAAAVY"]
[Tue Jul 28 15:53:02.198669 2026] [:error] [pid 31473:tid 140533888386816] [client 162.158.244.153:11279] [client 162.158.244.153] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "ami0PgiTq2daiUZjsUF23QAAAVY"]
[Tue Jul 28 15:53:02.199012 2026] [:error] [pid 31473:tid 140533888386816] [client 162.158.244.153:11279] [client 162.158.244.153] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "ami0PgiTq2daiUZjsUF23QAAAVY"]
[Tue Jul 28 15:53:02.199101 2026] [:error] [pid 31473:tid 140533888386816] [client 162.158.244.153:11279] [client 162.158.244.153] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "ami0PgiTq2daiUZjsUF23QAAAVY"]
[Tue Jul 28 15:53:02.199229 2026] [:error] [pid 31473:tid 140533888386816] [client 162.158.244.153:11279] [client 162.158.244.153] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "ami0PgiTq2daiUZjsUF23QAAAVY"]
[Tue Jul 28 16:06:19.021666 2026] [:error] [pid 31473:tid 140534095824640] [client 162.158.152.148:12698] [client 162.158.152.148] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ami3WwiTq2daiUZjsUGOdQAAAUY"]
[Tue Jul 28 16:06:19.022539 2026] [:error] [pid 31473:tid 140534095824640] [client 162.158.152.148:12698] [client 162.158.152.148] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ami3WwiTq2daiUZjsUGOdQAAAUY"]
[Tue Jul 28 16:06:19.023074 2026] [:error] [pid 31473:tid 140534095824640] [client 162.158.152.148:12698] [client 162.158.152.148] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ami3WwiTq2daiUZjsUGOdQAAAUY"]
[Tue Jul 28 16:09:17.555672 2026] [:error] [pid 31088:tid 140534121002752] [client 104.23.172.125:13596] [client 104.23.172.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ami4DfdDbqUNvvZoMq8vwQAAAEM"]
[Tue Jul 28 16:09:17.556727 2026] [:error] [pid 31088:tid 140534121002752] [client 104.23.172.125:13596] [client 104.23.172.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ami4DfdDbqUNvvZoMq8vwQAAAEM"]
[Tue Jul 28 16:09:17.557307 2026] [:error] [pid 31088:tid 140534121002752] [client 104.23.172.125:13596] [client 104.23.172.125] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ami4DfdDbqUNvvZoMq8vwQAAAEM"]
[Tue Jul 28 16:09:17.557544 2026] [:error] [pid 31088:tid 140534121002752] [client 104.23.172.125:13596] [client 104.23.172.125] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ami4DfdDbqUNvvZoMq8vwQAAAEM"]
[Tue Jul 28 16:09:19.548300 2026] [:error] [pid 31471:tid 140533921957632] [client 104.23.166.83:10219] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aws.env"] [unique_id "ami4D8bo_8Uj3iOaYH6oyAAAARI"]
[Tue Jul 28 16:09:19.549244 2026] [:error] [pid 31471:tid 140533921957632] [client 104.23.166.83:10219] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aws.env"] [unique_id "ami4D8bo_8Uj3iOaYH6oyAAAARI"]
[Tue Jul 28 16:09:19.549707 2026] [:error] [pid 31471:tid 140533921957632] [client 104.23.166.83:10219] [client 104.23.166.83] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/aws.env"] [unique_id "ami4D8bo_8Uj3iOaYH6oyAAAARI"]
[Tue Jul 28 16:09:19.549832 2026] [:error] [pid 31471:tid 140533921957632] [client 104.23.166.83:10219] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/aws.env"] [unique_id "ami4D8bo_8Uj3iOaYH6oyAAAARI"]
[Tue Jul 28 16:09:19.597518 2026] [:error] [pid 31473:tid 140533888386816] [client 172.71.98.106:10626] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "ami4DwiTq2daiUZjsUGTkQAAAVY"]
[Tue Jul 28 16:09:19.598270 2026] [:error] [pid 31473:tid 140533888386816] [client 172.71.98.106:10626] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "ami4DwiTq2daiUZjsUGTkQAAAVY"]
[Tue Jul 28 16:09:19.598735 2026] [:error] [pid 31473:tid 140533888386816] [client 172.71.98.106:10626] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "ami4DwiTq2daiUZjsUGTkQAAAVY"]
[Tue Jul 28 16:09:19.598995 2026] [:error] [pid 31473:tid 140533888386816] [client 172.71.98.106:10626] [client 172.71.98.106] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "ami4DwiTq2daiUZjsUGTkQAAAVY"]
[Tue Jul 28 16:19:44.646641 2026] [:error] [pid 31088:tid 140533888386816] [client 172.69.60.207:12556] [client 172.69.60.207] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ami6gPdDbqUNvvZoMq8yXQAAAFY"]
[Tue Jul 28 16:19:44.647346 2026] [:error] [pid 31088:tid 140533888386816] [client 172.69.60.207:12556] [client 172.69.60.207] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ami6gPdDbqUNvvZoMq8yXQAAAFY"]
[Tue Jul 28 16:19:44.647701 2026] [:error] [pid 31088:tid 140533888386816] [client 172.69.60.207:12556] [client 172.69.60.207] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ami6gPdDbqUNvvZoMq8yXQAAAFY"]
[Tue Jul 28 16:19:45.734618 2026] [:error] [pid 31473:tid 140534005884672] [client 172.68.210.253:10624] [client 172.68.210.253] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ami6gQiTq2daiUZjsUGj2gAAAUg"]
[Tue Jul 28 16:19:45.735710 2026] [:error] [pid 31473:tid 140534005884672] [client 172.68.210.253:10624] [client 172.68.210.253] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ami6gQiTq2daiUZjsUGj2gAAAUg"]
[Tue Jul 28 16:19:45.736223 2026] [:error] [pid 31473:tid 140534005884672] [client 172.68.210.253:10624] [client 172.68.210.253] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ami6gQiTq2daiUZjsUGj2gAAAUg"]
[Tue Jul 28 16:40:17.485605 2026] [:error] [pid 31473:tid 140533938743040] [client 104.23.211.17:12740] [client 104.23.211.17] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ami_UQiTq2daiUZjsUHFUgAAAVA"]
[Tue Jul 28 16:40:17.532306 2026] [:error] [pid 31473:tid 140533938743040] [client 104.23.211.17:12740] [client 104.23.211.17] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ami_UQiTq2daiUZjsUHFUgAAAVA"]
[Tue Jul 28 16:40:17.532770 2026] [:error] [pid 31473:tid 140533938743040] [client 104.23.211.17:12740] [client 104.23.211.17] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ami_UQiTq2daiUZjsUHFUgAAAVA"]
[Tue Jul 28 16:40:17.532902 2026] [:error] [pid 31473:tid 140533938743040] [client 104.23.211.17:12740] [client 104.23.211.17] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ami_UQiTq2daiUZjsUHFUgAAAVA"]
[Tue Jul 28 16:49:25.565676 2026] [:error] [pid 31471:tid 140533938743040] [client 104.23.243.19:13958] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amjBdcbo_8Uj3iOaYH7O9AAAARA"]
[Tue Jul 28 16:49:25.566367 2026] [:error] [pid 31471:tid 140533938743040] [client 104.23.243.19:13958] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amjBdcbo_8Uj3iOaYH7O9AAAARA"]
[Tue Jul 28 16:49:25.566800 2026] [:error] [pid 31471:tid 140533938743040] [client 104.23.243.19:13958] [client 104.23.243.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amjBdcbo_8Uj3iOaYH7O9AAAARA"]
[Tue Jul 28 16:55:42.100989 2026] [:error] [pid 31473:tid 140533921957632] [client 104.23.197.77:12646] [client 104.23.197.77] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amjC7giTq2daiUZjsUHcqgAAAVI"]
[Tue Jul 28 16:55:42.101911 2026] [:error] [pid 31473:tid 140533921957632] [client 104.23.197.77:12646] [client 104.23.197.77] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amjC7giTq2daiUZjsUHcqgAAAVI"]
[Tue Jul 28 16:55:42.102361 2026] [:error] [pid 31473:tid 140533921957632] [client 104.23.197.77:12646] [client 104.23.197.77] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amjC7giTq2daiUZjsUHcqgAAAVI"]
[Tue Jul 28 16:57:26.707958 2026] [:error] [pid 31473:tid 140533947135744] [client 172.70.240.105:11119] [client 172.70.240.105] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amjDVgiTq2daiUZjsUHe2wAAAU8"]
[Tue Jul 28 16:57:26.708920 2026] [:error] [pid 31473:tid 140533947135744] [client 172.70.240.105:11119] [client 172.70.240.105] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amjDVgiTq2daiUZjsUHe2wAAAU8"]
[Tue Jul 28 16:57:26.709562 2026] [:error] [pid 31473:tid 140533947135744] [client 172.70.240.105:11119] [client 172.70.240.105] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amjDVgiTq2daiUZjsUHe2wAAAU8"]
[Tue Jul 28 17:07:19.354381 2026] [:error] [pid 31356:tid 140533905172224] [client 172.71.154.26:11483] [client 172.71.154.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-json/batch/v1"] [unique_id "amjFp8z37IgzFQUBXwTl0wAAANQ"]
[Tue Jul 28 17:07:19.355373 2026] [:error] [pid 31356:tid 140533905172224] [client 172.71.154.26:11483] [client 172.71.154.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-json/batch/v1"] [unique_id "amjFp8z37IgzFQUBXwTl0wAAANQ"]
[Tue Jul 28 17:07:19.355688 2026] [:error] [pid 31356:tid 140533905172224] [client 172.71.154.26:11483] [client 172.71.154.26] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-json/batch/v1"] [unique_id "amjFp8z37IgzFQUBXwTl0wAAANQ"]
[Tue Jul 28 17:07:19.356007 2026] [:error] [pid 31356:tid 140533905172224] [client 172.71.154.26:11483] [client 172.71.154.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-json/batch/v1"] [unique_id "amjFp8z37IgzFQUBXwTl0wAAANQ"]
[Tue Jul 28 17:07:19.831438 2026] [:error] [pid 31471:tid 140533989099264] [client 104.22.17.80:10504] [client 104.22.17.80] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjFp8bo_8Uj3iOaYH7gIQAAAQo"]
[Tue Jul 28 17:07:19.832317 2026] [:error] [pid 31471:tid 140533989099264] [client 104.22.17.80:10504] [client 104.22.17.80] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjFp8bo_8Uj3iOaYH7gIQAAAQo"]
[Tue Jul 28 17:07:19.832635 2026] [:error] [pid 31471:tid 140533989099264] [client 104.22.17.80:10504] [client 104.22.17.80] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/json|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjFp8bo_8Uj3iOaYH7gIQAAAQo"]
[Tue Jul 28 17:07:19.832993 2026] [:error] [pid 31471:tid 140533989099264] [client 104.22.17.80:10504] [client 104.22.17.80] ModSecurity: Warning. Found 2 byte(s) in ARGS:rest_route outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:rest_route=/batch/v1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjFp8bo_8Uj3iOaYH7gIQAAAQo"]
[Tue Jul 28 17:07:19.833056 2026] [:error] [pid 31471:tid 140533989099264] [client 104.22.17.80:10504] [client 104.22.17.80] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjFp8bo_8Uj3iOaYH7gIQAAAQo"]
[Tue Jul 28 17:13:40.643715 2026] [:error] [pid 31471:tid 140533913564928] [client 104.22.72.43:13596] [client 104.22.72.43] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amjHJMbo_8Uj3iOaYH7nOgAAARM"]
[Tue Jul 28 17:13:40.644826 2026] [:error] [pid 31471:tid 140533913564928] [client 104.22.72.43:13596] [client 104.22.72.43] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amjHJMbo_8Uj3iOaYH7nOgAAARM"]
[Tue Jul 28 17:13:40.645388 2026] [:error] [pid 31471:tid 140533913564928] [client 104.22.72.43:13596] [client 104.22.72.43] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amjHJMbo_8Uj3iOaYH7nOgAAARM"]
[Tue Jul 28 17:13:40.645599 2026] [:error] [pid 31471:tid 140533913564928] [client 104.22.72.43:13596] [client 104.22.72.43] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amjHJMbo_8Uj3iOaYH7nOgAAARM"]
[Tue Jul 28 17:21:31.307915 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amjI-8bo_8Uj3iOaYH7stAAAARM"]
[Tue Jul 28 17:21:31.308964 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amjI-8bo_8Uj3iOaYH7stAAAARM"]
[Tue Jul 28 17:21:31.309401 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amjI-8bo_8Uj3iOaYH7stAAAARM"]
[Tue Jul 28 17:21:31.309492 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amjI-8bo_8Uj3iOaYH7stAAAARM"]
[Tue Jul 28 17:21:31.916661 2026] [:error] [pid 31356:tid 140533980706560] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amjI-8z37IgzFQUBXwTtJQAAAMs"]
[Tue Jul 28 17:21:31.917644 2026] [:error] [pid 31356:tid 140533980706560] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amjI-8z37IgzFQUBXwTtJQAAAMs"]
[Tue Jul 28 17:21:31.918067 2026] [:error] [pid 31356:tid 140533980706560] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amjI-8z37IgzFQUBXwTtJQAAAMs"]
[Tue Jul 28 17:21:31.918149 2026] [:error] [pid 31356:tid 140533980706560] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amjI-8z37IgzFQUBXwTtJQAAAMs"]
[Tue Jul 28 17:21:32.285782 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/x.php"] [unique_id "amjI_Mbo_8Uj3iOaYH7stQAAARQ"]
[Tue Jul 28 17:21:32.286699 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/x.php"] [unique_id "amjI_Mbo_8Uj3iOaYH7stQAAARQ"]
[Tue Jul 28 17:21:32.287105 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/x.php"] [unique_id "amjI_Mbo_8Uj3iOaYH7stQAAARQ"]
[Tue Jul 28 17:21:32.287192 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/x.php"] [unique_id "amjI_Mbo_8Uj3iOaYH7stQAAARQ"]
[Tue Jul 28 17:21:32.504529 2026] [:error] [pid 31356:tid 140533955528448] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mgrr.php"] [unique_id "amjI_Mz37IgzFQUBXwTtKAAAAM4"]
[Tue Jul 28 17:21:32.505012 2026] [:error] [pid 31356:tid 140533955528448] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mgrr.php"] [unique_id "amjI_Mz37IgzFQUBXwTtKAAAAM4"]
[Tue Jul 28 17:21:32.505299 2026] [:error] [pid 31356:tid 140533955528448] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/mgrr.php"] [unique_id "amjI_Mz37IgzFQUBXwTtKAAAAM4"]
[Tue Jul 28 17:21:32.505410 2026] [:error] [pid 31356:tid 140533955528448] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mgrr.php"] [unique_id "amjI_Mz37IgzFQUBXwTtKAAAAM4"]
[Tue Jul 28 17:21:32.728600 2026] [:error] [pid 31471:tid 140534014277376] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/stdin.php"] [unique_id "amjI_Mbo_8Uj3iOaYH7suAAAAQc"]
[Tue Jul 28 17:21:32.729417 2026] [:error] [pid 31471:tid 140534014277376] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/stdin.php"] [unique_id "amjI_Mbo_8Uj3iOaYH7suAAAAQc"]
[Tue Jul 28 17:21:32.729910 2026] [:error] [pid 31471:tid 140534014277376] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/stdin.php"] [unique_id "amjI_Mbo_8Uj3iOaYH7suAAAAQc"]
[Tue Jul 28 17:21:32.730023 2026] [:error] [pid 31471:tid 140534014277376] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/stdin.php"] [unique_id "amjI_Mbo_8Uj3iOaYH7suAAAAQc"]
[Tue Jul 28 17:21:32.952979 2026] [:error] [pid 31356:tid 140533888386816] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/BDKR28.php"] [unique_id "amjI_Mz37IgzFQUBXwTtKwAAANY"]
[Tue Jul 28 17:21:32.953677 2026] [:error] [pid 31356:tid 140533888386816] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/BDKR28.php"] [unique_id "amjI_Mz37IgzFQUBXwTtKwAAANY"]
[Tue Jul 28 17:21:32.953933 2026] [:error] [pid 31356:tid 140533888386816] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/BDKR28.php"] [unique_id "amjI_Mz37IgzFQUBXwTtKwAAANY"]
[Tue Jul 28 17:21:32.953984 2026] [:error] [pid 31356:tid 140533888386816] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/BDKR28.php"] [unique_id "amjI_Mz37IgzFQUBXwTtKwAAANY"]
[Tue Jul 28 17:21:33.177266 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/001.php"] [unique_id "amjI_cbo_8Uj3iOaYH7svQAAAQE"]
[Tue Jul 28 17:21:33.177891 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/001.php"] [unique_id "amjI_cbo_8Uj3iOaYH7svQAAAQE"]
[Tue Jul 28 17:21:33.178178 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/001.php"] [unique_id "amjI_cbo_8Uj3iOaYH7svQAAAQE"]
[Tue Jul 28 17:21:33.178240 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/001.php"] [unique_id "amjI_cbo_8Uj3iOaYH7svQAAAQE"]
[Tue Jul 28 17:21:33.393659 2026] [:error] [pid 31356:tid 140533930350336] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/yup.php"] [unique_id "amjI_cz37IgzFQUBXwTtLgAAANE"]
[Tue Jul 28 17:21:33.394263 2026] [:error] [pid 31356:tid 140533930350336] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/yup.php"] [unique_id "amjI_cz37IgzFQUBXwTtLgAAANE"]
[Tue Jul 28 17:21:33.394592 2026] [:error] [pid 31356:tid 140533930350336] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/yup.php"] [unique_id "amjI_cz37IgzFQUBXwTtLgAAANE"]
[Tue Jul 28 17:21:33.394666 2026] [:error] [pid 31356:tid 140533930350336] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/yup.php"] [unique_id "amjI_cz37IgzFQUBXwTtLgAAANE"]
[Tue Jul 28 17:21:33.616829 2026] [:error] [pid 31471:tid 140533997491968] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/X.php"] [unique_id "amjI_cbo_8Uj3iOaYH7swwAAAQk"]
[Tue Jul 28 17:21:33.617605 2026] [:error] [pid 31471:tid 140533997491968] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/X.php"] [unique_id "amjI_cbo_8Uj3iOaYH7swwAAAQk"]
[Tue Jul 28 17:21:33.617927 2026] [:error] [pid 31471:tid 140533997491968] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/X.php"] [unique_id "amjI_cbo_8Uj3iOaYH7swwAAAQk"]
[Tue Jul 28 17:21:33.617989 2026] [:error] [pid 31471:tid 140533997491968] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/X.php"] [unique_id "amjI_cbo_8Uj3iOaYH7swwAAAQk"]
[Tue Jul 28 17:21:33.836683 2026] [:error] [pid 31356:tid 140533938743040] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/1polka.php"] [unique_id "amjI_cz37IgzFQUBXwTtMAAAANA"]
[Tue Jul 28 17:21:33.837393 2026] [:error] [pid 31356:tid 140533938743040] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/1polka.php"] [unique_id "amjI_cz37IgzFQUBXwTtMAAAANA"]
[Tue Jul 28 17:21:33.837695 2026] [:error] [pid 31356:tid 140533938743040] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/1polka.php"] [unique_id "amjI_cz37IgzFQUBXwTtMAAAANA"]
[Tue Jul 28 17:21:33.837748 2026] [:error] [pid 31356:tid 140533938743040] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/1polka.php"] [unique_id "amjI_cz37IgzFQUBXwTtMAAAANA"]
[Tue Jul 28 17:21:34.060771 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gec.php"] [unique_id "amjI_sbo_8Uj3iOaYH7sxwAAARY"]
[Tue Jul 28 17:21:34.061637 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gec.php"] [unique_id "amjI_sbo_8Uj3iOaYH7sxwAAARY"]
[Tue Jul 28 17:21:34.062003 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/gec.php"] [unique_id "amjI_sbo_8Uj3iOaYH7sxwAAARY"]
[Tue Jul 28 17:21:34.062099 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gec.php"] [unique_id "amjI_sbo_8Uj3iOaYH7sxwAAARY"]
[Tue Jul 28 17:21:34.278658 2026] [:error] [pid 31356:tid 140533921957632] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sky.php"] [unique_id "amjI_sz37IgzFQUBXwTtMgAAANI"]
[Tue Jul 28 17:21:34.279535 2026] [:error] [pid 31356:tid 140533921957632] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sky.php"] [unique_id "amjI_sz37IgzFQUBXwTtMgAAANI"]
[Tue Jul 28 17:21:34.279931 2026] [:error] [pid 31356:tid 140533921957632] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sky.php"] [unique_id "amjI_sz37IgzFQUBXwTtMgAAANI"]
[Tue Jul 28 17:21:34.280162 2026] [:error] [pid 31356:tid 140533921957632] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sky.php"] [unique_id "amjI_sz37IgzFQUBXwTtMgAAANI"]
[Tue Jul 28 17:21:34.522728 2026] [:error] [pid 31471:tid 140533947135744] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fffm.php"] [unique_id "amjI_sbo_8Uj3iOaYH7szAAAAQ8"]
[Tue Jul 28 17:21:34.523543 2026] [:error] [pid 31471:tid 140533947135744] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fffm.php"] [unique_id "amjI_sbo_8Uj3iOaYH7szAAAAQ8"]
[Tue Jul 28 17:21:34.523903 2026] [:error] [pid 31471:tid 140533947135744] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fffm.php"] [unique_id "amjI_sbo_8Uj3iOaYH7szAAAAQ8"]
[Tue Jul 28 17:21:34.523964 2026] [:error] [pid 31471:tid 140533947135744] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/fffm.php"] [unique_id "amjI_sbo_8Uj3iOaYH7szAAAAQ8"]
[Tue Jul 28 17:21:34.739299 2026] [:error] [pid 31356:tid 140533989099264] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sixxis.php"] [unique_id "amjI_sz37IgzFQUBXwTtNAAAAMo"]
[Tue Jul 28 17:21:34.739906 2026] [:error] [pid 31356:tid 140533989099264] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sixxis.php"] [unique_id "amjI_sz37IgzFQUBXwTtNAAAAMo"]
[Tue Jul 28 17:21:34.740217 2026] [:error] [pid 31356:tid 140533989099264] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sixxis.php"] [unique_id "amjI_sz37IgzFQUBXwTtNAAAAMo"]
[Tue Jul 28 17:21:34.740272 2026] [:error] [pid 31356:tid 140533989099264] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sixxis.php"] [unique_id "amjI_sz37IgzFQUBXwTtNAAAAMo"]
[Tue Jul 28 17:21:34.960474 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/yj09.php"] [unique_id "amjI_sbo_8Uj3iOaYH7szwAAAQ4"]
[Tue Jul 28 17:21:34.961333 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/yj09.php"] [unique_id "amjI_sbo_8Uj3iOaYH7szwAAAQ4"]
[Tue Jul 28 17:21:34.961762 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/yj09.php"] [unique_id "amjI_sbo_8Uj3iOaYH7szwAAAQ4"]
[Tue Jul 28 17:21:34.961883 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/yj09.php"] [unique_id "amjI_sbo_8Uj3iOaYH7szwAAAQ4"]
[Tue Jul 28 17:21:35.184067 2026] [:error] [pid 31356:tid 140533879994112] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/k.php"] [unique_id "amjI_8z37IgzFQUBXwTtNgAAANc"]
[Tue Jul 28 17:21:35.184748 2026] [:error] [pid 31356:tid 140533879994112] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/k.php"] [unique_id "amjI_8z37IgzFQUBXwTtNgAAANc"]
[Tue Jul 28 17:21:35.185025 2026] [:error] [pid 31356:tid 140533879994112] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/k.php"] [unique_id "amjI_8z37IgzFQUBXwTtNgAAANc"]
[Tue Jul 28 17:21:35.185078 2026] [:error] [pid 31356:tid 140533879994112] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/k.php"] [unique_id "amjI_8z37IgzFQUBXwTtNgAAANc"]
[Tue Jul 28 17:21:35.400172 2026] [:error] [pid 31356:tid 140534005884672] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/k2.php"] [unique_id "amjI_8z37IgzFQUBXwTtNwAAAMg"]
[Tue Jul 28 17:21:35.400858 2026] [:error] [pid 31356:tid 140534005884672] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/k2.php"] [unique_id "amjI_8z37IgzFQUBXwTtNwAAAMg"]
[Tue Jul 28 17:21:35.401109 2026] [:error] [pid 31356:tid 140534005884672] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/k2.php"] [unique_id "amjI_8z37IgzFQUBXwTtNwAAAMg"]
[Tue Jul 28 17:21:35.401186 2026] [:error] [pid 31356:tid 140534005884672] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/k2.php"] [unique_id "amjI_8z37IgzFQUBXwTtNwAAAMg"]
[Tue Jul 28 17:21:35.630340 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/w.php"] [unique_id "amjI_8bo_8Uj3iOaYH7s1gAAAQo"]
[Tue Jul 28 17:21:35.631401 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/w.php"] [unique_id "amjI_8bo_8Uj3iOaYH7s1gAAAQo"]
[Tue Jul 28 17:21:35.631783 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/w.php"] [unique_id "amjI_8bo_8Uj3iOaYH7s1gAAAQo"]
[Tue Jul 28 17:21:35.631854 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/w.php"] [unique_id "amjI_8bo_8Uj3iOaYH7s1gAAAQo"]
[Tue Jul 28 17:21:35.850176 2026] [:error] [pid 31356:tid 140533871601408] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fpwch.php"] [unique_id "amjI_8z37IgzFQUBXwTtOgAAANg"]
[Tue Jul 28 17:21:35.851139 2026] [:error] [pid 31356:tid 140533871601408] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fpwch.php"] [unique_id "amjI_8z37IgzFQUBXwTtOgAAANg"]
[Tue Jul 28 17:21:35.851642 2026] [:error] [pid 31356:tid 140533871601408] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fpwch.php"] [unique_id "amjI_8z37IgzFQUBXwTtOgAAANg"]
[Tue Jul 28 17:21:35.851740 2026] [:error] [pid 31356:tid 140533871601408] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/fpwch.php"] [unique_id "amjI_8z37IgzFQUBXwTtOgAAANg"]
[Tue Jul 28 17:21:36.075967 2026] [:error] [pid 31471:tid 140534014277376] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/w2025.php"] [unique_id "amjJAMbo_8Uj3iOaYH7s2AAAAQc"]
[Tue Jul 28 17:21:36.077137 2026] [:error] [pid 31471:tid 140534014277376] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/w2025.php"] [unique_id "amjJAMbo_8Uj3iOaYH7s2AAAAQc"]
[Tue Jul 28 17:21:36.077844 2026] [:error] [pid 31471:tid 140534014277376] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/w2025.php"] [unique_id "amjJAMbo_8Uj3iOaYH7s2AAAAQc"]
[Tue Jul 28 17:21:36.077999 2026] [:error] [pid 31471:tid 140534014277376] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/w2025.php"] [unique_id "amjJAMbo_8Uj3iOaYH7s2AAAAQc"]
[Tue Jul 28 17:21:36.296022 2026] [:error] [pid 31356:tid 140534104217344] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/FWAZ.php"] [unique_id "amjJAMz37IgzFQUBXwTtPAAAAMU"]
[Tue Jul 28 17:21:36.296669 2026] [:error] [pid 31356:tid 140534104217344] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/FWAZ.php"] [unique_id "amjJAMz37IgzFQUBXwTtPAAAAMU"]
[Tue Jul 28 17:21:36.296945 2026] [:error] [pid 31356:tid 140534104217344] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/FWAZ.php"] [unique_id "amjJAMz37IgzFQUBXwTtPAAAAMU"]
[Tue Jul 28 17:21:36.297009 2026] [:error] [pid 31356:tid 140534104217344] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/FWAZ.php"] [unique_id "amjJAMz37IgzFQUBXwTtPAAAAMU"]
[Tue Jul 28 17:21:36.511838 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/qterm.php"] [unique_id "amjJAMbo_8Uj3iOaYH7s2QAAAQY"]
[Tue Jul 28 17:21:36.512695 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/qterm.php"] [unique_id "amjJAMbo_8Uj3iOaYH7s2QAAAQY"]
[Tue Jul 28 17:21:36.513070 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/qterm.php"] [unique_id "amjJAMbo_8Uj3iOaYH7s2QAAAQY"]
[Tue Jul 28 17:21:36.513173 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/qterm.php"] [unique_id "amjJAMbo_8Uj3iOaYH7s2QAAAQY"]
[Tue Jul 28 17:21:36.728283 2026] [:error] [pid 31356:tid 140533955528448] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/blurbs.php"] [unique_id "amjJAMz37IgzFQUBXwTtPQAAAM4"]
[Tue Jul 28 17:21:36.729277 2026] [:error] [pid 31356:tid 140533955528448] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/blurbs.php"] [unique_id "amjJAMz37IgzFQUBXwTtPQAAAM4"]
[Tue Jul 28 17:21:36.729760 2026] [:error] [pid 31356:tid 140533955528448] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/blurbs.php"] [unique_id "amjJAMz37IgzFQUBXwTtPQAAAM4"]
[Tue Jul 28 17:21:36.729824 2026] [:error] [pid 31356:tid 140533955528448] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/blurbs.php"] [unique_id "amjJAMz37IgzFQUBXwTtPQAAAM4"]
[Tue Jul 28 17:21:36.951321 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/v543.php"] [unique_id "amjJAMbo_8Uj3iOaYH7s2gAAAQU"]
[Tue Jul 28 17:21:36.952358 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/v543.php"] [unique_id "amjJAMbo_8Uj3iOaYH7s2gAAAQU"]
[Tue Jul 28 17:21:36.952914 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/v543.php"] [unique_id "amjJAMbo_8Uj3iOaYH7s2gAAAQU"]
[Tue Jul 28 17:21:36.953024 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/v543.php"] [unique_id "amjJAMbo_8Uj3iOaYH7s2gAAAQU"]
[Tue Jul 28 17:21:37.177342 2026] [:error] [pid 31356:tid 140533930350336] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/w3lls.php"] [unique_id "amjJAcz37IgzFQUBXwTtPwAAANE"]
[Tue Jul 28 17:21:37.178343 2026] [:error] [pid 31356:tid 140533930350336] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/w3lls.php"] [unique_id "amjJAcz37IgzFQUBXwTtPwAAANE"]
[Tue Jul 28 17:21:37.178793 2026] [:error] [pid 31356:tid 140533930350336] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/w3lls.php"] [unique_id "amjJAcz37IgzFQUBXwTtPwAAANE"]
[Tue Jul 28 17:21:37.178877 2026] [:error] [pid 31356:tid 140533930350336] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/w3lls.php"] [unique_id "amjJAcz37IgzFQUBXwTtPwAAANE"]
[Tue Jul 28 17:21:37.396691 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-ws68.php"] [unique_id "amjJAcbo_8Uj3iOaYH7s2wAAAQE"]
[Tue Jul 28 17:21:37.397481 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-ws68.php"] [unique_id "amjJAcbo_8Uj3iOaYH7s2wAAAQE"]
[Tue Jul 28 17:21:37.397762 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-ws68.php"] [unique_id "amjJAcbo_8Uj3iOaYH7s2wAAAQE"]
[Tue Jul 28 17:21:37.397838 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-ws68.php"] [unique_id "amjJAcbo_8Uj3iOaYH7s2wAAAQE"]
[Tue Jul 28 17:21:37.612369 2026] [:error] [pid 31356:tid 140533938743040] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xyn.php"] [unique_id "amjJAcz37IgzFQUBXwTtQAAAANA"]
[Tue Jul 28 17:21:37.613264 2026] [:error] [pid 31356:tid 140533938743040] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xyn.php"] [unique_id "amjJAcz37IgzFQUBXwTtQAAAANA"]
[Tue Jul 28 17:21:37.613724 2026] [:error] [pid 31356:tid 140533938743040] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/xyn.php"] [unique_id "amjJAcz37IgzFQUBXwTtQAAAANA"]
[Tue Jul 28 17:21:37.613854 2026] [:error] [pid 31356:tid 140533938743040] [client 172.69.114.29:11742] [client 172.69.114.29] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xyn.php"] [unique_id "amjJAcz37IgzFQUBXwTtQAAAANA"]
[Tue Jul 28 17:21:37.838149 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/green3.php"] [unique_id "amjJAcbo_8Uj3iOaYH7s3AAAAQ0"]
[Tue Jul 28 17:21:37.839191 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/green3.php"] [unique_id "amjJAcbo_8Uj3iOaYH7s3AAAAQ0"]
[Tue Jul 28 17:21:37.839641 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/green3.php"] [unique_id "amjJAcbo_8Uj3iOaYH7s3AAAAQ0"]
[Tue Jul 28 17:21:37.839759 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/green3.php"] [unique_id "amjJAcbo_8Uj3iOaYH7s3AAAAQ0"]
[Tue Jul 28 17:21:38.075671 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ccc.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s3gAAARM"]
[Tue Jul 28 17:21:38.076406 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ccc.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s3gAAARM"]
[Tue Jul 28 17:21:38.076785 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ccc.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s3gAAARM"]
[Tue Jul 28 17:21:38.076861 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ccc.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s3gAAARM"]
[Tue Jul 28 17:21:38.387216 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/get.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s4AAAAQM"]
[Tue Jul 28 17:21:38.388231 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/get.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s4AAAAQM"]
[Tue Jul 28 17:21:38.388676 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/get.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s4AAAAQM"]
[Tue Jul 28 17:21:38.388765 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/get.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s4AAAAQM"]
[Tue Jul 28 17:21:38.605591 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/images.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s4QAAARQ"]
[Tue Jul 28 17:21:38.606261 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/images.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s4QAAARQ"]
[Tue Jul 28 17:21:38.606652 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/images.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s4QAAARQ"]
[Tue Jul 28 17:21:38.606733 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/images.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s4QAAARQ"]
[Tue Jul 28 17:21:38.822081 2026] [:error] [pid 31471:tid 140533997491968] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/alls.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s4gAAAQk"]
[Tue Jul 28 17:21:38.822791 2026] [:error] [pid 31471:tid 140533997491968] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/alls.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s4gAAAQk"]
[Tue Jul 28 17:21:38.823087 2026] [:error] [pid 31471:tid 140533997491968] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/alls.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s4gAAAQk"]
[Tue Jul 28 17:21:38.823146 2026] [:error] [pid 31471:tid 140533997491968] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/alls.php"] [unique_id "amjJAsbo_8Uj3iOaYH7s4gAAAQk"]
[Tue Jul 28 17:21:39.040743 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/coffexium.php"] [unique_id "amjJA8bo_8Uj3iOaYH7s4wAAARg"]
[Tue Jul 28 17:21:39.041638 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/coffexium.php"] [unique_id "amjJA8bo_8Uj3iOaYH7s4wAAARg"]
[Tue Jul 28 17:21:39.042039 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/coffexium.php"] [unique_id "amjJA8bo_8Uj3iOaYH7s4wAAARg"]
[Tue Jul 28 17:21:39.042152 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/coffexium.php"] [unique_id "amjJA8bo_8Uj3iOaYH7s4wAAARg"]
[Tue Jul 28 17:21:39.262304 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/red.php"] [unique_id "amjJA8bo_8Uj3iOaYH7s5AAAARA"]
[Tue Jul 28 17:21:39.262981 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/red.php"] [unique_id "amjJA8bo_8Uj3iOaYH7s5AAAARA"]
[Tue Jul 28 17:21:39.263282 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/red.php"] [unique_id "amjJA8bo_8Uj3iOaYH7s5AAAARA"]
[Tue Jul 28 17:21:39.263362 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/red.php"] [unique_id "amjJA8bo_8Uj3iOaYH7s5AAAARA"]
[Tue Jul 28 17:21:39.486981 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "amjJA8bo_8Uj3iOaYH7s5QAAAQo"]
[Tue Jul 28 17:21:39.487778 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "amjJA8bo_8Uj3iOaYH7s5QAAAQo"]
[Tue Jul 28 17:21:39.488141 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "amjJA8bo_8Uj3iOaYH7s5QAAAQo"]
[Tue Jul 28 17:21:39.488196 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "amjJA8bo_8Uj3iOaYH7s5QAAAQo"]
[Tue Jul 28 17:21:39.740148 2026] [:error] [pid 31471:tid 140534129395456] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amjJA8bo_8Uj3iOaYH7s5gAAAQI"]
[Tue Jul 28 17:21:39.740798 2026] [:error] [pid 31471:tid 140534129395456] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amjJA8bo_8Uj3iOaYH7s5gAAAQI"]
[Tue Jul 28 17:21:39.741080 2026] [:error] [pid 31471:tid 140534129395456] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amjJA8bo_8Uj3iOaYH7s5gAAAQI"]
[Tue Jul 28 17:21:39.741144 2026] [:error] [pid 31471:tid 140534129395456] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amjJA8bo_8Uj3iOaYH7s5gAAAQI"]
[Tue Jul 28 17:21:39.956174 2026] [:error] [pid 31471:tid 140534112610048] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/Text/"] [unique_id "amjJA8bo_8Uj3iOaYH7s5wAAAQQ"]
[Tue Jul 28 17:21:39.957016 2026] [:error] [pid 31471:tid 140534112610048] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/Text/"] [unique_id "amjJA8bo_8Uj3iOaYH7s5wAAAQQ"]
[Tue Jul 28 17:21:39.957387 2026] [:error] [pid 31471:tid 140534112610048] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/Text/"] [unique_id "amjJA8bo_8Uj3iOaYH7s5wAAAQQ"]
[Tue Jul 28 17:21:39.957503 2026] [:error] [pid 31471:tid 140534112610048] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/Text/"] [unique_id "amjJA8bo_8Uj3iOaYH7s5wAAAQQ"]
[Tue Jul 28 17:21:40.174985 2026] [:error] [pid 31471:tid 140534014277376] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/uploads/"] [unique_id "amjJBMbo_8Uj3iOaYH7s6AAAAQc"]
[Tue Jul 28 17:21:40.175744 2026] [:error] [pid 31471:tid 140534014277376] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/uploads/"] [unique_id "amjJBMbo_8Uj3iOaYH7s6AAAAQc"]
[Tue Jul 28 17:21:40.176083 2026] [:error] [pid 31471:tid 140534014277376] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/uploads/"] [unique_id "amjJBMbo_8Uj3iOaYH7s6AAAAQc"]
[Tue Jul 28 17:21:40.176165 2026] [:error] [pid 31471:tid 140534014277376] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-content/uploads/"] [unique_id "amjJBMbo_8Uj3iOaYH7s6AAAAQc"]
[Tue Jul 28 17:21:40.402930 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/index.php"] [unique_id "amjJBMbo_8Uj3iOaYH7s6gAAAQg"]
[Tue Jul 28 17:21:40.403749 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/index.php"] [unique_id "amjJBMbo_8Uj3iOaYH7s6gAAAQg"]
[Tue Jul 28 17:21:40.404058 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/index.php"] [unique_id "amjJBMbo_8Uj3iOaYH7s6gAAAQg"]
[Tue Jul 28 17:21:40.404141 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-content/index.php"] [unique_id "amjJBMbo_8Uj3iOaYH7s6gAAAQg"]
[Tue Jul 28 17:21:40.619765 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amjJBMbo_8Uj3iOaYH7s6wAAAQY"]
[Tue Jul 28 17:21:40.620146 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amjJBMbo_8Uj3iOaYH7s6wAAAQY"]
[Tue Jul 28 17:21:40.620400 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amjJBMbo_8Uj3iOaYH7s6wAAAQY"]
[Tue Jul 28 17:21:40.620480 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amjJBMbo_8Uj3iOaYH7s6wAAAQY"]
[Tue Jul 28 17:21:40.835363 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/177.php"] [unique_id "amjJBMbo_8Uj3iOaYH7s7QAAARM"]
[Tue Jul 28 17:21:40.836032 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/177.php"] [unique_id "amjJBMbo_8Uj3iOaYH7s7QAAARM"]
[Tue Jul 28 17:21:40.836286 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/177.php"] [unique_id "amjJBMbo_8Uj3iOaYH7s7QAAARM"]
[Tue Jul 28 17:21:40.836337 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/177.php"] [unique_id "amjJBMbo_8Uj3iOaYH7s7QAAARM"]
[Tue Jul 28 17:21:41.051875 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/199.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s7gAAAQ4"]
[Tue Jul 28 17:21:41.052738 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/199.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s7gAAAQ4"]
[Tue Jul 28 17:21:41.053097 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/199.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s7gAAAQ4"]
[Tue Jul 28 17:21:41.053182 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/199.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s7gAAAQ4"]
[Tue Jul 28 17:21:41.268606 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file52.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s7wAAARA"]
[Tue Jul 28 17:21:41.269253 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file52.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s7wAAARA"]
[Tue Jul 28 17:21:41.269630 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file52.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s7wAAARA"]
[Tue Jul 28 17:21:41.269698 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file52.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s7wAAARA"]
[Tue Jul 28 17:21:41.486404 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/geck.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s8AAAAQw"]
[Tue Jul 28 17:21:41.487232 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/geck.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s8AAAAQw"]
[Tue Jul 28 17:21:41.487639 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/geck.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s8AAAAQw"]
[Tue Jul 28 17:21:41.487742 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/geck.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s8AAAAQw"]
[Tue Jul 28 17:21:41.705989 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/biufile.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s8gAAARY"]
[Tue Jul 28 17:21:41.707048 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/biufile.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s8gAAARY"]
[Tue Jul 28 17:21:41.707491 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/biufile.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s8gAAARY"]
[Tue Jul 28 17:21:41.707605 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/biufile.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s8gAAARY"]
[Tue Jul 28 17:21:41.925590 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mosty.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s8wAAAQo"]
[Tue Jul 28 17:21:41.926426 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mosty.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s8wAAAQo"]
[Tue Jul 28 17:21:41.926816 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/mosty.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s8wAAAQo"]
[Tue Jul 28 17:21:41.926925 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mosty.php"] [unique_id "amjJBcbo_8Uj3iOaYH7s8wAAAQo"]
[Tue Jul 28 17:21:42.143575 2026] [:error] [pid 31471:tid 140534129395456] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dejavu.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s9AAAAQI"]
[Tue Jul 28 17:21:42.144390 2026] [:error] [pid 31471:tid 140534129395456] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dejavu.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s9AAAAQI"]
[Tue Jul 28 17:21:42.144752 2026] [:error] [pid 31471:tid 140534129395456] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/dejavu.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s9AAAAQI"]
[Tue Jul 28 17:21:42.144813 2026] [:error] [pid 31471:tid 140534129395456] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dejavu.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s9AAAAQI"]
[Tue Jul 28 17:21:42.359693 2026] [:error] [pid 31471:tid 140534112610048] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aaf.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s9QAAAQQ"]
[Tue Jul 28 17:21:42.360317 2026] [:error] [pid 31471:tid 140534112610048] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aaf.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s9QAAAQQ"]
[Tue Jul 28 17:21:42.360644 2026] [:error] [pid 31471:tid 140534112610048] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/aaf.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s9QAAAQQ"]
[Tue Jul 28 17:21:42.360724 2026] [:error] [pid 31471:tid 140534112610048] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/aaf.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s9QAAAQQ"]
[Tue Jul 28 17:21:42.576510 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ha.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s-gAAAQE"]
[Tue Jul 28 17:21:42.577137 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ha.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s-gAAAQE"]
[Tue Jul 28 17:21:42.577444 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ha.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s-gAAAQE"]
[Tue Jul 28 17:21:42.577524 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ha.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s-gAAAQE"]
[Tue Jul 28 17:21:42.792599 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/hur.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s_QAAARQ"]
[Tue Jul 28 17:21:42.793112 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/hur.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s_QAAARQ"]
[Tue Jul 28 17:21:42.793343 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/hur.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s_QAAARQ"]
[Tue Jul 28 17:21:42.793392 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/hur.php"] [unique_id "amjJBsbo_8Uj3iOaYH7s_QAAARQ"]
[Tue Jul 28 17:21:43.018517 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/h02ugyh.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tAQAAARI"]
[Tue Jul 28 17:21:43.018906 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/h02ugyh.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tAQAAARI"]
[Tue Jul 28 17:21:43.019114 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/h02ugyh.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tAQAAARI"]
[Tue Jul 28 17:21:43.019160 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/h02ugyh.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tAQAAARI"]
[Tue Jul 28 17:21:43.233920 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/155.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tBgAAAQo"]
[Tue Jul 28 17:21:43.234708 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/155.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tBgAAAQo"]
[Tue Jul 28 17:21:43.235058 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/155.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tBgAAAQo"]
[Tue Jul 28 17:21:43.235140 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/155.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tBgAAAQo"]
[Tue Jul 28 17:21:43.465536 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/pp.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tBwAAARg"]
[Tue Jul 28 17:21:43.466314 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/pp.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tBwAAARg"]
[Tue Jul 28 17:21:43.466779 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/pp.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tBwAAARg"]
[Tue Jul 28 17:21:43.466872 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/pp.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tBwAAARg"]
[Tue Jul 28 17:21:43.682116 2026] [:error] [pid 31471:tid 140534146180864] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ops.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tDAAAAQA"]
[Tue Jul 28 17:21:43.683014 2026] [:error] [pid 31471:tid 140534146180864] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ops.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tDAAAAQA"]
[Tue Jul 28 17:21:43.683804 2026] [:error] [pid 31471:tid 140534146180864] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ops.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tDAAAAQA"]
[Tue Jul 28 17:21:43.683943 2026] [:error] [pid 31471:tid 140534146180864] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ops.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tDAAAAQA"]
[Tue Jul 28 17:21:43.901666 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ingfo.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tEQAAAQ0"]
[Tue Jul 28 17:21:43.902302 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ingfo.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tEQAAAQ0"]
[Tue Jul 28 17:21:43.902701 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ingfo.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tEQAAAQ0"]
[Tue Jul 28 17:21:43.902810 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ingfo.php"] [unique_id "amjJB8bo_8Uj3iOaYH7tEQAAAQ0"]
[Tue Jul 28 17:21:44.118153 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/error_log.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tEwAAAQM"]
[Tue Jul 28 17:21:44.118972 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/error_log.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tEwAAAQM"]
[Tue Jul 28 17:21:44.119355 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/error_log.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tEwAAAQM"]
[Tue Jul 28 17:21:44.119453 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/error_log.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tEwAAAQM"]
[Tue Jul 28 17:21:44.338803 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/koala.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tGgAAARc"]
[Tue Jul 28 17:21:44.339422 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/koala.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tGgAAARc"]
[Tue Jul 28 17:21:44.339721 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/koala.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tGgAAARc"]
[Tue Jul 28 17:21:44.339800 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/koala.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tGgAAARc"]
[Tue Jul 28 17:21:44.556967 2026] [:error] [pid 31471:tid 140534129395456] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mac.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tIAAAAQI"]
[Tue Jul 28 17:21:44.557794 2026] [:error] [pid 31471:tid 140534129395456] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mac.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tIAAAAQI"]
[Tue Jul 28 17:21:44.558149 2026] [:error] [pid 31471:tid 140534129395456] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/mac.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tIAAAAQI"]
[Tue Jul 28 17:21:44.558213 2026] [:error] [pid 31471:tid 140534129395456] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mac.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tIAAAAQI"]
[Tue Jul 28 17:21:44.784366 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wefile.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tIgAAAQg"]
[Tue Jul 28 17:21:44.784831 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wefile.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tIgAAAQg"]
[Tue Jul 28 17:21:44.785064 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wefile.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tIgAAAQg"]
[Tue Jul 28 17:21:44.785129 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wefile.php"] [unique_id "amjJCMbo_8Uj3iOaYH7tIgAAAQg"]
[Tue Jul 28 17:21:44.999242 2026] [:error] [pid 31471:tid 140534146180864] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "amjJCMbo_8Uj3iOaYH7tIwAAAQA"]
[Tue Jul 28 17:21:44.999745 2026] [:error] [pid 31471:tid 140534146180864] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "amjJCMbo_8Uj3iOaYH7tIwAAAQA"]
[Tue Jul 28 17:21:44.999969 2026] [:error] [pid 31471:tid 140534146180864] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "amjJCMbo_8Uj3iOaYH7tIwAAAQA"]
[Tue Jul 28 17:21:45.000018 2026] [:error] [pid 31471:tid 140534146180864] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "amjJCMbo_8Uj3iOaYH7tIwAAAQA"]
[Tue Jul 28 17:21:45.220009 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/js/"] [unique_id "amjJCcbo_8Uj3iOaYH7tJAAAAQY"]
[Tue Jul 28 17:21:45.220808 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/js/"] [unique_id "amjJCcbo_8Uj3iOaYH7tJAAAAQY"]
[Tue Jul 28 17:21:45.221218 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/js/"] [unique_id "amjJCcbo_8Uj3iOaYH7tJAAAAQY"]
[Tue Jul 28 17:21:45.221352 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/js/"] [unique_id "amjJCcbo_8Uj3iOaYH7tJAAAAQY"]
[Tue Jul 28 17:21:45.438517 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/makeasmtp.php"] [unique_id "amjJCcbo_8Uj3iOaYH7tJwAAAQE"]
[Tue Jul 28 17:21:45.439311 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/makeasmtp.php"] [unique_id "amjJCcbo_8Uj3iOaYH7tJwAAAQE"]
[Tue Jul 28 17:21:45.439731 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/makeasmtp.php"] [unique_id "amjJCcbo_8Uj3iOaYH7tJwAAAQE"]
[Tue Jul 28 17:21:45.439826 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/makeasmtp.php"] [unique_id "amjJCcbo_8Uj3iOaYH7tJwAAAQE"]
[Tue Jul 28 17:21:45.658536 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/2P.php"] [unique_id "amjJCcbo_8Uj3iOaYH7tKQAAARM"]
[Tue Jul 28 17:21:45.659094 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/2P.php"] [unique_id "amjJCcbo_8Uj3iOaYH7tKQAAARM"]
[Tue Jul 28 17:21:45.659417 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/2P.php"] [unique_id "amjJCcbo_8Uj3iOaYH7tKQAAARM"]
[Tue Jul 28 17:21:45.659506 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/2P.php"] [unique_id "amjJCcbo_8Uj3iOaYH7tKQAAARM"]
[Tue Jul 28 17:21:45.875646 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/about.php"] [unique_id "amjJCcbo_8Uj3iOaYH7tLQAAARI"]
[Tue Jul 28 17:21:45.876200 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/about.php"] [unique_id "amjJCcbo_8Uj3iOaYH7tLQAAARI"]
[Tue Jul 28 17:21:45.876453 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.well-known/about.php"] [unique_id "amjJCcbo_8Uj3iOaYH7tLQAAARI"]
[Tue Jul 28 17:21:45.876530 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/about.php"] [unique_id "amjJCcbo_8Uj3iOaYH7tLQAAARI"]
[Tue Jul 28 17:21:46.092942 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amjJCsbo_8Uj3iOaYH7tMgAAAQw"]
[Tue Jul 28 17:21:46.093717 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amjJCsbo_8Uj3iOaYH7tMgAAAQw"]
[Tue Jul 28 17:21:46.094030 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amjJCsbo_8Uj3iOaYH7tMgAAAQw"]
[Tue Jul 28 17:21:46.094088 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amjJCsbo_8Uj3iOaYH7tMgAAAQw"]
[Tue Jul 28 17:21:46.309966 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/system_log.php"] [unique_id "amjJCsbo_8Uj3iOaYH7tNQAAARg"]
[Tue Jul 28 17:21:46.310519 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/system_log.php"] [unique_id "amjJCsbo_8Uj3iOaYH7tNQAAARg"]
[Tue Jul 28 17:21:46.310766 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/system_log.php"] [unique_id "amjJCsbo_8Uj3iOaYH7tNQAAARg"]
[Tue Jul 28 17:21:46.310829 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/system_log.php"] [unique_id "amjJCsbo_8Uj3iOaYH7tNQAAARg"]
[Tue Jul 28 17:21:46.526955 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/"] [unique_id "amjJCsbo_8Uj3iOaYH7tOQAAAQg"]
[Tue Jul 28 17:21:46.527730 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/"] [unique_id "amjJCsbo_8Uj3iOaYH7tOQAAAQg"]
[Tue Jul 28 17:21:46.528069 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/"] [unique_id "amjJCsbo_8Uj3iOaYH7tOQAAAQg"]
[Tue Jul 28 17:21:46.528144 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/"] [unique_id "amjJCsbo_8Uj3iOaYH7tOQAAAQg"]
[Tue Jul 28 17:21:46.742755 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "amjJCsbo_8Uj3iOaYH7tPAAAAQU"]
[Tue Jul 28 17:21:46.743462 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "amjJCsbo_8Uj3iOaYH7tPAAAAQU"]
[Tue Jul 28 17:21:46.743927 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "amjJCsbo_8Uj3iOaYH7tPAAAAQU"]
[Tue Jul 28 17:21:46.744037 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "amjJCsbo_8Uj3iOaYH7tPAAAAQU"]
[Tue Jul 28 17:21:46.958229 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/crgio.php"] [unique_id "amjJCsbo_8Uj3iOaYH7tPwAAAQ0"]
[Tue Jul 28 17:21:46.959168 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/crgio.php"] [unique_id "amjJCsbo_8Uj3iOaYH7tPwAAAQ0"]
[Tue Jul 28 17:21:46.959631 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/crgio.php"] [unique_id "amjJCsbo_8Uj3iOaYH7tPwAAAQ0"]
[Tue Jul 28 17:21:46.959727 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/crgio.php"] [unique_id "amjJCsbo_8Uj3iOaYH7tPwAAAQ0"]
[Tue Jul 28 17:21:47.180596 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/pucci.php"] [unique_id "amjJC8bo_8Uj3iOaYH7tQAAAAQM"]
[Tue Jul 28 17:21:47.181488 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/pucci.php"] [unique_id "amjJC8bo_8Uj3iOaYH7tQAAAAQM"]
[Tue Jul 28 17:21:47.181932 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/pucci.php"] [unique_id "amjJC8bo_8Uj3iOaYH7tQAAAAQM"]
[Tue Jul 28 17:21:47.182048 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/pucci.php"] [unique_id "amjJC8bo_8Uj3iOaYH7tQAAAAQM"]
[Tue Jul 28 17:21:47.398590 2026] [:error] [pid 31471:tid 140533947135744] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/details/"] [unique_id "amjJC8bo_8Uj3iOaYH7tQwAAAQ8"]
[Tue Jul 28 17:21:47.399182 2026] [:error] [pid 31471:tid 140533947135744] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/details/"] [unique_id "amjJC8bo_8Uj3iOaYH7tQwAAAQ8"]
[Tue Jul 28 17:21:47.399448 2026] [:error] [pid 31471:tid 140533947135744] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/details/"] [unique_id "amjJC8bo_8Uj3iOaYH7tQwAAAQ8"]
[Tue Jul 28 17:21:47.399515 2026] [:error] [pid 31471:tid 140533947135744] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/details/"] [unique_id "amjJC8bo_8Uj3iOaYH7tQwAAAQ8"]
[Tue Jul 28 17:21:47.615967 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "amjJC8bo_8Uj3iOaYH7tRAAAARI"]
[Tue Jul 28 17:21:47.617094 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "amjJC8bo_8Uj3iOaYH7tRAAAARI"]
[Tue Jul 28 17:21:47.617666 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "amjJC8bo_8Uj3iOaYH7tRAAAARI"]
[Tue Jul 28 17:21:47.617765 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "amjJC8bo_8Uj3iOaYH7tRAAAARI"]
[Tue Jul 28 17:21:47.833314 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-temp.php"] [unique_id "amjJC8bo_8Uj3iOaYH7tRQAAAQ4"]
[Tue Jul 28 17:21:47.834385 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-temp.php"] [unique_id "amjJC8bo_8Uj3iOaYH7tRQAAAQ4"]
[Tue Jul 28 17:21:47.834880 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-temp.php"] [unique_id "amjJC8bo_8Uj3iOaYH7tRQAAAQ4"]
[Tue Jul 28 17:21:47.834976 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-temp.php"] [unique_id "amjJC8bo_8Uj3iOaYH7tRQAAAQ4"]
[Tue Jul 28 17:21:48.057567 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/js/index.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tSQAAAQw"]
[Tue Jul 28 17:21:48.058370 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/js/index.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tSQAAAQw"]
[Tue Jul 28 17:21:48.058801 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/js/index.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tSQAAAQw"]
[Tue Jul 28 17:21:48.058911 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/js/index.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tSQAAAQw"]
[Tue Jul 28 17:21:48.274709 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/puc.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tSgAAARY"]
[Tue Jul 28 17:21:48.275589 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/puc.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tSgAAARY"]
[Tue Jul 28 17:21:48.275997 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/puc.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tSgAAARY"]
[Tue Jul 28 17:21:48.276085 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/puc.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tSgAAARY"]
[Tue Jul 28 17:21:48.493016 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dx.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tSwAAAQo"]
[Tue Jul 28 17:21:48.493875 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dx.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tSwAAAQo"]
[Tue Jul 28 17:21:48.494258 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/dx.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tSwAAAQo"]
[Tue Jul 28 17:21:48.494343 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dx.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tSwAAAQo"]
[Tue Jul 28 17:21:48.710124 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/Requests/"] [unique_id "amjJDMbo_8Uj3iOaYH7tUgAAAQU"]
[Tue Jul 28 17:21:48.711597 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/Requests/"] [unique_id "amjJDMbo_8Uj3iOaYH7tUgAAAQU"]
[Tue Jul 28 17:21:48.711951 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/Requests/"] [unique_id "amjJDMbo_8Uj3iOaYH7tUgAAAQU"]
[Tue Jul 28 17:21:48.712021 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/Requests/"] [unique_id "amjJDMbo_8Uj3iOaYH7tUgAAAQU"]
[Tue Jul 28 17:21:48.927651 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/7.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tVAAAAQM"]
[Tue Jul 28 17:21:48.928092 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/7.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tVAAAAQM"]
[Tue Jul 28 17:21:48.928310 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/7.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tVAAAAQM"]
[Tue Jul 28 17:21:48.928362 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/7.php"] [unique_id "amjJDMbo_8Uj3iOaYH7tVAAAAQM"]
[Tue Jul 28 17:21:49.143282 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/8.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tVwAAARQ"]
[Tue Jul 28 17:21:49.144130 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/8.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tVwAAARQ"]
[Tue Jul 28 17:21:49.144530 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/8.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tVwAAARQ"]
[Tue Jul 28 17:21:49.144641 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/8.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tVwAAARQ"]
[Tue Jul 28 17:21:49.361659 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/1.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tWQAAARI"]
[Tue Jul 28 17:21:49.374293 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/1.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tWQAAARI"]
[Tue Jul 28 17:21:49.374929 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/1.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tWQAAARI"]
[Tue Jul 28 17:21:49.375036 2026] [:error] [pid 31471:tid 140533921957632] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/1.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tWQAAARI"]
[Tue Jul 28 17:21:49.590287 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/about.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tXgAAARc"]
[Tue Jul 28 17:21:49.591160 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/about.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tXgAAARc"]
[Tue Jul 28 17:21:49.591589 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/about.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tXgAAARc"]
[Tue Jul 28 17:21:49.591711 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/about.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tXgAAARc"]
[Tue Jul 28 17:21:49.830543 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tXwAAARA"]
[Tue Jul 28 17:21:49.831337 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tXwAAARA"]
[Tue Jul 28 17:21:49.831739 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tXwAAARA"]
[Tue Jul 28 17:21:49.831821 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amjJDcbo_8Uj3iOaYH7tXwAAARA"]
[Tue Jul 28 17:21:50.046191 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/edit.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tYgAAARg"]
[Tue Jul 28 17:21:50.047075 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/edit.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tYgAAARg"]
[Tue Jul 28 17:21:50.047419 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/edit.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tYgAAARg"]
[Tue Jul 28 17:21:50.047572 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/edit.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tYgAAARg"]
[Tue Jul 28 17:21:50.266527 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/admin.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tZQAAAQY"]
[Tue Jul 28 17:21:50.267289 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/admin.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tZQAAAQY"]
[Tue Jul 28 17:21:50.267658 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/admin.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tZQAAAQY"]
[Tue Jul 28 17:21:50.267730 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-content/admin.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tZQAAAQY"]
[Tue Jul 28 17:21:50.487380 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/inputs.php"] [unique_id "amjJDsbo_8Uj3iOaYH7taQAAAQU"]
[Tue Jul 28 17:21:50.488308 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/inputs.php"] [unique_id "amjJDsbo_8Uj3iOaYH7taQAAAQU"]
[Tue Jul 28 17:21:50.488747 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/inputs.php"] [unique_id "amjJDsbo_8Uj3iOaYH7taQAAAQU"]
[Tue Jul 28 17:21:50.488859 2026] [:error] [pid 31471:tid 140534104217344] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/inputs.php"] [unique_id "amjJDsbo_8Uj3iOaYH7taQAAAQU"]
[Tue Jul 28 17:21:50.703513 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/av.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tagAAAQE"]
[Tue Jul 28 17:21:50.704318 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/av.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tagAAAQE"]
[Tue Jul 28 17:21:50.704969 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/av.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tagAAAQE"]
[Tue Jul 28 17:21:50.705079 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/av.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tagAAAQE"]
[Tue Jul 28 17:21:50.920272 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/classwithtostring.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tawAAAQM"]
[Tue Jul 28 17:21:50.921121 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/classwithtostring.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tawAAAQM"]
[Tue Jul 28 17:21:50.921513 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/classwithtostring.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tawAAAQM"]
[Tue Jul 28 17:21:50.921620 2026] [:error] [pid 31471:tid 140534121002752] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/classwithtostring.php"] [unique_id "amjJDsbo_8Uj3iOaYH7tawAAAQM"]
[Tue Jul 28 17:21:51.139629 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/themes/index.php"] [unique_id "amjJD8bo_8Uj3iOaYH7tbQAAARQ"]
[Tue Jul 28 17:21:51.140454 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/themes/index.php"] [unique_id "amjJD8bo_8Uj3iOaYH7tbQAAARQ"]
[Tue Jul 28 17:21:51.140885 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/themes/index.php"] [unique_id "amjJD8bo_8Uj3iOaYH7tbQAAARQ"]
[Tue Jul 28 17:21:51.140972 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-content/themes/index.php"] [unique_id "amjJD8bo_8Uj3iOaYH7tbQAAARQ"]
[Tue Jul 28 17:21:51.356172 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-blog.php"] [unique_id "amjJD8bo_8Uj3iOaYH7tegAAAQY"]
[Tue Jul 28 17:21:51.357232 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-blog.php"] [unique_id "amjJD8bo_8Uj3iOaYH7tegAAAQY"]
[Tue Jul 28 17:21:51.357741 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-blog.php"] [unique_id "amjJD8bo_8Uj3iOaYH7tegAAAQY"]
[Tue Jul 28 17:21:51.357896 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-blog.php"] [unique_id "amjJD8bo_8Uj3iOaYH7tegAAAQY"]
[Tue Jul 28 17:21:51.572692 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/js/jquery/"] [unique_id "amjJD8bo_8Uj3iOaYH7tfwAAAQE"]
[Tue Jul 28 17:21:51.573532 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/js/jquery/"] [unique_id "amjJD8bo_8Uj3iOaYH7tfwAAAQE"]
[Tue Jul 28 17:21:51.573926 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/js/jquery/"] [unique_id "amjJD8bo_8Uj3iOaYH7tfwAAAQE"]
[Tue Jul 28 17:21:51.574012 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/js/jquery/"] [unique_id "amjJD8bo_8Uj3iOaYH7tfwAAAQE"]
[Tue Jul 28 17:21:51.793047 2026] [:error] [pid 31471:tid 140533947135744] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/admin.php"] [unique_id "amjJD8bo_8Uj3iOaYH7tgAAAAQ8"]
[Tue Jul 28 17:21:51.793925 2026] [:error] [pid 31471:tid 140533947135744] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/admin.php"] [unique_id "amjJD8bo_8Uj3iOaYH7tgAAAAQ8"]
[Tue Jul 28 17:21:51.794316 2026] [:error] [pid 31471:tid 140533947135744] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/admin.php"] [unique_id "amjJD8bo_8Uj3iOaYH7tgAAAAQ8"]
[Tue Jul 28 17:21:51.794392 2026] [:error] [pid 31471:tid 140533947135744] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-content/admin.php"] [unique_id "amjJD8bo_8Uj3iOaYH7tgAAAAQ8"]
[Tue Jul 28 17:21:52.021439 2026] [:error] [pid 31471:tid 140533997491968] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/adminfuns.php"] [unique_id "amjJEMbo_8Uj3iOaYH7tggAAAQk"]
[Tue Jul 28 17:21:52.022220 2026] [:error] [pid 31471:tid 140533997491968] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/adminfuns.php"] [unique_id "amjJEMbo_8Uj3iOaYH7tggAAAQk"]
[Tue Jul 28 17:21:52.022605 2026] [:error] [pid 31471:tid 140533997491968] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/adminfuns.php"] [unique_id "amjJEMbo_8Uj3iOaYH7tggAAAQk"]
[Tue Jul 28 17:21:52.022712 2026] [:error] [pid 31471:tid 140533997491968] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/adminfuns.php"] [unique_id "amjJEMbo_8Uj3iOaYH7tggAAAQk"]
[Tue Jul 28 17:21:52.246926 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/goods.php"] [unique_id "amjJEMbo_8Uj3iOaYH7tgwAAARQ"]
[Tue Jul 28 17:21:52.247603 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/goods.php"] [unique_id "amjJEMbo_8Uj3iOaYH7tgwAAARQ"]
[Tue Jul 28 17:21:52.247904 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/goods.php"] [unique_id "amjJEMbo_8Uj3iOaYH7tgwAAARQ"]
[Tue Jul 28 17:21:52.247960 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/goods.php"] [unique_id "amjJEMbo_8Uj3iOaYH7tgwAAARQ"]
[Tue Jul 28 17:21:52.464781 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ms-edit.php"] [unique_id "amjJEMbo_8Uj3iOaYH7thAAAAQ4"]
[Tue Jul 28 17:21:52.465760 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ms-edit.php"] [unique_id "amjJEMbo_8Uj3iOaYH7thAAAAQ4"]
[Tue Jul 28 17:21:52.466179 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ms-edit.php"] [unique_id "amjJEMbo_8Uj3iOaYH7thAAAAQ4"]
[Tue Jul 28 17:21:52.466265 2026] [:error] [pid 31471:tid 140533955528448] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ms-edit.php"] [unique_id "amjJEMbo_8Uj3iOaYH7thAAAAQ4"]
[Tue Jul 28 17:21:52.683832 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/222.php"] [unique_id "amjJEMbo_8Uj3iOaYH7thgAAARc"]
[Tue Jul 28 17:21:52.684513 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/222.php"] [unique_id "amjJEMbo_8Uj3iOaYH7thgAAARc"]
[Tue Jul 28 17:21:52.684899 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/222.php"] [unique_id "amjJEMbo_8Uj3iOaYH7thgAAARc"]
[Tue Jul 28 17:21:52.684958 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/222.php"] [unique_id "amjJEMbo_8Uj3iOaYH7thgAAARc"]
[Tue Jul 28 17:21:52.903796 2026] [:error] [pid 31471:tid 140533896779520] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cgi-bin/index.php"] [unique_id "amjJEMbo_8Uj3iOaYH7thwAAARU"]
[Tue Jul 28 17:21:52.904499 2026] [:error] [pid 31471:tid 140533896779520] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cgi-bin/index.php"] [unique_id "amjJEMbo_8Uj3iOaYH7thwAAARU"]
[Tue Jul 28 17:21:52.904888 2026] [:error] [pid 31471:tid 140533896779520] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/cgi-bin/index.php"] [unique_id "amjJEMbo_8Uj3iOaYH7thwAAARU"]
[Tue Jul 28 17:21:52.904988 2026] [:error] [pid 31471:tid 140533896779520] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cgi-bin/index.php"] [unique_id "amjJEMbo_8Uj3iOaYH7thwAAARU"]
[Tue Jul 28 17:21:53.128094 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css/dist/"] [unique_id "amjJEcbo_8Uj3iOaYH7tiAAAARA"]
[Tue Jul 28 17:21:53.128685 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css/dist/"] [unique_id "amjJEcbo_8Uj3iOaYH7tiAAAARA"]
[Tue Jul 28 17:21:53.128933 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css/dist/"] [unique_id "amjJEcbo_8Uj3iOaYH7tiAAAARA"]
[Tue Jul 28 17:21:53.129006 2026] [:error] [pid 31471:tid 140533938743040] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css/dist/"] [unique_id "amjJEcbo_8Uj3iOaYH7tiAAAARA"]
[Tue Jul 28 17:21:53.345178 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/BDKR28WP.php"] [unique_id "amjJEcbo_8Uj3iOaYH7tigAAAQw"]
[Tue Jul 28 17:21:53.346058 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/BDKR28WP.php"] [unique_id "amjJEcbo_8Uj3iOaYH7tigAAAQw"]
[Tue Jul 28 17:21:53.346402 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/BDKR28WP.php"] [unique_id "amjJEcbo_8Uj3iOaYH7tigAAAQw"]
[Tue Jul 28 17:21:53.346485 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/BDKR28WP.php"] [unique_id "amjJEcbo_8Uj3iOaYH7tigAAAQw"]
[Tue Jul 28 17:21:53.563809 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/"] [unique_id "amjJEcbo_8Uj3iOaYH7tjAAAAQ0"]
[Tue Jul 28 17:21:53.564499 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/"] [unique_id "amjJEcbo_8Uj3iOaYH7tjAAAAQ0"]
[Tue Jul 28 17:21:53.564863 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/"] [unique_id "amjJEcbo_8Uj3iOaYH7tjAAAAQ0"]
[Tue Jul 28 17:21:53.564923 2026] [:error] [pid 31471:tid 140533963921152] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/"] [unique_id "amjJEcbo_8Uj3iOaYH7tjAAAAQ0"]
[Tue Jul 28 17:21:53.782060 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/uploads/"] [unique_id "amjJEcbo_8Uj3iOaYH7tjQAAARg"]
[Tue Jul 28 17:21:53.782749 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/uploads/"] [unique_id "amjJEcbo_8Uj3iOaYH7tjQAAARg"]
[Tue Jul 28 17:21:53.783031 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/uploads/"] [unique_id "amjJEcbo_8Uj3iOaYH7tjQAAARg"]
[Tue Jul 28 17:21:53.783089 2026] [:error] [pid 31471:tid 140533871601408] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-content/uploads/"] [unique_id "amjJEcbo_8Uj3iOaYH7tjQAAARg"]
[Tue Jul 28 17:21:53.998984 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp.php"] [unique_id "amjJEcbo_8Uj3iOaYH7tjwAAAQg"]
[Tue Jul 28 17:21:53.999642 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp.php"] [unique_id "amjJEcbo_8Uj3iOaYH7tjwAAAQg"]
[Tue Jul 28 17:21:53.999926 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp.php"] [unique_id "amjJEcbo_8Uj3iOaYH7tjwAAAQg"]
[Tue Jul 28 17:21:53.999982 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp.php"] [unique_id "amjJEcbo_8Uj3iOaYH7tjwAAAQg"]
[Tue Jul 28 17:21:54.217726 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/abcd.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tkAAAAQY"]
[Tue Jul 28 17:21:54.218318 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/abcd.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tkAAAAQY"]
[Tue Jul 28 17:21:54.218617 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/abcd.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tkAAAAQY"]
[Tue Jul 28 17:21:54.218670 2026] [:error] [pid 31471:tid 140534095824640] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/abcd.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tkAAAAQY"]
[Tue Jul 28 17:21:54.434197 2026] [:error] [pid 31471:tid 140533930350336] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/a1.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tkQAAARE"]
[Tue Jul 28 17:21:54.434994 2026] [:error] [pid 31471:tid 140533930350336] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/a1.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tkQAAARE"]
[Tue Jul 28 17:21:54.435345 2026] [:error] [pid 31471:tid 140533930350336] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/a1.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tkQAAARE"]
[Tue Jul 28 17:21:54.435417 2026] [:error] [pid 31471:tid 140533930350336] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/a1.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tkQAAARE"]
[Tue Jul 28 17:21:54.654499 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tkwAAAQo"]
[Tue Jul 28 17:21:54.655427 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tkwAAAQo"]
[Tue Jul 28 17:21:54.655901 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tkwAAAQo"]
[Tue Jul 28 17:21:54.655998 2026] [:error] [pid 31471:tid 140533989099264] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tkwAAAQo"]
[Tue Jul 28 17:21:54.878753 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cgi-bin/admin.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tlAAAAQE"]
[Tue Jul 28 17:21:54.879392 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cgi-bin/admin.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tlAAAAQE"]
[Tue Jul 28 17:21:54.879743 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/cgi-bin/admin.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tlAAAAQE"]
[Tue Jul 28 17:21:54.879809 2026] [:error] [pid 31471:tid 140534137788160] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cgi-bin/admin.php"] [unique_id "amjJEsbo_8Uj3iOaYH7tlAAAAQE"]
[Tue Jul 28 17:21:55.097875 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/"] [unique_id "amjJE8bo_8Uj3iOaYH7tlQAAARM"]
[Tue Jul 28 17:21:55.098353 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/"] [unique_id "amjJE8bo_8Uj3iOaYH7tlQAAARM"]
[Tue Jul 28 17:21:55.098616 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/"] [unique_id "amjJE8bo_8Uj3iOaYH7tlQAAARM"]
[Tue Jul 28 17:21:55.098665 2026] [:error] [pid 31471:tid 140533913564928] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-content/"] [unique_id "amjJE8bo_8Uj3iOaYH7tlQAAARM"]
[Tue Jul 28 17:21:55.313363 2026] [:error] [pid 31471:tid 140534112610048] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/simple.php"] [unique_id "amjJE8bo_8Uj3iOaYH7tlwAAAQQ"]
[Tue Jul 28 17:21:55.314172 2026] [:error] [pid 31471:tid 140534112610048] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/simple.php"] [unique_id "amjJE8bo_8Uj3iOaYH7tlwAAAQQ"]
[Tue Jul 28 17:21:55.314591 2026] [:error] [pid 31471:tid 140534112610048] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/simple.php"] [unique_id "amjJE8bo_8Uj3iOaYH7tlwAAAQQ"]
[Tue Jul 28 17:21:55.314831 2026] [:error] [pid 31471:tid 140534112610048] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/simple.php"] [unique_id "amjJE8bo_8Uj3iOaYH7tlwAAAQQ"]
[Tue Jul 28 17:21:55.531757 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xxx.php"] [unique_id "amjJE8bo_8Uj3iOaYH7tmAAAARQ"]
[Tue Jul 28 17:21:55.532626 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xxx.php"] [unique_id "amjJE8bo_8Uj3iOaYH7tmAAAARQ"]
[Tue Jul 28 17:21:55.532999 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/xxx.php"] [unique_id "amjJE8bo_8Uj3iOaYH7tmAAAARQ"]
[Tue Jul 28 17:21:55.533082 2026] [:error] [pid 31471:tid 140533905172224] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xxx.php"] [unique_id "amjJE8bo_8Uj3iOaYH7tmAAAARQ"]
[Tue Jul 28 17:21:55.749542 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/hypo.php"] [unique_id "amjJE8bo_8Uj3iOaYH7tmgAAARc"]
[Tue Jul 28 17:21:55.750144 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/hypo.php"] [unique_id "amjJE8bo_8Uj3iOaYH7tmgAAARc"]
[Tue Jul 28 17:21:55.750480 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/hypo.php"] [unique_id "amjJE8bo_8Uj3iOaYH7tmgAAARc"]
[Tue Jul 28 17:21:55.750571 2026] [:error] [pid 31471:tid 140533879994112] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/hypo.php"] [unique_id "amjJE8bo_8Uj3iOaYH7tmgAAARc"]
[Tue Jul 28 17:21:55.972229 2026] [:error] [pid 31471:tid 140533980706560] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amjJE8bo_8Uj3iOaYH7tmwAAAQs"]
[Tue Jul 28 17:21:55.973081 2026] [:error] [pid 31471:tid 140533980706560] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amjJE8bo_8Uj3iOaYH7tmwAAAQs"]
[Tue Jul 28 17:21:55.973523 2026] [:error] [pid 31471:tid 140533980706560] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amjJE8bo_8Uj3iOaYH7tmwAAAQs"]
[Tue Jul 28 17:21:55.973615 2026] [:error] [pid 31471:tid 140533980706560] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amjJE8bo_8Uj3iOaYH7tmwAAAQs"]
[Tue Jul 28 17:21:56.192092 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/chosen.php"] [unique_id "amjJFMbo_8Uj3iOaYH7tnQAAAQw"]
[Tue Jul 28 17:21:56.192758 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/chosen.php"] [unique_id "amjJFMbo_8Uj3iOaYH7tnQAAAQw"]
[Tue Jul 28 17:21:56.193055 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/chosen.php"] [unique_id "amjJFMbo_8Uj3iOaYH7tnQAAAQw"]
[Tue Jul 28 17:21:56.193135 2026] [:error] [pid 31471:tid 140533972313856] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/chosen.php"] [unique_id "amjJFMbo_8Uj3iOaYH7tnQAAAQw"]
[Tue Jul 28 17:21:56.409096 2026] [:error] [pid 31471:tid 140534146180864] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/block-bindings/"] [unique_id "amjJFMbo_8Uj3iOaYH7tngAAAQA"]
[Tue Jul 28 17:21:56.409738 2026] [:error] [pid 31471:tid 140534146180864] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/block-bindings/"] [unique_id "amjJFMbo_8Uj3iOaYH7tngAAAQA"]
[Tue Jul 28 17:21:56.410026 2026] [:error] [pid 31471:tid 140534146180864] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/block-bindings/"] [unique_id "amjJFMbo_8Uj3iOaYH7tngAAAQA"]
[Tue Jul 28 17:21:56.410087 2026] [:error] [pid 31471:tid 140534146180864] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/block-bindings/"] [unique_id "amjJFMbo_8Uj3iOaYH7tngAAAQA"]
[Tue Jul 28 17:21:56.624397 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/als.php"] [unique_id "amjJFMbo_8Uj3iOaYH7tnwAAAQg"]
[Tue Jul 28 17:21:56.625176 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/als.php"] [unique_id "amjJFMbo_8Uj3iOaYH7tnwAAAQg"]
[Tue Jul 28 17:21:56.625578 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/als.php"] [unique_id "amjJFMbo_8Uj3iOaYH7tnwAAAQg"]
[Tue Jul 28 17:21:56.625660 2026] [:error] [pid 31471:tid 140534005884672] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/als.php"] [unique_id "amjJFMbo_8Uj3iOaYH7tnwAAAQg"]
[Tue Jul 28 17:21:56.847066 2026] [:error] [pid 31471:tid 140533930350336] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/pol.php"] [unique_id "amjJFMbo_8Uj3iOaYH7toQAAARE"]
[Tue Jul 28 17:21:56.847859 2026] [:error] [pid 31471:tid 140533930350336] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/pol.php"] [unique_id "amjJFMbo_8Uj3iOaYH7toQAAARE"]
[Tue Jul 28 17:21:56.848285 2026] [:error] [pid 31471:tid 140533930350336] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/pol.php"] [unique_id "amjJFMbo_8Uj3iOaYH7toQAAARE"]
[Tue Jul 28 17:21:56.848374 2026] [:error] [pid 31471:tid 140533930350336] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/pol.php"] [unique_id "amjJFMbo_8Uj3iOaYH7toQAAARE"]
[Tue Jul 28 17:21:57.083975 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file5.php"] [unique_id "amjJFcbo_8Uj3iOaYH7towAAARY"]
[Tue Jul 28 17:21:57.084718 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file5.php"] [unique_id "amjJFcbo_8Uj3iOaYH7towAAARY"]
[Tue Jul 28 17:21:57.085056 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file5.php"] [unique_id "amjJFcbo_8Uj3iOaYH7towAAARY"]
[Tue Jul 28 17:21:57.085123 2026] [:error] [pid 31471:tid 140533888386816] [client 172.69.11.219:14242] [client 172.69.11.219] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file5.php"] [unique_id "amjJFcbo_8Uj3iOaYH7towAAARY"]
[Tue Jul 28 17:21:57.498852 2026] [:error] [pid 31088:tid 140533947135744] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file.php"] [unique_id "amjJFfdDbqUNvvZoMq9I7QAAAE8"]
[Tue Jul 28 17:21:57.499806 2026] [:error] [pid 31088:tid 140533947135744] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file.php"] [unique_id "amjJFfdDbqUNvvZoMq9I7QAAAE8"]
[Tue Jul 28 17:21:57.500203 2026] [:error] [pid 31088:tid 140533947135744] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file.php"] [unique_id "amjJFfdDbqUNvvZoMq9I7QAAAE8"]
[Tue Jul 28 17:21:57.500292 2026] [:error] [pid 31088:tid 140533947135744] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file.php"] [unique_id "amjJFfdDbqUNvvZoMq9I7QAAAE8"]
[Tue Jul 28 17:21:57.717257 2026] [:error] [pid 31088:tid 140533938743040] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amjJFfdDbqUNvvZoMq9I7gAAAFA"]
[Tue Jul 28 17:21:57.718155 2026] [:error] [pid 31088:tid 140533938743040] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amjJFfdDbqUNvvZoMq9I7gAAAFA"]
[Tue Jul 28 17:21:57.718583 2026] [:error] [pid 31088:tid 140533938743040] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amjJFfdDbqUNvvZoMq9I7gAAAFA"]
[Tue Jul 28 17:21:57.718671 2026] [:error] [pid 31088:tid 140533938743040] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amjJFfdDbqUNvvZoMq9I7gAAAFA"]
[Tue Jul 28 17:21:57.935508 2026] [:error] [pid 31088:tid 140533896779520] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aa2.php"] [unique_id "amjJFfdDbqUNvvZoMq9I8AAAAFU"]
[Tue Jul 28 17:21:57.936284 2026] [:error] [pid 31088:tid 140533896779520] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aa2.php"] [unique_id "amjJFfdDbqUNvvZoMq9I8AAAAFU"]
[Tue Jul 28 17:21:57.936568 2026] [:error] [pid 31088:tid 140533896779520] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/aa2.php"] [unique_id "amjJFfdDbqUNvvZoMq9I8AAAAFU"]
[Tue Jul 28 17:21:57.936635 2026] [:error] [pid 31088:tid 140533896779520] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/aa2.php"] [unique_id "amjJFfdDbqUNvvZoMq9I8AAAAFU"]
[Tue Jul 28 17:21:58.155910 2026] [:error] [pid 31088:tid 140534121002752] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ccou.php"] [unique_id "amjJFvdDbqUNvvZoMq9I8QAAAEM"]
[Tue Jul 28 17:21:58.156707 2026] [:error] [pid 31088:tid 140534121002752] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ccou.php"] [unique_id "amjJFvdDbqUNvvZoMq9I8QAAAEM"]
[Tue Jul 28 17:21:58.157078 2026] [:error] [pid 31088:tid 140534121002752] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ccou.php"] [unique_id "amjJFvdDbqUNvvZoMq9I8QAAAEM"]
[Tue Jul 28 17:21:58.157163 2026] [:error] [pid 31088:tid 140534121002752] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ccou.php"] [unique_id "amjJFvdDbqUNvvZoMq9I8QAAAEM"]
[Tue Jul 28 17:21:58.389160 2026] [:error] [pid 31088:tid 140533905172224] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dr.php"] [unique_id "amjJFvdDbqUNvvZoMq9I8gAAAFQ"]
[Tue Jul 28 17:21:58.389800 2026] [:error] [pid 31088:tid 140533905172224] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dr.php"] [unique_id "amjJFvdDbqUNvvZoMq9I8gAAAFQ"]
[Tue Jul 28 17:21:58.390069 2026] [:error] [pid 31088:tid 140533905172224] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/dr.php"] [unique_id "amjJFvdDbqUNvvZoMq9I8gAAAFQ"]
[Tue Jul 28 17:21:58.390125 2026] [:error] [pid 31088:tid 140533905172224] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dr.php"] [unique_id "amjJFvdDbqUNvvZoMq9I8gAAAFQ"]
[Tue Jul 28 17:21:58.606013 2026] [:error] [pid 31088:tid 140534137788160] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xamp.php"] [unique_id "amjJFvdDbqUNvvZoMq9I9AAAAEE"]
[Tue Jul 28 17:21:58.606806 2026] [:error] [pid 31088:tid 140534137788160] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xamp.php"] [unique_id "amjJFvdDbqUNvvZoMq9I9AAAAEE"]
[Tue Jul 28 17:21:58.607141 2026] [:error] [pid 31088:tid 140534137788160] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/xamp.php"] [unique_id "amjJFvdDbqUNvvZoMq9I9AAAAEE"]
[Tue Jul 28 17:21:58.607202 2026] [:error] [pid 31088:tid 140534137788160] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xamp.php"] [unique_id "amjJFvdDbqUNvvZoMq9I9AAAAEE"]
[Tue Jul 28 17:21:58.834857 2026] [:error] [pid 31088:tid 140533930350336] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bless.php"] [unique_id "amjJFvdDbqUNvvZoMq9I9QAAAFE"]
[Tue Jul 28 17:21:58.835745 2026] [:error] [pid 31088:tid 140533930350336] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bless.php"] [unique_id "amjJFvdDbqUNvvZoMq9I9QAAAFE"]
[Tue Jul 28 17:21:58.836186 2026] [:error] [pid 31088:tid 140533930350336] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bless.php"] [unique_id "amjJFvdDbqUNvvZoMq9I9QAAAFE"]
[Tue Jul 28 17:21:58.836286 2026] [:error] [pid 31088:tid 140533930350336] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bless.php"] [unique_id "amjJFvdDbqUNvvZoMq9I9QAAAFE"]
[Tue Jul 28 17:21:59.063111 2026] [:error] [pid 31088:tid 140533913564928] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file25.php"] [unique_id "amjJF_dDbqUNvvZoMq9I9gAAAFM"]
[Tue Jul 28 17:21:59.063924 2026] [:error] [pid 31088:tid 140533913564928] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file25.php"] [unique_id "amjJF_dDbqUNvvZoMq9I9gAAAFM"]
[Tue Jul 28 17:21:59.064320 2026] [:error] [pid 31088:tid 140533913564928] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file25.php"] [unique_id "amjJF_dDbqUNvvZoMq9I9gAAAFM"]
[Tue Jul 28 17:21:59.064412 2026] [:error] [pid 31088:tid 140533913564928] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file25.php"] [unique_id "amjJF_dDbqUNvvZoMq9I9gAAAFM"]
[Tue Jul 28 17:21:59.282429 2026] [:error] [pid 31088:tid 140534005884672] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file6.php"] [unique_id "amjJF_dDbqUNvvZoMq9I-AAAAEg"]
[Tue Jul 28 17:21:59.283025 2026] [:error] [pid 31088:tid 140534005884672] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file6.php"] [unique_id "amjJF_dDbqUNvvZoMq9I-AAAAEg"]
[Tue Jul 28 17:21:59.283346 2026] [:error] [pid 31088:tid 140534005884672] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file6.php"] [unique_id "amjJF_dDbqUNvvZoMq9I-AAAAEg"]
[Tue Jul 28 17:21:59.283440 2026] [:error] [pid 31088:tid 140534005884672] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file6.php"] [unique_id "amjJF_dDbqUNvvZoMq9I-AAAAEg"]
[Tue Jul 28 17:21:59.507125 2026] [:error] [pid 31088:tid 140533997491968] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/a2.php"] [unique_id "amjJF_dDbqUNvvZoMq9I-QAAAEk"]
[Tue Jul 28 17:21:59.507966 2026] [:error] [pid 31088:tid 140533997491968] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/a2.php"] [unique_id "amjJF_dDbqUNvvZoMq9I-QAAAEk"]
[Tue Jul 28 17:21:59.508393 2026] [:error] [pid 31088:tid 140533997491968] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/a2.php"] [unique_id "amjJF_dDbqUNvvZoMq9I-QAAAEk"]
[Tue Jul 28 17:21:59.508509 2026] [:error] [pid 31088:tid 140533997491968] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/a2.php"] [unique_id "amjJF_dDbqUNvvZoMq9I-QAAAEk"]
[Tue Jul 28 17:21:59.725088 2026] [:error] [pid 31088:tid 140534129395456] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file15.php"] [unique_id "amjJF_dDbqUNvvZoMq9I-gAAAEI"]
[Tue Jul 28 17:21:59.725737 2026] [:error] [pid 31088:tid 140534129395456] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file15.php"] [unique_id "amjJF_dDbqUNvvZoMq9I-gAAAEI"]
[Tue Jul 28 17:21:59.726060 2026] [:error] [pid 31088:tid 140534129395456] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file15.php"] [unique_id "amjJF_dDbqUNvvZoMq9I-gAAAEI"]
[Tue Jul 28 17:21:59.726138 2026] [:error] [pid 31088:tid 140534129395456] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file15.php"] [unique_id "amjJF_dDbqUNvvZoMq9I-gAAAEI"]
[Tue Jul 28 17:21:59.943665 2026] [:error] [pid 31088:tid 140533963921152] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/f35.php"] [unique_id "amjJF_dDbqUNvvZoMq9I_AAAAE0"]
[Tue Jul 28 17:21:59.944568 2026] [:error] [pid 31088:tid 140533963921152] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/f35.php"] [unique_id "amjJF_dDbqUNvvZoMq9I_AAAAE0"]
[Tue Jul 28 17:21:59.944955 2026] [:error] [pid 31088:tid 140533963921152] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/f35.php"] [unique_id "amjJF_dDbqUNvvZoMq9I_AAAAE0"]
[Tue Jul 28 17:21:59.945038 2026] [:error] [pid 31088:tid 140533963921152] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/f35.php"] [unique_id "amjJF_dDbqUNvvZoMq9I_AAAAE0"]
[Tue Jul 28 17:22:00.163526 2026] [:error] [pid 31088:tid 140534014277376] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-load.php"] [unique_id "amjJGPdDbqUNvvZoMq9I_QAAAEc"]
[Tue Jul 28 17:22:00.164689 2026] [:error] [pid 31088:tid 140534014277376] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-load.php"] [unique_id "amjJGPdDbqUNvvZoMq9I_QAAAEc"]
[Tue Jul 28 17:22:00.165244 2026] [:error] [pid 31088:tid 140534014277376] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-load.php"] [unique_id "amjJGPdDbqUNvvZoMq9I_QAAAEc"]
[Tue Jul 28 17:22:00.165370 2026] [:error] [pid 31088:tid 140534014277376] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-load.php"] [unique_id "amjJGPdDbqUNvvZoMq9I_QAAAEc"]
[Tue Jul 28 17:22:00.381419 2026] [:error] [pid 31088:tid 140533955528448] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xwpg.php"] [unique_id "amjJGPdDbqUNvvZoMq9I_gAAAE4"]
[Tue Jul 28 17:22:00.382253 2026] [:error] [pid 31088:tid 140533955528448] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xwpg.php"] [unique_id "amjJGPdDbqUNvvZoMq9I_gAAAE4"]
[Tue Jul 28 17:22:00.382706 2026] [:error] [pid 31088:tid 140533955528448] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/xwpg.php"] [unique_id "amjJGPdDbqUNvvZoMq9I_gAAAE4"]
[Tue Jul 28 17:22:00.382786 2026] [:error] [pid 31088:tid 140533955528448] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xwpg.php"] [unique_id "amjJGPdDbqUNvvZoMq9I_gAAAE4"]
[Tue Jul 28 17:22:00.606869 2026] [:error] [pid 31088:tid 140533871601408] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/assets/"] [unique_id "amjJGPdDbqUNvvZoMq9I_wAAAFg"]
[Tue Jul 28 17:22:00.607465 2026] [:error] [pid 31088:tid 140533871601408] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/assets/"] [unique_id "amjJGPdDbqUNvvZoMq9I_wAAAFg"]
[Tue Jul 28 17:22:00.607764 2026] [:error] [pid 31088:tid 140533871601408] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/assets/"] [unique_id "amjJGPdDbqUNvvZoMq9I_wAAAFg"]
[Tue Jul 28 17:22:00.607818 2026] [:error] [pid 31088:tid 140533871601408] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/assets/"] [unique_id "amjJGPdDbqUNvvZoMq9I_wAAAFg"]
[Tue Jul 28 17:22:00.839115 2026] [:error] [pid 31088:tid 140534095824640] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "amjJGPdDbqUNvvZoMq9JAQAAAEY"]
[Tue Jul 28 17:22:00.839827 2026] [:error] [pid 31088:tid 140534095824640] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "amjJGPdDbqUNvvZoMq9JAQAAAEY"]
[Tue Jul 28 17:22:00.840088 2026] [:error] [pid 31088:tid 140534095824640] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "amjJGPdDbqUNvvZoMq9JAQAAAEY"]
[Tue Jul 28 17:22:00.840163 2026] [:error] [pid 31088:tid 140534095824640] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "amjJGPdDbqUNvvZoMq9JAQAAAEY"]
[Tue Jul 28 17:22:01.060288 2026] [:error] [pid 31088:tid 140534104217344] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xstelth.php"] [unique_id "amjJGfdDbqUNvvZoMq9JAgAAAEU"]
[Tue Jul 28 17:22:01.061117 2026] [:error] [pid 31088:tid 140534104217344] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xstelth.php"] [unique_id "amjJGfdDbqUNvvZoMq9JAgAAAEU"]
[Tue Jul 28 17:22:01.061509 2026] [:error] [pid 31088:tid 140534104217344] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/xstelth.php"] [unique_id "amjJGfdDbqUNvvZoMq9JAgAAAEU"]
[Tue Jul 28 17:22:01.061611 2026] [:error] [pid 31088:tid 140534104217344] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xstelth.php"] [unique_id "amjJGfdDbqUNvvZoMq9JAgAAAEU"]
[Tue Jul 28 17:22:01.279241 2026] [:error] [pid 31088:tid 140533972313856] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amjJGfdDbqUNvvZoMq9JAwAAAEw"]
[Tue Jul 28 17:22:01.280165 2026] [:error] [pid 31088:tid 140533972313856] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amjJGfdDbqUNvvZoMq9JAwAAAEw"]
[Tue Jul 28 17:22:01.280607 2026] [:error] [pid 31088:tid 140533972313856] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amjJGfdDbqUNvvZoMq9JAwAAAEw"]
[Tue Jul 28 17:22:01.280728 2026] [:error] [pid 31088:tid 140533972313856] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amjJGfdDbqUNvvZoMq9JAwAAAEw"]
[Tue Jul 28 17:22:01.509816 2026] [:error] [pid 31088:tid 140533947135744] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aaa.php"] [unique_id "amjJGfdDbqUNvvZoMq9JBQAAAE8"]
[Tue Jul 28 17:22:01.510591 2026] [:error] [pid 31088:tid 140533947135744] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aaa.php"] [unique_id "amjJGfdDbqUNvvZoMq9JBQAAAE8"]
[Tue Jul 28 17:22:01.510972 2026] [:error] [pid 31088:tid 140533947135744] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/aaa.php"] [unique_id "amjJGfdDbqUNvvZoMq9JBQAAAE8"]
[Tue Jul 28 17:22:01.511060 2026] [:error] [pid 31088:tid 140533947135744] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/aaa.php"] [unique_id "amjJGfdDbqUNvvZoMq9JBQAAAE8"]
[Tue Jul 28 17:22:01.729687 2026] [:error] [pid 31088:tid 140533921957632] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gecko.php"] [unique_id "amjJGfdDbqUNvvZoMq9JBgAAAFI"]
[Tue Jul 28 17:22:01.730669 2026] [:error] [pid 31088:tid 140533921957632] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gecko.php"] [unique_id "amjJGfdDbqUNvvZoMq9JBgAAAFI"]
[Tue Jul 28 17:22:01.731063 2026] [:error] [pid 31088:tid 140533921957632] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/gecko.php"] [unique_id "amjJGfdDbqUNvvZoMq9JBgAAAFI"]
[Tue Jul 28 17:22:01.731143 2026] [:error] [pid 31088:tid 140533921957632] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gecko.php"] [unique_id "amjJGfdDbqUNvvZoMq9JBgAAAFI"]
[Tue Jul 28 17:22:01.948166 2026] [:error] [pid 31088:tid 140533938743040] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sh3ll.php"] [unique_id "amjJGfdDbqUNvvZoMq9JBwAAAFA"]
[Tue Jul 28 17:22:01.948944 2026] [:error] [pid 31088:tid 140533938743040] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sh3ll.php"] [unique_id "amjJGfdDbqUNvvZoMq9JBwAAAFA"]
[Tue Jul 28 17:22:01.949331 2026] [:error] [pid 31088:tid 140533938743040] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sh3ll.php"] [unique_id "amjJGfdDbqUNvvZoMq9JBwAAAFA"]
[Tue Jul 28 17:22:01.949410 2026] [:error] [pid 31088:tid 140533938743040] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sh3ll.php"] [unique_id "amjJGfdDbqUNvvZoMq9JBwAAAFA"]
[Tue Jul 28 17:22:02.181249 2026] [:error] [pid 31088:tid 140533896779520] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/pbck.php"] [unique_id "amjJGvdDbqUNvvZoMq9JCAAAAFU"]
[Tue Jul 28 17:22:02.181972 2026] [:error] [pid 31088:tid 140533896779520] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/pbck.php"] [unique_id "amjJGvdDbqUNvvZoMq9JCAAAAFU"]
[Tue Jul 28 17:22:02.182282 2026] [:error] [pid 31088:tid 140533896779520] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/pbck.php"] [unique_id "amjJGvdDbqUNvvZoMq9JCAAAAFU"]
[Tue Jul 28 17:22:02.182337 2026] [:error] [pid 31088:tid 140533896779520] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/pbck.php"] [unique_id "amjJGvdDbqUNvvZoMq9JCAAAAFU"]
[Tue Jul 28 17:22:02.403023 2026] [:error] [pid 31088:tid 140534121002752] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xiugai.php"] [unique_id "amjJGvdDbqUNvvZoMq9JCQAAAEM"]
[Tue Jul 28 17:22:02.403843 2026] [:error] [pid 31088:tid 140534121002752] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xiugai.php"] [unique_id "amjJGvdDbqUNvvZoMq9JCQAAAEM"]
[Tue Jul 28 17:22:02.404215 2026] [:error] [pid 31088:tid 140534121002752] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/xiugai.php"] [unique_id "amjJGvdDbqUNvvZoMq9JCQAAAEM"]
[Tue Jul 28 17:22:02.404307 2026] [:error] [pid 31088:tid 140534121002752] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xiugai.php"] [unique_id "amjJGvdDbqUNvvZoMq9JCQAAAEM"]
[Tue Jul 28 17:22:02.623326 2026] [:error] [pid 31088:tid 140534137788160] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/e.php"] [unique_id "amjJGvdDbqUNvvZoMq9JCwAAAEE"]
[Tue Jul 28 17:22:02.624243 2026] [:error] [pid 31088:tid 140534137788160] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/e.php"] [unique_id "amjJGvdDbqUNvvZoMq9JCwAAAEE"]
[Tue Jul 28 17:22:02.624663 2026] [:error] [pid 31088:tid 140534137788160] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/e.php"] [unique_id "amjJGvdDbqUNvvZoMq9JCwAAAEE"]
[Tue Jul 28 17:22:02.624738 2026] [:error] [pid 31088:tid 140534137788160] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/e.php"] [unique_id "amjJGvdDbqUNvvZoMq9JCwAAAEE"]
[Tue Jul 28 17:22:02.859847 2026] [:error] [pid 31088:tid 140533930350336] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/for.php"] [unique_id "amjJGvdDbqUNvvZoMq9JDAAAAFE"]
[Tue Jul 28 17:22:02.860824 2026] [:error] [pid 31088:tid 140533930350336] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/for.php"] [unique_id "amjJGvdDbqUNvvZoMq9JDAAAAFE"]
[Tue Jul 28 17:22:02.861255 2026] [:error] [pid 31088:tid 140533930350336] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/for.php"] [unique_id "amjJGvdDbqUNvvZoMq9JDAAAAFE"]
[Tue Jul 28 17:22:02.861378 2026] [:error] [pid 31088:tid 140533930350336] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/for.php"] [unique_id "amjJGvdDbqUNvvZoMq9JDAAAAFE"]
[Tue Jul 28 17:22:03.077658 2026] [:error] [pid 31088:tid 140533989099264] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/adminner.php"] [unique_id "amjJG_dDbqUNvvZoMq9JDQAAAEo"]
[Tue Jul 28 17:22:03.078517 2026] [:error] [pid 31088:tid 140533989099264] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/adminner.php"] [unique_id "amjJG_dDbqUNvvZoMq9JDQAAAEo"]
[Tue Jul 28 17:22:03.078907 2026] [:error] [pid 31088:tid 140533989099264] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/adminner.php"] [unique_id "amjJG_dDbqUNvvZoMq9JDQAAAEo"]
[Tue Jul 28 17:22:03.078988 2026] [:error] [pid 31088:tid 140533989099264] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/adminner.php"] [unique_id "amjJG_dDbqUNvvZoMq9JDQAAAEo"]
[Tue Jul 28 17:22:03.353189 2026] [:error] [pid 31088:tid 140534005884672] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/82.php"] [unique_id "amjJG_dDbqUNvvZoMq9JEAAAAEg"]
[Tue Jul 28 17:22:03.354198 2026] [:error] [pid 31088:tid 140534005884672] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/82.php"] [unique_id "amjJG_dDbqUNvvZoMq9JEAAAAEg"]
[Tue Jul 28 17:22:03.354635 2026] [:error] [pid 31088:tid 140534005884672] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/82.php"] [unique_id "amjJG_dDbqUNvvZoMq9JEAAAAEg"]
[Tue Jul 28 17:22:03.354733 2026] [:error] [pid 31088:tid 140534005884672] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/82.php"] [unique_id "amjJG_dDbqUNvvZoMq9JEAAAAEg"]
[Tue Jul 28 17:22:03.574439 2026] [:error] [pid 31088:tid 140533997491968] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/kir.php"] [unique_id "amjJG_dDbqUNvvZoMq9JEQAAAEk"]
[Tue Jul 28 17:22:03.575220 2026] [:error] [pid 31088:tid 140533997491968] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/kir.php"] [unique_id "amjJG_dDbqUNvvZoMq9JEQAAAEk"]
[Tue Jul 28 17:22:03.575516 2026] [:error] [pid 31088:tid 140533997491968] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/kir.php"] [unique_id "amjJG_dDbqUNvvZoMq9JEQAAAEk"]
[Tue Jul 28 17:22:03.575586 2026] [:error] [pid 31088:tid 140533997491968] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/kir.php"] [unique_id "amjJG_dDbqUNvvZoMq9JEQAAAEk"]
[Tue Jul 28 17:22:03.791040 2026] [:error] [pid 31088:tid 140533879994112] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xhar.php"] [unique_id "amjJG_dDbqUNvvZoMq9JEgAAAFc"]
[Tue Jul 28 17:22:03.791864 2026] [:error] [pid 31088:tid 140533879994112] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xhar.php"] [unique_id "amjJG_dDbqUNvvZoMq9JEgAAAFc"]
[Tue Jul 28 17:22:03.792234 2026] [:error] [pid 31088:tid 140533879994112] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/xhar.php"] [unique_id "amjJG_dDbqUNvvZoMq9JEgAAAFc"]
[Tue Jul 28 17:22:03.792335 2026] [:error] [pid 31088:tid 140533879994112] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xhar.php"] [unique_id "amjJG_dDbqUNvvZoMq9JEgAAAFc"]
[Tue Jul 28 17:22:04.009721 2026] [:error] [pid 31088:tid 140534129395456] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file1221.php"] [unique_id "amjJHPdDbqUNvvZoMq9JEwAAAEI"]
[Tue Jul 28 17:22:04.010308 2026] [:error] [pid 31088:tid 140534129395456] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file1221.php"] [unique_id "amjJHPdDbqUNvvZoMq9JEwAAAEI"]
[Tue Jul 28 17:22:04.010636 2026] [:error] [pid 31088:tid 140534129395456] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file1221.php"] [unique_id "amjJHPdDbqUNvvZoMq9JEwAAAEI"]
[Tue Jul 28 17:22:04.010692 2026] [:error] [pid 31088:tid 140534129395456] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file1221.php"] [unique_id "amjJHPdDbqUNvvZoMq9JEwAAAEI"]
[Tue Jul 28 17:22:04.228102 2026] [:error] [pid 31088:tid 140534014277376] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/inx.php"] [unique_id "amjJHPdDbqUNvvZoMq9JFQAAAEc"]
[Tue Jul 28 17:22:04.228743 2026] [:error] [pid 31088:tid 140534014277376] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/inx.php"] [unique_id "amjJHPdDbqUNvvZoMq9JFQAAAEc"]
[Tue Jul 28 17:22:04.229055 2026] [:error] [pid 31088:tid 140534014277376] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/inx.php"] [unique_id "amjJHPdDbqUNvvZoMq9JFQAAAEc"]
[Tue Jul 28 17:22:04.229121 2026] [:error] [pid 31088:tid 140534014277376] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/inx.php"] [unique_id "amjJHPdDbqUNvvZoMq9JFQAAAEc"]
[Tue Jul 28 17:22:04.456895 2026] [:error] [pid 31088:tid 140533955528448] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/qqqa.php"] [unique_id "amjJHPdDbqUNvvZoMq9JFgAAAE4"]
[Tue Jul 28 17:22:04.457647 2026] [:error] [pid 31088:tid 140533955528448] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/qqqa.php"] [unique_id "amjJHPdDbqUNvvZoMq9JFgAAAE4"]
[Tue Jul 28 17:22:04.458046 2026] [:error] [pid 31088:tid 140533955528448] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/qqqa.php"] [unique_id "amjJHPdDbqUNvvZoMq9JFgAAAE4"]
[Tue Jul 28 17:22:04.458130 2026] [:error] [pid 31088:tid 140533955528448] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/qqqa.php"] [unique_id "amjJHPdDbqUNvvZoMq9JFgAAAE4"]
[Tue Jul 28 17:22:04.675320 2026] [:error] [pid 31088:tid 140534146180864] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-firewall.php"] [unique_id "amjJHPdDbqUNvvZoMq9JFwAAAEA"]
[Tue Jul 28 17:22:04.675910 2026] [:error] [pid 31088:tid 140534146180864] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-firewall.php"] [unique_id "amjJHPdDbqUNvvZoMq9JFwAAAEA"]
[Tue Jul 28 17:22:04.676198 2026] [:error] [pid 31088:tid 140534146180864] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-firewall.php"] [unique_id "amjJHPdDbqUNvvZoMq9JFwAAAEA"]
[Tue Jul 28 17:22:04.676252 2026] [:error] [pid 31088:tid 140534146180864] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-firewall.php"] [unique_id "amjJHPdDbqUNvvZoMq9JFwAAAEA"]
[Tue Jul 28 17:22:04.892431 2026] [:error] [pid 31088:tid 140534095824640] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/reviall.php"] [unique_id "amjJHPdDbqUNvvZoMq9JGQAAAEY"]
[Tue Jul 28 17:22:04.893036 2026] [:error] [pid 31088:tid 140534095824640] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/reviall.php"] [unique_id "amjJHPdDbqUNvvZoMq9JGQAAAEY"]
[Tue Jul 28 17:22:04.893371 2026] [:error] [pid 31088:tid 140534095824640] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/reviall.php"] [unique_id "amjJHPdDbqUNvvZoMq9JGQAAAEY"]
[Tue Jul 28 17:22:04.893427 2026] [:error] [pid 31088:tid 140534095824640] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/reviall.php"] [unique_id "amjJHPdDbqUNvvZoMq9JGQAAAEY"]
[Tue Jul 28 17:22:05.115073 2026] [:error] [pid 31088:tid 140534104217344] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/404.php"] [unique_id "amjJHfdDbqUNvvZoMq9JGgAAAEU"]
[Tue Jul 28 17:22:05.115712 2026] [:error] [pid 31088:tid 140534104217344] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/404.php"] [unique_id "amjJHfdDbqUNvvZoMq9JGgAAAEU"]
[Tue Jul 28 17:22:05.116013 2026] [:error] [pid 31088:tid 140534104217344] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/404.php"] [unique_id "amjJHfdDbqUNvvZoMq9JGgAAAEU"]
[Tue Jul 28 17:22:05.116071 2026] [:error] [pid 31088:tid 140534104217344] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/404.php"] [unique_id "amjJHfdDbqUNvvZoMq9JGgAAAEU"]
[Tue Jul 28 17:22:05.333648 2026] [:error] [pid 31088:tid 140533980706560] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bolt.php"] [unique_id "amjJHfdDbqUNvvZoMq9JGwAAAEs"]
[Tue Jul 28 17:22:05.334349 2026] [:error] [pid 31088:tid 140533980706560] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bolt.php"] [unique_id "amjJHfdDbqUNvvZoMq9JGwAAAEs"]
[Tue Jul 28 17:22:05.334693 2026] [:error] [pid 31088:tid 140533980706560] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bolt.php"] [unique_id "amjJHfdDbqUNvvZoMq9JGwAAAEs"]
[Tue Jul 28 17:22:05.334777 2026] [:error] [pid 31088:tid 140533980706560] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bolt.php"] [unique_id "amjJHfdDbqUNvvZoMq9JGwAAAEs"]
[Tue Jul 28 17:22:05.551026 2026] [:error] [pid 31088:tid 140533947135744] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/File.php"] [unique_id "amjJHfdDbqUNvvZoMq9JHQAAAE8"]
[Tue Jul 28 17:22:05.551886 2026] [:error] [pid 31088:tid 140533947135744] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/File.php"] [unique_id "amjJHfdDbqUNvvZoMq9JHQAAAE8"]
[Tue Jul 28 17:22:05.552270 2026] [:error] [pid 31088:tid 140533947135744] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/File.php"] [unique_id "amjJHfdDbqUNvvZoMq9JHQAAAE8"]
[Tue Jul 28 17:22:05.552358 2026] [:error] [pid 31088:tid 140533947135744] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/File.php"] [unique_id "amjJHfdDbqUNvvZoMq9JHQAAAE8"]
[Tue Jul 28 17:22:05.772816 2026] [:error] [pid 31088:tid 140534112610048] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fi22.php"] [unique_id "amjJHfdDbqUNvvZoMq9JHwAAAEQ"]
[Tue Jul 28 17:22:05.773375 2026] [:error] [pid 31088:tid 140534112610048] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fi22.php"] [unique_id "amjJHfdDbqUNvvZoMq9JHwAAAEQ"]
[Tue Jul 28 17:22:05.773678 2026] [:error] [pid 31088:tid 140534112610048] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fi22.php"] [unique_id "amjJHfdDbqUNvvZoMq9JHwAAAEQ"]
[Tue Jul 28 17:22:05.773746 2026] [:error] [pid 31088:tid 140534112610048] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/fi22.php"] [unique_id "amjJHfdDbqUNvvZoMq9JHwAAAEQ"]
[Tue Jul 28 17:22:05.990597 2026] [:error] [pid 31088:tid 140533938743040] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/zero.php"] [unique_id "amjJHfdDbqUNvvZoMq9JIAAAAFA"]
[Tue Jul 28 17:22:05.991346 2026] [:error] [pid 31088:tid 140533938743040] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/zero.php"] [unique_id "amjJHfdDbqUNvvZoMq9JIAAAAFA"]
[Tue Jul 28 17:22:05.991742 2026] [:error] [pid 31088:tid 140533938743040] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/zero.php"] [unique_id "amjJHfdDbqUNvvZoMq9JIAAAAFA"]
[Tue Jul 28 17:22:05.991825 2026] [:error] [pid 31088:tid 140533938743040] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/zero.php"] [unique_id "amjJHfdDbqUNvvZoMq9JIAAAAFA"]
[Tue Jul 28 17:22:06.211389 2026] [:error] [pid 31088:tid 140534121002752] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/1xmomo.php"] [unique_id "amjJHvdDbqUNvvZoMq9JIgAAAEM"]
[Tue Jul 28 17:22:06.212040 2026] [:error] [pid 31088:tid 140534121002752] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/1xmomo.php"] [unique_id "amjJHvdDbqUNvvZoMq9JIgAAAEM"]
[Tue Jul 28 17:22:06.212352 2026] [:error] [pid 31088:tid 140534121002752] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/1xmomo.php"] [unique_id "amjJHvdDbqUNvvZoMq9JIgAAAEM"]
[Tue Jul 28 17:22:06.212409 2026] [:error] [pid 31088:tid 140534121002752] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/1xmomo.php"] [unique_id "amjJHvdDbqUNvvZoMq9JIgAAAEM"]
[Tue Jul 28 17:22:06.434412 2026] [:error] [pid 31088:tid 140534137788160] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fmws.php"] [unique_id "amjJHvdDbqUNvvZoMq9JIwAAAEE"]
[Tue Jul 28 17:22:06.435162 2026] [:error] [pid 31088:tid 140534137788160] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fmws.php"] [unique_id "amjJHvdDbqUNvvZoMq9JIwAAAEE"]
[Tue Jul 28 17:22:06.435491 2026] [:error] [pid 31088:tid 140534137788160] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fmws.php"] [unique_id "amjJHvdDbqUNvvZoMq9JIwAAAEE"]
[Tue Jul 28 17:22:06.435593 2026] [:error] [pid 31088:tid 140534137788160] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/fmws.php"] [unique_id "amjJHvdDbqUNvvZoMq9JIwAAAEE"]
[Tue Jul 28 17:22:06.651137 2026] [:error] [pid 31088:tid 140533930350336] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bico.php"] [unique_id "amjJHvdDbqUNvvZoMq9JJAAAAFE"]
[Tue Jul 28 17:22:06.651961 2026] [:error] [pid 31088:tid 140533930350336] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bico.php"] [unique_id "amjJHvdDbqUNvvZoMq9JJAAAAFE"]
[Tue Jul 28 17:22:06.652329 2026] [:error] [pid 31088:tid 140533930350336] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bico.php"] [unique_id "amjJHvdDbqUNvvZoMq9JJAAAAFE"]
[Tue Jul 28 17:22:06.652412 2026] [:error] [pid 31088:tid 140533930350336] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bico.php"] [unique_id "amjJHvdDbqUNvvZoMq9JJAAAAFE"]
[Tue Jul 28 17:22:06.869262 2026] [:error] [pid 31088:tid 140533905172224] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amjJHvdDbqUNvvZoMq9JJgAAAFQ"]
[Tue Jul 28 17:22:06.869896 2026] [:error] [pid 31088:tid 140533905172224] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amjJHvdDbqUNvvZoMq9JJgAAAFQ"]
[Tue Jul 28 17:22:06.870230 2026] [:error] [pid 31088:tid 140533905172224] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amjJHvdDbqUNvvZoMq9JJgAAAFQ"]
[Tue Jul 28 17:22:06.870303 2026] [:error] [pid 31088:tid 140533905172224] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amjJHvdDbqUNvvZoMq9JJgAAAFQ"]
[Tue Jul 28 17:22:07.087871 2026] [:error] [pid 31088:tid 140534005884672] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/alfabet.php"] [unique_id "amjJH_dDbqUNvvZoMq9JJwAAAEg"]
[Tue Jul 28 17:22:07.088744 2026] [:error] [pid 31088:tid 140534005884672] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/alfabet.php"] [unique_id "amjJH_dDbqUNvvZoMq9JJwAAAEg"]
[Tue Jul 28 17:22:07.089131 2026] [:error] [pid 31088:tid 140534005884672] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/alfabet.php"] [unique_id "amjJH_dDbqUNvvZoMq9JJwAAAEg"]
[Tue Jul 28 17:22:07.089247 2026] [:error] [pid 31088:tid 140534005884672] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/alfabet.php"] [unique_id "amjJH_dDbqUNvvZoMq9JJwAAAEg"]
[Tue Jul 28 17:22:07.306655 2026] [:error] [pid 31088:tid 140533997491968] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/vq15lj.php"] [unique_id "amjJH_dDbqUNvvZoMq9JKAAAAEk"]
[Tue Jul 28 17:22:07.307314 2026] [:error] [pid 31088:tid 140533997491968] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/vq15lj.php"] [unique_id "amjJH_dDbqUNvvZoMq9JKAAAAEk"]
[Tue Jul 28 17:22:07.307686 2026] [:error] [pid 31088:tid 140533997491968] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/vq15lj.php"] [unique_id "amjJH_dDbqUNvvZoMq9JKAAAAEk"]
[Tue Jul 28 17:22:07.307767 2026] [:error] [pid 31088:tid 140533997491968] [client 172.69.11.218:13065] [client 172.69.11.218] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/vq15lj.php"] [unique_id "amjJH_dDbqUNvvZoMq9JKAAAAEk"]
[Tue Jul 28 18:21:49.448858 2026] [:error] [pid 31473:tid 140533938743040] [client 172.71.164.5:10627] [client 172.71.164.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjXHQiTq2daiUZjsUFsDQAAAVA"]
[Tue Jul 28 18:21:49.455339 2026] [:error] [pid 31473:tid 140533938743040] [client 172.71.164.5:10627] [client 172.71.164.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjXHQiTq2daiUZjsUFsDQAAAVA"]
[Tue Jul 28 18:21:49.455820 2026] [:error] [pid 31473:tid 140533938743040] [client 172.71.164.5:10627] [client 172.71.164.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjXHQiTq2daiUZjsUFsDQAAAVA"]
[Tue Jul 28 18:21:52.045755 2026] [:error] [pid 31471:tid 140534121002752] [client 172.70.242.202:9538] [client 172.70.242.202] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjXIMbo_8Uj3iOaYH4lzAAAAQM"]
[Tue Jul 28 18:21:52.046714 2026] [:error] [pid 31471:tid 140534121002752] [client 172.70.242.202:9538] [client 172.70.242.202] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "HEAD"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjXIMbo_8Uj3iOaYH4lzAAAAQM"]
[Tue Jul 28 18:21:52.047364 2026] [:error] [pid 31471:tid 140534121002752] [client 172.70.242.202:9538] [client 172.70.242.202] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjXIMbo_8Uj3iOaYH4lzAAAAQM"]
[Tue Jul 28 18:21:55.440975 2026] [:error] [pid 31088:tid 140534095824640] [client 172.70.243.188:14053] [client 172.70.243.188] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amjXI_dDbqUNvvZoMq9jWAAAAEY"]
[Tue Jul 28 18:21:55.441684 2026] [:error] [pid 31088:tid 140534095824640] [client 172.70.243.188:14053] [client 172.70.243.188] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amjXI_dDbqUNvvZoMq9jWAAAAEY"]
[Tue Jul 28 18:21:55.442129 2026] [:error] [pid 31088:tid 140534095824640] [client 172.70.243.188:14053] [client 172.70.243.188] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amjXI_dDbqUNvvZoMq9jWAAAAEY"]
[Tue Jul 28 18:21:55.442353 2026] [:error] [pid 31088:tid 140534095824640] [client 172.70.243.188:14053] [client 172.70.243.188] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amjXI_dDbqUNvvZoMq9jWAAAAEY"]
[Tue Jul 28 18:21:56.520347 2026] [:error] [pid 31088:tid 140533921957632] [client 172.70.243.188:14053] [client 172.70.243.188] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amjXJPdDbqUNvvZoMq9jWQAAAFI"]
[Tue Jul 28 18:21:56.520908 2026] [:error] [pid 31088:tid 140533921957632] [client 172.70.243.188:14053] [client 172.70.243.188] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amjXJPdDbqUNvvZoMq9jWQAAAFI"]
[Tue Jul 28 18:21:56.521261 2026] [:error] [pid 31088:tid 140533921957632] [client 172.70.243.188:14053] [client 172.70.243.188] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amjXJPdDbqUNvvZoMq9jWQAAAFI"]
[Tue Jul 28 18:21:56.521414 2026] [:error] [pid 31088:tid 140533921957632] [client 172.70.243.188:14053] [client 172.70.243.188] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amjXJPdDbqUNvvZoMq9jWQAAAFI"]
[Tue Jul 28 18:32:26.187619 2026] [:error] [pid 31473:tid 140534121002752] [client 162.159.113.3:9374] [client 162.159.113.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/wp-json/"] [unique_id "amjZmgiTq2daiUZjsUF_KwAAAUM"]
[Tue Jul 28 18:32:26.188335 2026] [:error] [pid 31473:tid 140534121002752] [client 162.159.113.3:9374] [client 162.159.113.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/wp-json/"] [unique_id "amjZmgiTq2daiUZjsUF_KwAAAUM"]
[Tue Jul 28 18:32:26.188712 2026] [:error] [pid 31473:tid 140534121002752] [client 162.159.113.3:9374] [client 162.159.113.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/wp-json/"] [unique_id "amjZmgiTq2daiUZjsUF_KwAAAUM"]
[Tue Jul 28 18:32:26.233150 2026] [:error] [pid 31473:tid 140534137788160] [client 162.159.113.2:13855] [client 162.159.113.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "amjZmgiTq2daiUZjsUF_LAAAAUE"]
[Tue Jul 28 18:32:26.233950 2026] [:error] [pid 31473:tid 140534137788160] [client 162.159.113.2:13855] [client 162.159.113.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "amjZmgiTq2daiUZjsUF_LAAAAUE"]
[Tue Jul 28 18:32:26.234446 2026] [:error] [pid 31473:tid 140534137788160] [client 162.159.113.2:13855] [client 162.159.113.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "amjZmgiTq2daiUZjsUF_LAAAAUE"]
[Tue Jul 28 18:32:26.252526 2026] [:error] [pid 31473:tid 140533997491968] [client 162.159.113.2:13855] [client 162.159.113.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/wp-json/"] [unique_id "amjZmgiTq2daiUZjsUF_LQAAAUk"]
[Tue Jul 28 18:32:26.253348 2026] [:error] [pid 31473:tid 140533997491968] [client 162.159.113.2:13855] [client 162.159.113.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/wp-json/"] [unique_id "amjZmgiTq2daiUZjsUF_LQAAAUk"]
[Tue Jul 28 18:32:26.253703 2026] [:error] [pid 31473:tid 140533997491968] [client 162.159.113.2:13855] [client 162.159.113.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/wp-json/"] [unique_id "amjZmgiTq2daiUZjsUF_LQAAAUk"]
[Tue Jul 28 18:37:03.283251 2026] [:error] [pid 31473:tid 140533963921152] [client 172.71.172.192:12237] [client 172.71.172.192] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjarwiTq2daiUZjsUGG9AAAAU0"]
[Tue Jul 28 18:37:03.286807 2026] [:error] [pid 31473:tid 140533963921152] [client 172.71.172.192:12237] [client 172.71.172.192] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjarwiTq2daiUZjsUGG9AAAAU0"]
[Tue Jul 28 18:37:03.287193 2026] [:error] [pid 31473:tid 140533963921152] [client 172.71.172.192:12237] [client 172.71.172.192] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjarwiTq2daiUZjsUGG9AAAAU0"]
[Tue Jul 28 18:49:38.446376 2026] [:error] [pid 31473:tid 140534129395456] [client 104.23.243.18:13124] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amjdogiTq2daiUZjsUGcwQAAAUI"]
[Tue Jul 28 18:49:38.447344 2026] [:error] [pid 31473:tid 140534129395456] [client 104.23.243.18:13124] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amjdogiTq2daiUZjsUGcwQAAAUI"]
[Tue Jul 28 18:49:38.447897 2026] [:error] [pid 31473:tid 140534129395456] [client 104.23.243.18:13124] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amjdogiTq2daiUZjsUGcwQAAAUI"]
[Tue Jul 28 19:41:09.121372 2026] [:error] [pid 11831:tid 140254035998464] [client 104.23.243.180:14219] [client 104.23.243.180] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amjpta1pcvJQ08UlsIoIgAAAABg"]
[Tue Jul 28 19:41:09.153476 2026] [:error] [pid 11831:tid 140254035998464] [client 104.23.243.180:14219] [client 104.23.243.180] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amjpta1pcvJQ08UlsIoIgAAAABg"]
[Tue Jul 28 19:41:09.154071 2026] [:error] [pid 11831:tid 140254035998464] [client 104.23.243.180:14219] [client 104.23.243.180] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amjpta1pcvJQ08UlsIoIgAAAABg"]
[Tue Jul 28 19:44:23.070802 2026] [:error] [pid 31432:tid 140254153496320] [client 104.22.93.88:12962] [client 104.22.93.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjqdxTJGXjs973h3x8nIQAAAYo"]
[Tue Jul 28 19:44:23.071340 2026] [:error] [pid 31432:tid 140254153496320] [client 104.22.93.88:12962] [client 104.22.93.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjqdxTJGXjs973h3x8nIQAAAYo"]
[Tue Jul 28 19:44:23.071734 2026] [:error] [pid 31432:tid 140254153496320] [client 104.22.93.88:12962] [client 104.22.93.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjqdxTJGXjs973h3x8nIQAAAYo"]
[Tue Jul 28 19:48:03.379819 2026] [:error] [pid 31504:tid 140254111532800] [client 172.70.46.165:11398] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjrU76SJayGrl0sDpEM-wAAAc8"]
[Tue Jul 28 19:48:03.380685 2026] [:error] [pid 31504:tid 140254111532800] [client 172.70.46.165:11398] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjrU76SJayGrl0sDpEM-wAAAc8"]
[Tue Jul 28 19:48:03.381200 2026] [:error] [pid 31504:tid 140254111532800] [client 172.70.46.165:11398] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjrU76SJayGrl0sDpEM-wAAAc8"]
[Tue Jul 28 19:48:08.025280 2026] [:error] [pid 31431:tid 140254111532800] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/rboyeuobzy5ebxfzz6nrzkly"] [unique_id "amjrWFTL6Zxx7wY924HA3QAAAU8"]
[Tue Jul 28 19:48:08.026032 2026] [:error] [pid 31431:tid 140254111532800] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/rboyeuobzy5ebxfzz6nrzkly"] [unique_id "amjrWFTL6Zxx7wY924HA3QAAAU8"]
[Tue Jul 28 19:48:08.026451 2026] [:error] [pid 31431:tid 140254111532800] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/rboyeuobzy5ebxfzz6nrzkly"] [unique_id "amjrWFTL6Zxx7wY924HA3QAAAU8"]
[Tue Jul 28 19:48:08.884349 2026] [:error] [pid 31659:tid 140254103140096] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/hqpxps96ydha1q93ow63r7bxf.html"] [unique_id "amjrWOJ1c9-ffzxJaaaUcwAAABA"]
[Tue Jul 28 19:48:08.885070 2026] [:error] [pid 31659:tid 140254103140096] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/hqpxps96ydha1q93ow63r7bxf.html"] [unique_id "amjrWOJ1c9-ffzxJaaaUcwAAABA"]
[Tue Jul 28 19:48:08.885441 2026] [:error] [pid 31659:tid 140254103140096] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/hqpxps96ydha1q93ow63r7bxf.html"] [unique_id "amjrWOJ1c9-ffzxJaaaUcwAAABA"]
[Tue Jul 28 19:48:09.453109 2026] [:error] [pid 31431:tid 140254187067136] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/p36zk2am04wskdiipfmu09u.php"] [unique_id "amjrWVTL6Zxx7wY924HA4wAAAUY"]
[Tue Jul 28 19:48:09.453911 2026] [:error] [pid 31431:tid 140254187067136] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/p36zk2am04wskdiipfmu09u.php"] [unique_id "amjrWVTL6Zxx7wY924HA4wAAAUY"]
[Tue Jul 28 19:48:09.454368 2026] [:error] [pid 31431:tid 140254187067136] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/p36zk2am04wskdiipfmu09u.php"] [unique_id "amjrWVTL6Zxx7wY924HA4wAAAUY"]
[Tue Jul 28 19:48:11.465125 2026] [:error] [pid 31659:tid 140254212245248] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/WEB-INF/web.xml"] [unique_id "amjrW-J1c9-ffzxJaaaUeQAAAAM"]
[Tue Jul 28 19:48:11.465967 2026] [:error] [pid 31659:tid 140254212245248] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/WEB-INF/web.xml"] [unique_id "amjrW-J1c9-ffzxJaaaUeQAAAAM"]
[Tue Jul 28 19:48:11.466469 2026] [:error] [pid 31659:tid 140254212245248] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/WEB-INF/web.xml"] [unique_id "amjrW-J1c9-ffzxJaaaUeQAAAAM"]
[Tue Jul 28 19:48:11.537170 2026] [:error] [pid 31659:tid 140254035998464] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amjrW-J1c9-ffzxJaaaUegAAABg"]
[Tue Jul 28 19:48:11.538033 2026] [:error] [pid 31659:tid 140254035998464] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amjrW-J1c9-ffzxJaaaUegAAABg"]
[Tue Jul 28 19:48:11.538500 2026] [:error] [pid 31659:tid 140254035998464] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amjrW-J1c9-ffzxJaaaUegAAABg"]
[Tue Jul 28 19:48:11.538729 2026] [:error] [pid 31659:tid 140254035998464] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amjrW-J1c9-ffzxJaaaUegAAABg"]
[Tue Jul 28 19:48:11.544320 2026] [:error] [pid 31431:tid 140254170281728] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amjrW1TL6Zxx7wY924HA7QAAAUg"]
[Tue Jul 28 19:48:11.545295 2026] [:error] [pid 31431:tid 140254170281728] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amjrW1TL6Zxx7wY924HA7QAAAUg"]
[Tue Jul 28 19:48:11.545791 2026] [:error] [pid 31431:tid 140254170281728] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amjrW1TL6Zxx7wY924HA7QAAAUg"]
[Tue Jul 28 19:48:11.546013 2026] [:error] [pid 31431:tid 140254170281728] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amjrW1TL6Zxx7wY924HA7QAAAUg"]
[Tue Jul 28 19:48:12.003926 2026] [:error] [pid 31659:tid 140254145103616] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amjrXOJ1c9-ffzxJaaaUewAAAAs"]
[Tue Jul 28 19:48:12.004487 2026] [:error] [pid 31659:tid 140254145103616] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amjrXOJ1c9-ffzxJaaaUewAAAAs"]
[Tue Jul 28 19:48:12.004926 2026] [:error] [pid 31659:tid 140254145103616] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amjrXOJ1c9-ffzxJaaaUewAAAAs"]
[Tue Jul 28 19:48:12.005075 2026] [:error] [pid 31659:tid 140254145103616] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amjrXOJ1c9-ffzxJaaaUewAAAAs"]
[Tue Jul 28 19:48:12.008459 2026] [:error] [pid 31431:tid 140254220637952] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.gitlab-ci.yml"] [unique_id "amjrXFTL6Zxx7wY924HA7gAAAUI"]
[Tue Jul 28 19:48:12.009284 2026] [:error] [pid 31431:tid 140254220637952] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.gitlab-ci.yml"] [unique_id "amjrXFTL6Zxx7wY924HA7gAAAUI"]
[Tue Jul 28 19:48:12.009745 2026] [:error] [pid 31431:tid 140254220637952] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.gitlab-ci.yml"] [unique_id "amjrXFTL6Zxx7wY924HA7gAAAUI"]
[Tue Jul 28 19:48:12.010013 2026] [:error] [pid 31431:tid 140254220637952] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .gitlab-ci.yml found within REQUEST_FILENAME: /.gitlab-ci.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.gitlab-ci.yml"] [unique_id "amjrXFTL6Zxx7wY924HA7gAAAUI"]
[Tue Jul 28 19:48:12.361820 2026] [:error] [pid 31431:tid 140254052783872] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/deploy.sh"] [unique_id "amjrXFTL6Zxx7wY924HA8AAAAVY"]
[Tue Jul 28 19:48:12.362222 2026] [:error] [pid 31431:tid 140254052783872] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/deploy.sh"] [unique_id "amjrXFTL6Zxx7wY924HA8AAAAVY"]
[Tue Jul 28 19:48:12.362470 2026] [:error] [pid 31431:tid 140254052783872] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/deploy.sh"] [unique_id "amjrXFTL6Zxx7wY924HA8AAAAVY"]
[Tue Jul 28 19:48:13.563433 2026] [:error] [pid 31659:tid 140254052783872] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.env"] [unique_id "amjrXeJ1c9-ffzxJaaaUfwAAABY"]
[Tue Jul 28 19:48:13.564273 2026] [:error] [pid 31659:tid 140254052783872] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.env"] [unique_id "amjrXeJ1c9-ffzxJaaaUfwAAABY"]
[Tue Jul 28 19:48:13.564758 2026] [:error] [pid 31659:tid 140254052783872] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.env"] [unique_id "amjrXeJ1c9-ffzxJaaaUfwAAABY"]
[Tue Jul 28 19:48:13.567442 2026] [:error] [pid 31431:tid 140254094747392] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/source/.env"] [unique_id "amjrXVTL6Zxx7wY924HA9gAAAVE"]
[Tue Jul 28 19:48:13.568054 2026] [:error] [pid 31431:tid 140254094747392] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/source/.env"] [unique_id "amjrXVTL6Zxx7wY924HA9gAAAVE"]
[Tue Jul 28 19:48:13.568501 2026] [:error] [pid 31431:tid 140254094747392] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/source/.env"] [unique_id "amjrXVTL6Zxx7wY924HA9gAAAVE"]
[Tue Jul 28 19:48:13.568728 2026] [:error] [pid 31431:tid 140254094747392] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /source/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/source/.env"] [unique_id "amjrXVTL6Zxx7wY924HA9gAAAVE"]
[Tue Jul 28 19:48:14.469955 2026] [:error] [pid 31431:tid 140254161889024] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/framework/.env"] [unique_id "amjrXlTL6Zxx7wY924HA-wAAAUk"]
[Tue Jul 28 19:48:14.471060 2026] [:error] [pid 31431:tid 140254161889024] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/framework/.env"] [unique_id "amjrXlTL6Zxx7wY924HA-wAAAUk"]
[Tue Jul 28 19:48:14.471663 2026] [:error] [pid 31431:tid 140254161889024] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/framework/.env"] [unique_id "amjrXlTL6Zxx7wY924HA-wAAAUk"]
[Tue Jul 28 19:48:14.471879 2026] [:error] [pid 31431:tid 140254161889024] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /framework/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/framework/.env"] [unique_id "amjrXlTL6Zxx7wY924HA-wAAAUk"]
[Tue Jul 28 19:48:14.815635 2026] [:error] [pid 31659:tid 140254136710912] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ikiwiki/.env"] [unique_id "amjrXuJ1c9-ffzxJaaaUgwAAAAw"]
[Tue Jul 28 19:48:14.816291 2026] [:error] [pid 31431:tid 140254136710912] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.inc.php"] [unique_id "amjrXlTL6Zxx7wY924HA_QAAAUw"]
[Tue Jul 28 19:48:14.816428 2026] [:error] [pid 31659:tid 140254136710912] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ikiwiki/.env"] [unique_id "amjrXuJ1c9-ffzxJaaaUgwAAAAw"]
[Tue Jul 28 19:48:14.816899 2026] [:error] [pid 31659:tid 140254136710912] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ikiwiki/.env"] [unique_id "amjrXuJ1c9-ffzxJaaaUgwAAAAw"]
[Tue Jul 28 19:48:14.816955 2026] [:error] [pid 31431:tid 140254136710912] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.inc.php"] [unique_id "amjrXlTL6Zxx7wY924HA_QAAAUw"]
[Tue Jul 28 19:48:14.817132 2026] [:error] [pid 31659:tid 140254136710912] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /ikiwiki/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/ikiwiki/.env"] [unique_id "amjrXuJ1c9-ffzxJaaaUgwAAAAw"]
[Tue Jul 28 19:48:14.817366 2026] [:error] [pid 31431:tid 140254136710912] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.inc.php"] [unique_id "amjrXlTL6Zxx7wY924HA_QAAAUw"]
[Tue Jul 28 19:48:16.059340 2026] [:error] [pid 31659:tid 140254061176576] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/system/.env"] [unique_id "amjrYOJ1c9-ffzxJaaaUhAAAABU"]
[Tue Jul 28 19:48:16.059912 2026] [:error] [pid 31659:tid 140254061176576] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/system/.env"] [unique_id "amjrYOJ1c9-ffzxJaaaUhAAAABU"]
[Tue Jul 28 19:48:16.060305 2026] [:error] [pid 31659:tid 140254061176576] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/system/.env"] [unique_id "amjrYOJ1c9-ffzxJaaaUhAAAABU"]
[Tue Jul 28 19:48:16.060455 2026] [:error] [pid 31659:tid 140254061176576] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /system/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/system/.env"] [unique_id "amjrYOJ1c9-ffzxJaaaUhAAAABU"]
[Tue Jul 28 19:48:16.081729 2026] [:error] [pid 31431:tid 140254044391168] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/test/"] [unique_id "amjrYFTL6Zxx7wY924HBAwAAAVc"]
[Tue Jul 28 19:48:16.082521 2026] [:error] [pid 31431:tid 140254044391168] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/test/"] [unique_id "amjrYFTL6Zxx7wY924HBAwAAAVc"]
[Tue Jul 28 19:48:16.082980 2026] [:error] [pid 31431:tid 140254044391168] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/test/"] [unique_id "amjrYFTL6Zxx7wY924HBAwAAAVc"]
[Tue Jul 28 19:48:16.533729 2026] [:error] [pid 31431:tid 140254111532800] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amjrYFTL6Zxx7wY924HBBgAAAU8"]
[Tue Jul 28 19:48:16.534614 2026] [:error] [pid 31431:tid 140254111532800] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amjrYFTL6Zxx7wY924HBBgAAAU8"]
[Tue Jul 28 19:48:16.535132 2026] [:error] [pid 31431:tid 140254111532800] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amjrYFTL6Zxx7wY924HBBgAAAU8"]
[Tue Jul 28 19:48:16.535365 2026] [:error] [pid 31431:tid 140254111532800] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amjrYFTL6Zxx7wY924HBBgAAAU8"]
[Tue Jul 28 19:48:16.851335 2026] [:error] [pid 31431:tid 140254119925504] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amjrYFTL6Zxx7wY924HBCAAAAU4"]
[Tue Jul 28 19:48:16.853788 2026] [:error] [pid 31431:tid 140254119925504] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amjrYFTL6Zxx7wY924HBCAAAAU4"]
[Tue Jul 28 19:48:16.854793 2026] [:error] [pid 31431:tid 140254119925504] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amjrYFTL6Zxx7wY924HBCAAAAU4"]
[Tue Jul 28 19:48:16.855215 2026] [:error] [pid 31431:tid 140254119925504] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amjrYFTL6Zxx7wY924HBCAAAAU4"]
[Tue Jul 28 19:48:16.862409 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "amjrYOJ1c9-ffzxJaaaUhgAAABc"]
[Tue Jul 28 19:48:16.862998 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "amjrYOJ1c9-ffzxJaaaUhgAAABc"]
[Tue Jul 28 19:48:16.863351 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in ARGS:file outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:file=app/config/parameters.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "amjrYOJ1c9-ffzxJaaaUhgAAABc"]
[Tue Jul 28 19:48:16.863413 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "amjrYOJ1c9-ffzxJaaaUhgAAABc"]
[Tue Jul 28 19:48:16.863653 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "parameters.yml" at ARGS:file. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "97"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: parameters.yml found within ARGS:file: app/config/parameters.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "amjrYOJ1c9-ffzxJaaaUhgAAABc"]
[Tue Jul 28 19:48:17.309228 2026] [:error] [pid 31431:tid 140254094747392] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/mysql.sql"] [unique_id "amjrYVTL6Zxx7wY924HBCgAAAVE"]
[Tue Jul 28 19:48:17.309804 2026] [:error] [pid 31431:tid 140254094747392] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/mysql.sql"] [unique_id "amjrYVTL6Zxx7wY924HBCgAAAVE"]
[Tue Jul 28 19:48:17.310207 2026] [:error] [pid 31431:tid 140254094747392] [client 172.70.47.5:13210] [client 172.70.47.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-content/mysql.sql"] [unique_id "amjrYVTL6Zxx7wY924HBCgAAAVE"]
[Tue Jul 28 19:48:17.320667 2026] [:error] [pid 31659:tid 140254195459840] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amjrYeJ1c9-ffzxJaaaUiQAAAAU"]
[Tue Jul 28 19:48:17.321344 2026] [:error] [pid 31659:tid 140254195459840] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amjrYeJ1c9-ffzxJaaaUiQAAAAU"]
[Tue Jul 28 19:48:17.321829 2026] [:error] [pid 31659:tid 140254195459840] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amjrYeJ1c9-ffzxJaaaUiQAAAAU"]
[Tue Jul 28 19:48:17.322073 2026] [:error] [pid 31659:tid 140254195459840] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amjrYeJ1c9-ffzxJaaaUiQAAAAU"]
[Tue Jul 28 19:48:17.732544 2026] [:error] [pid 31659:tid 140254145103616] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.dev.local"] [unique_id "amjrYeJ1c9-ffzxJaaaUjAAAAAs"]
[Tue Jul 28 19:48:17.733358 2026] [:error] [pid 31659:tid 140254145103616] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.dev.local"] [unique_id "amjrYeJ1c9-ffzxJaaaUjAAAAAs"]
[Tue Jul 28 19:48:17.733831 2026] [:error] [pid 31659:tid 140254145103616] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev.local"] [unique_id "amjrYeJ1c9-ffzxJaaaUjAAAAAs"]
[Tue Jul 28 19:48:17.734497 2026] [:error] [pid 31659:tid 140254145103616] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev.local"] [unique_id "amjrYeJ1c9-ffzxJaaaUjAAAAAs"]
[Tue Jul 28 19:48:17.937850 2026] [:error] [pid 31659:tid 140254111532800] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amjrYeJ1c9-ffzxJaaaUjgAAAA8"]
[Tue Jul 28 19:48:17.938806 2026] [:error] [pid 31659:tid 140254111532800] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amjrYeJ1c9-ffzxJaaaUjgAAAA8"]
[Tue Jul 28 19:48:17.939323 2026] [:error] [pid 31659:tid 140254111532800] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amjrYeJ1c9-ffzxJaaaUjgAAAA8"]
[Tue Jul 28 19:48:17.985486 2026] [:error] [pid 31659:tid 140254094747392] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amjrYeJ1c9-ffzxJaaaUjwAAABE"]
[Tue Jul 28 19:48:17.986422 2026] [:error] [pid 31659:tid 140254094747392] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amjrYeJ1c9-ffzxJaaaUjwAAABE"]
[Tue Jul 28 19:48:17.986930 2026] [:error] [pid 31659:tid 140254094747392] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amjrYeJ1c9-ffzxJaaaUjwAAABE"]
[Tue Jul 28 19:48:17.987179 2026] [:error] [pid 31659:tid 140254094747392] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amjrYeJ1c9-ffzxJaaaUjwAAABE"]
[Tue Jul 28 19:48:21.771612 2026] [:error] [pid 31659:tid 140254069569280] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amjrZeJ1c9-ffzxJaaaUlgAAABQ"]
[Tue Jul 28 19:48:21.772382 2026] [:error] [pid 31659:tid 140254069569280] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amjrZeJ1c9-ffzxJaaaUlgAAABQ"]
[Tue Jul 28 19:48:21.772836 2026] [:error] [pid 31659:tid 140254069569280] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amjrZeJ1c9-ffzxJaaaUlgAAABQ"]
[Tue Jul 28 19:48:21.773050 2026] [:error] [pid 31659:tid 140254069569280] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amjrZeJ1c9-ffzxJaaaUlgAAABQ"]
[Tue Jul 28 19:48:21.774828 2026] [:error] [pid 31659:tid 140254069569280] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amjrZeJ1c9-ffzxJaaaUlwAAABQ"]
[Tue Jul 28 19:48:21.775355 2026] [:error] [pid 31659:tid 140254069569280] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amjrZeJ1c9-ffzxJaaaUlwAAABQ"]
[Tue Jul 28 19:48:21.775742 2026] [:error] [pid 31659:tid 140254069569280] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amjrZeJ1c9-ffzxJaaaUlwAAABQ"]
[Tue Jul 28 19:48:21.799363 2026] [:error] [pid 4873:tid 140254136710912] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amjrZUe-4ohj6ta8_U4WvQAAAIw"]
[Tue Jul 28 19:48:21.799936 2026] [:error] [pid 4873:tid 140254136710912] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amjrZUe-4ohj6ta8_U4WvQAAAIw"]
[Tue Jul 28 19:48:21.800289 2026] [:error] [pid 4873:tid 140254136710912] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amjrZUe-4ohj6ta8_U4WvQAAAIw"]
[Tue Jul 28 19:48:23.044581 2026] [:error] [pid 4873:tid 140254229030656] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env/.env"] [unique_id "amjrZ0e-4ohj6ta8_U4WvgAAAIE"]
[Tue Jul 28 19:48:23.045354 2026] [:error] [pid 4873:tid 140254229030656] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env/.env"] [unique_id "amjrZ0e-4ohj6ta8_U4WvgAAAIE"]
[Tue Jul 28 19:48:23.045896 2026] [:error] [pid 4873:tid 140254229030656] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/env/.env"] [unique_id "amjrZ0e-4ohj6ta8_U4WvgAAAIE"]
[Tue Jul 28 19:48:23.046134 2026] [:error] [pid 4873:tid 140254229030656] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /env/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/env/.env"] [unique_id "amjrZ0e-4ohj6ta8_U4WvgAAAIE"]
[Tue Jul 28 19:48:23.047646 2026] [:error] [pid 31659:tid 140254111532800] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amjrZ-J1c9-ffzxJaaaUmwAAAA8"]
[Tue Jul 28 19:48:23.048331 2026] [:error] [pid 31659:tid 140254111532800] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amjrZ-J1c9-ffzxJaaaUmwAAAA8"]
[Tue Jul 28 19:48:23.048717 2026] [:error] [pid 31659:tid 140254111532800] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amjrZ-J1c9-ffzxJaaaUmwAAAA8"]
[Tue Jul 28 19:48:23.048933 2026] [:error] [pid 31659:tid 140254111532800] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amjrZ-J1c9-ffzxJaaaUmwAAAA8"]
[Tue Jul 28 19:48:23.050229 2026] [:error] [pid 31659:tid 140254212245248] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/info.txt"] [unique_id "amjrZ-J1c9-ffzxJaaaUnAAAAAM"]
[Tue Jul 28 19:48:23.050739 2026] [:error] [pid 31659:tid 140254212245248] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/info.txt"] [unique_id "amjrZ-J1c9-ffzxJaaaUnAAAAAM"]
[Tue Jul 28 19:48:23.051137 2026] [:error] [pid 31659:tid 140254212245248] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/info.txt"] [unique_id "amjrZ-J1c9-ffzxJaaaUnAAAAAM"]
[Tue Jul 28 19:48:23.843181 2026] [:error] [pid 4873:tid 140254035998464] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amjrZ0e-4ohj6ta8_U4WvwAAAJg"]
[Tue Jul 28 19:48:23.843843 2026] [:error] [pid 4873:tid 140254035998464] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amjrZ0e-4ohj6ta8_U4WvwAAAJg"]
[Tue Jul 28 19:48:23.844147 2026] [:error] [pid 31659:tid 140254170281728] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amjrZ-J1c9-ffzxJaaaUnwAAAAg"]
[Tue Jul 28 19:48:23.844176 2026] [:error] [pid 4873:tid 140254035998464] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "amjrZ0e-4ohj6ta8_U4WvwAAAJg"]
[Tue Jul 28 19:48:23.844650 2026] [:error] [pid 31659:tid 140254170281728] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amjrZ-J1c9-ffzxJaaaUnwAAAAg"]
[Tue Jul 28 19:48:23.845039 2026] [:error] [pid 31659:tid 140254170281728] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amjrZ-J1c9-ffzxJaaaUnwAAAAg"]
[Tue Jul 28 19:48:23.845082 2026] [:error] [pid 31659:tid 140254187067136] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amjrZ-J1c9-ffzxJaaaUoAAAAAY"]
[Tue Jul 28 19:48:23.845246 2026] [:error] [pid 31659:tid 140254170281728] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amjrZ-J1c9-ffzxJaaaUnwAAAAg"]
[Tue Jul 28 19:48:23.845443 2026] [:error] [pid 31659:tid 140254187067136] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amjrZ-J1c9-ffzxJaaaUoAAAAAY"]
[Tue Jul 28 19:48:23.845707 2026] [:error] [pid 31659:tid 140254187067136] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amjrZ-J1c9-ffzxJaaaUoAAAAAY"]
[Tue Jul 28 19:48:23.845883 2026] [:error] [pid 31659:tid 140254187067136] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_copy"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amjrZ-J1c9-ffzxJaaaUoAAAAAY"]
[Tue Jul 28 19:48:24.891519 2026] [:error] [pid 4873:tid 140254187067136] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/app.php"] [unique_id "amjraEe-4ohj6ta8_U4WwAAAAIY"]
[Tue Jul 28 19:48:24.891708 2026] [:error] [pid 31659:tid 140254136710912] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amjraOJ1c9-ffzxJaaaUoQAAAAw"]
[Tue Jul 28 19:48:24.892229 2026] [:error] [pid 4873:tid 140254187067136] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/app.php"] [unique_id "amjraEe-4ohj6ta8_U4WwAAAAIY"]
[Tue Jul 28 19:48:24.892415 2026] [:error] [pid 31659:tid 140254136710912] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amjraOJ1c9-ffzxJaaaUoQAAAAw"]
[Tue Jul 28 19:48:24.892625 2026] [:error] [pid 31659:tid 140254161889024] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env.example"] [unique_id "amjraOJ1c9-ffzxJaaaUogAAAAk"]
[Tue Jul 28 19:48:24.892667 2026] [:error] [pid 4873:tid 140254187067136] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/app.php"] [unique_id "amjraEe-4ohj6ta8_U4WwAAAAIY"]
[Tue Jul 28 19:48:24.892954 2026] [:error] [pid 31659:tid 140254136710912] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amjraOJ1c9-ffzxJaaaUoQAAAAw"]
[Tue Jul 28 19:48:24.893251 2026] [:error] [pid 31659:tid 140254161889024] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env.example"] [unique_id "amjraOJ1c9-ffzxJaaaUogAAAAk"]
[Tue Jul 28 19:48:24.893765 2026] [:error] [pid 31659:tid 140254161889024] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/env.example"] [unique_id "amjraOJ1c9-ffzxJaaaUogAAAAk"]
[Tue Jul 28 19:48:26.291301 2026] [:error] [pid 4873:tid 140254170281728] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amjrake-4ohj6ta8_U4WwgAAAIg"]
[Tue Jul 28 19:48:26.292091 2026] [:error] [pid 4873:tid 140254170281728] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amjrake-4ohj6ta8_U4WwgAAAIg"]
[Tue Jul 28 19:48:26.292522 2026] [:error] [pid 4873:tid 140254170281728] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amjrake-4ohj6ta8_U4WwgAAAIg"]
[Tue Jul 28 19:48:26.292739 2026] [:error] [pid 4873:tid 140254170281728] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amjrake-4ohj6ta8_U4WwgAAAIg"]
[Tue Jul 28 19:48:26.295298 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amjrauJ1c9-ffzxJaaaUqQAAABc"]
[Tue Jul 28 19:48:26.295870 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amjrauJ1c9-ffzxJaaaUqQAAABc"]
[Tue Jul 28 19:48:26.296299 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amjrauJ1c9-ffzxJaaaUqQAAABc"]
[Tue Jul 28 19:48:26.296499 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amjrauJ1c9-ffzxJaaaUqQAAABc"]
[Tue Jul 28 19:48:26.298282 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php3"] [unique_id "amjrauJ1c9-ffzxJaaaUqgAAABc"]
[Tue Jul 28 19:48:26.298797 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php3"] [unique_id "amjrauJ1c9-ffzxJaaaUqgAAABc"]
[Tue Jul 28 19:48:26.299179 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php3"] [unique_id "amjrauJ1c9-ffzxJaaaUqgAAABc"]
[Tue Jul 28 19:48:27.997280 2026] [:error] [pid 4873:tid 140254111532800] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env"] [unique_id "amjra0e-4ohj6ta8_U4WxAAAAI8"]
[Tue Jul 28 19:48:27.997824 2026] [:error] [pid 4873:tid 140254111532800] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env"] [unique_id "amjra0e-4ohj6ta8_U4WxAAAAI8"]
[Tue Jul 28 19:48:27.998144 2026] [:error] [pid 4873:tid 140254111532800] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/env"] [unique_id "amjra0e-4ohj6ta8_U4WxAAAAI8"]
[Tue Jul 28 19:48:28.003084 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.bashrc"] [unique_id "amjrbOJ1c9-ffzxJaaaUswAAABc"]
[Tue Jul 28 19:48:28.003902 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.bashrc"] [unique_id "amjrbOJ1c9-ffzxJaaaUswAAABc"]
[Tue Jul 28 19:48:28.004393 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.bashrc"] [unique_id "amjrbOJ1c9-ffzxJaaaUswAAABc"]
[Tue Jul 28 19:48:28.004657 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.165:12758] [client 172.70.46.165] ModSecurity: Warning. Matched phrase ".bashrc" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .bashrc found within REQUEST_FILENAME: /.bashrc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.bashrc"] [unique_id "amjrbOJ1c9-ffzxJaaaUswAAABc"]
[Tue Jul 28 19:48:28.006818 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amjrbOJ1c9-ffzxJaaaUtAAAABc"]
[Tue Jul 28 19:48:28.007461 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amjrbOJ1c9-ffzxJaaaUtAAAABc"]
[Tue Jul 28 19:48:28.007898 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amjrbOJ1c9-ffzxJaaaUtAAAABc"]
[Tue Jul 28 19:48:28.008119 2026] [:error] [pid 31659:tid 140254044391168] [client 172.70.46.164:10016] [client 172.70.46.164] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.envrc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.envrc"] [unique_id "amjrbOJ1c9-ffzxJaaaUtAAAABc"]
[Tue Jul 28 19:48:28.835541 2026] [:error] [pid 4873:tid 140254237423360] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjrbEe-4ohj6ta8_U4WyAAAAIA"]
[Tue Jul 28 19:48:28.836318 2026] [:error] [pid 4873:tid 140254237423360] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjrbEe-4ohj6ta8_U4WyAAAAIA"]
[Tue Jul 28 19:48:28.836761 2026] [:error] [pid 4873:tid 140254237423360] [client 172.70.46.165:13031] [client 172.70.46.165] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjrbEe-4ohj6ta8_U4WyAAAAIA"]
[Tue Jul 28 20:11:30.930812 2026] [:error] [pid 31504:tid 140254119925504] [client 162.158.210.20:13386] [client 162.158.210.20] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjw0r6SJayGrl0sDpEzngAAAc4"]
[Tue Jul 28 20:11:30.931783 2026] [:error] [pid 31504:tid 140254119925504] [client 162.158.210.20:13386] [client 162.158.210.20] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjw0r6SJayGrl0sDpEzngAAAc4"]
[Tue Jul 28 20:11:30.932246 2026] [:error] [pid 31504:tid 140254119925504] [client 162.158.210.20:13386] [client 162.158.210.20] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjw0r6SJayGrl0sDpEzngAAAc4"]
[Tue Jul 28 20:13:44.023765 2026] [:error] [pid 31378:tid 140254161889024] [client 104.23.166.83:11786] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aws.env"] [unique_id "amjxWDps7SmFbinM124W5wAAAEk"]
[Tue Jul 28 20:13:44.024733 2026] [:error] [pid 31378:tid 140254161889024] [client 104.23.166.83:11786] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aws.env"] [unique_id "amjxWDps7SmFbinM124W5wAAAEk"]
[Tue Jul 28 20:13:44.025428 2026] [:error] [pid 31378:tid 140254161889024] [client 104.23.166.83:11786] [client 104.23.166.83] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/aws.env"] [unique_id "amjxWDps7SmFbinM124W5wAAAEk"]
[Tue Jul 28 20:13:44.025567 2026] [:error] [pid 31378:tid 140254161889024] [client 104.23.166.83:11786] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/aws.env"] [unique_id "amjxWDps7SmFbinM124W5wAAAEk"]
[Tue Jul 28 20:13:44.033513 2026] [:error] [pid 31504:tid 140254077961984] [client 141.101.76.33:10901] [client 141.101.76.33] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amjxWL6SJayGrl0sDpE32QAAAdM"]
[Tue Jul 28 20:13:44.034180 2026] [:error] [pid 31504:tid 140254077961984] [client 141.101.76.33:10901] [client 141.101.76.33] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amjxWL6SJayGrl0sDpE32QAAAdM"]
[Tue Jul 28 20:13:44.034615 2026] [:error] [pid 31504:tid 140254077961984] [client 141.101.76.33:10901] [client 141.101.76.33] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amjxWL6SJayGrl0sDpE32QAAAdM"]
[Tue Jul 28 20:13:44.034796 2026] [:error] [pid 31504:tid 140254077961984] [client 141.101.76.33:10901] [client 141.101.76.33] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amjxWL6SJayGrl0sDpE32QAAAdM"]
[Tue Jul 28 20:13:44.049346 2026] [:error] [pid 31504:tid 140254170281728] [client 172.71.103.42:9953] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amjxWL6SJayGrl0sDpE32gAAAcg"]
[Tue Jul 28 20:13:44.049938 2026] [:error] [pid 31504:tid 140254170281728] [client 172.71.103.42:9953] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amjxWL6SJayGrl0sDpE32gAAAcg"]
[Tue Jul 28 20:13:44.050324 2026] [:error] [pid 31504:tid 140254170281728] [client 172.71.103.42:9953] [client 172.71.103.42] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amjxWL6SJayGrl0sDpE32gAAAcg"]
[Tue Jul 28 20:13:44.050398 2026] [:error] [pid 31504:tid 140254170281728] [client 172.71.103.42:9953] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amjxWL6SJayGrl0sDpE32gAAAcg"]
[Tue Jul 28 20:13:44.050583 2026] [:error] [pid 31504:tid 140254170281728] [client 172.71.103.42:9953] [client 172.71.103.42] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amjxWL6SJayGrl0sDpE32gAAAcg"]
[Tue Jul 28 20:20:28.015797 2026] [:error] [pid 31659:tid 140254103140096] [client 172.68.242.16:13082] [client 172.68.242.16] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjy7OJ1c9-ffzxJaaa3DwAAABA"]
[Tue Jul 28 20:20:28.016672 2026] [:error] [pid 31659:tid 140254103140096] [client 172.68.242.16:13082] [client 172.68.242.16] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjy7OJ1c9-ffzxJaaa3DwAAABA"]
[Tue Jul 28 20:20:28.017157 2026] [:error] [pid 31659:tid 140254103140096] [client 172.68.242.16:13082] [client 172.68.242.16] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjy7OJ1c9-ffzxJaaa3DwAAABA"]
[Tue Jul 28 20:20:30.086503 2026] [:error] [pid 31431:tid 140254103140096] [client 162.158.122.145:14032] [client 162.158.122.145] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjy7lTL6Zxx7wY924HLLAAAAVA"]
[Tue Jul 28 20:20:30.087397 2026] [:error] [pid 31431:tid 140254103140096] [client 162.158.122.145:14032] [client 162.158.122.145] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjy7lTL6Zxx7wY924HLLAAAAVA"]
[Tue Jul 28 20:20:30.087971 2026] [:error] [pid 31431:tid 140254103140096] [client 162.158.122.145:14032] [client 162.158.122.145] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amjy7lTL6Zxx7wY924HLLAAAAVA"]
[Tue Jul 28 20:31:48.832518 2026] [:error] [pid 31504:tid 140254136710912] [client 104.23.223.55:10288] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amj1lL6SJayGrl0sDpFXEgAAAcw"]
[Tue Jul 28 20:31:48.833447 2026] [:error] [pid 31504:tid 140254136710912] [client 104.23.223.55:10288] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amj1lL6SJayGrl0sDpFXEgAAAcw"]
[Tue Jul 28 20:31:48.834156 2026] [:error] [pid 31504:tid 140254136710912] [client 104.23.223.55:10288] [client 104.23.223.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amj1lL6SJayGrl0sDpFXEgAAAcw"]
[Tue Jul 28 20:34:40.821693 2026] [:error] [pid 31659:tid 140254145103616] [client 104.23.243.18:12499] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amj2QOJ1c9-ffzxJaabD1QAAAAs"]
[Tue Jul 28 20:34:40.877243 2026] [:error] [pid 31659:tid 140254145103616] [client 104.23.243.18:12499] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amj2QOJ1c9-ffzxJaabD1QAAAAs"]
[Tue Jul 28 20:34:40.877766 2026] [:error] [pid 31659:tid 140254145103616] [client 104.23.243.18:12499] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amj2QOJ1c9-ffzxJaabD1QAAAAs"]
[Tue Jul 28 20:57:48.881466 2026] [:error] [pid 31659:tid 140254052783872] [client 162.158.210.88:13161] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj7rOJ1c9-ffzxJaabdJAAAABY"]
[Tue Jul 28 20:57:48.882397 2026] [:error] [pid 31659:tid 140254052783872] [client 162.158.210.88:13161] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj7rOJ1c9-ffzxJaabdJAAAABY"]
[Tue Jul 28 20:57:48.882889 2026] [:error] [pid 31659:tid 140254052783872] [client 162.158.210.88:13161] [client 162.158.210.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj7rOJ1c9-ffzxJaabdJAAAABY"]
[Tue Jul 28 20:58:39.078439 2026] [:error] [pid 31504:tid 140254111532800] [client 104.23.213.53:13699] [client 104.23.213.53] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amj7376SJayGrl0sDpGFYgAAAc8"]
[Tue Jul 28 20:58:39.079270 2026] [:error] [pid 31504:tid 140254111532800] [client 104.23.213.53:13699] [client 104.23.213.53] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amj7376SJayGrl0sDpGFYgAAAc8"]
[Tue Jul 28 20:58:39.079775 2026] [:error] [pid 31504:tid 140254111532800] [client 104.23.213.53:13699] [client 104.23.213.53] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:From outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:From=wc@verisign.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amj7376SJayGrl0sDpGFYgAAAc8"]
[Tue Jul 28 20:58:39.079830 2026] [:error] [pid 31504:tid 140254111532800] [client 104.23.213.53:13699] [client 104.23.213.53] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amj7376SJayGrl0sDpGFYgAAAc8"]
[Tue Jul 28 20:58:40.279603 2026] [:error] [pid 31504:tid 140254061176576] [client 104.23.211.15:11500] [client 104.23.211.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj74L6SJayGrl0sDpGFbgAAAdU"]
[Tue Jul 28 20:58:40.280274 2026] [:error] [pid 31504:tid 140254061176576] [client 104.23.211.15:11500] [client 104.23.211.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj74L6SJayGrl0sDpGFbgAAAdU"]
[Tue Jul 28 20:58:40.280701 2026] [:error] [pid 31504:tid 140254061176576] [client 104.23.211.15:11500] [client 104.23.211.15] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:From outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:From=wc@verisign.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj74L6SJayGrl0sDpGFbgAAAdU"]
[Tue Jul 28 20:58:40.280739 2026] [:error] [pid 31504:tid 140254061176576] [client 104.23.211.15:11500] [client 104.23.211.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj74L6SJayGrl0sDpGFbgAAAdU"]
[Tue Jul 28 21:00:07.422784 2026] [:error] [pid 31378:tid 140254044391168] [client 172.69.23.91:12631] [client 172.69.23.91] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj8Nzps7SmFbinM124wbAAAAFc"]
[Tue Jul 28 21:00:07.423753 2026] [:error] [pid 31378:tid 140254044391168] [client 172.69.23.91:12631] [client 172.69.23.91] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj8Nzps7SmFbinM124wbAAAAFc"]
[Tue Jul 28 21:00:07.424379 2026] [:error] [pid 31378:tid 140254044391168] [client 172.69.23.91:12631] [client 172.69.23.91] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj8Nzps7SmFbinM124wbAAAAFc"]
[Tue Jul 28 21:01:32.683611 2026] [:error] [pid 4873:tid 140254153496320] [client 172.69.192.157:9831] [client 172.69.192.157] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj8jEe-4ohj6ta8_U5ErgAAAIo"]
[Tue Jul 28 21:01:32.684286 2026] [:error] [pid 4873:tid 140254153496320] [client 172.69.192.157:9831] [client 172.69.192.157] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj8jEe-4ohj6ta8_U5ErgAAAIo"]
[Tue Jul 28 21:01:32.684643 2026] [:error] [pid 4873:tid 140254153496320] [client 172.69.192.157:9831] [client 172.69.192.157] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj8jEe-4ohj6ta8_U5ErgAAAIo"]
[Tue Jul 28 21:01:32.684706 2026] [:error] [pid 4873:tid 140254153496320] [client 172.69.192.157:9831] [client 172.69.192.157] ModSecurity: Warning. Found 1 byte(s) in ARGS:rest_route outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:rest_route=/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj8jEe-4ohj6ta8_U5ErgAAAIo"]
[Tue Jul 28 21:01:32.684769 2026] [:error] [pid 4873:tid 140254153496320] [client 172.69.192.157:9831] [client 172.69.192.157] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj8jEe-4ohj6ta8_U5ErgAAAIo"]
[Tue Jul 28 21:01:32.903312 2026] [:error] [pid 4873:tid 140254220637952] [client 172.69.192.157:9831] [client 172.69.192.157] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj8jEe-4ohj6ta8_U5EsAAAAII"]
[Tue Jul 28 21:01:32.903791 2026] [:error] [pid 4873:tid 140254220637952] [client 172.69.192.157:9831] [client 172.69.192.157] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj8jEe-4ohj6ta8_U5EsAAAAII"]
[Tue Jul 28 21:01:32.904053 2026] [:error] [pid 4873:tid 140254220637952] [client 172.69.192.157:9831] [client 172.69.192.157] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj8jEe-4ohj6ta8_U5EsAAAAII"]
[Tue Jul 28 21:01:32.904115 2026] [:error] [pid 4873:tid 140254220637952] [client 172.69.192.157:9831] [client 172.69.192.157] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amj8jEe-4ohj6ta8_U5EsAAAAII"]
[Tue Jul 28 21:29:57.727933 2026] [:error] [pid 31432:tid 140254044391168] [client 172.71.8.98:11965] [client 172.71.8.98] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkDNRTJGXjs973h3x9OzAAAAZc"], referer: https://sbf-consultancy.com/
[Tue Jul 28 21:29:57.729130 2026] [:error] [pid 31432:tid 140254044391168] [client 172.71.8.98:11965] [client 172.71.8.98] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkDNRTJGXjs973h3x9OzAAAAZc"], referer: https://sbf-consultancy.com/
[Tue Jul 28 21:29:57.729680 2026] [:error] [pid 31432:tid 140254044391168] [client 172.71.8.98:11965] [client 172.71.8.98] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkDNRTJGXjs973h3x9OzAAAAZc"], referer: https://sbf-consultancy.com/
[Tue Jul 28 21:52:42.460402 2026] [:error] [pid 31659:tid 140254052783872] [client 104.23.243.19:12945] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amkIiuJ1c9-ffzxJaaYK-QAAABY"]
[Tue Jul 28 21:52:42.515236 2026] [:error] [pid 31659:tid 140254052783872] [client 104.23.243.19:12945] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amkIiuJ1c9-ffzxJaaYK-QAAABY"]
[Tue Jul 28 21:52:42.515809 2026] [:error] [pid 31659:tid 140254052783872] [client 104.23.243.19:12945] [client 104.23.243.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amkIiuJ1c9-ffzxJaaYK-QAAABY"]
[Tue Jul 28 21:52:42.942579 2026] [:error] [pid 31432:tid 140254119925504] [client 104.23.243.181:13952] [client 104.23.243.181] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amkIihTJGXjs973h3x90FgAAAY4"]
[Tue Jul 28 21:52:42.943440 2026] [:error] [pid 31432:tid 140254119925504] [client 104.23.243.181:13952] [client 104.23.243.181] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amkIihTJGXjs973h3x90FgAAAY4"]
[Tue Jul 28 21:52:42.943956 2026] [:error] [pid 31432:tid 140254119925504] [client 104.23.243.181:13952] [client 104.23.243.181] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amkIihTJGXjs973h3x90FgAAAY4"]
[Tue Jul 28 21:53:49.446799 2026] [:error] [pid 31432:tid 140254103140096] [client 104.23.168.92:9365] [client 104.23.168.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amkIzRTJGXjs973h3x92PwAAAZA"]
[Tue Jul 28 21:53:49.447873 2026] [:error] [pid 31432:tid 140254103140096] [client 104.23.168.92:9365] [client 104.23.168.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amkIzRTJGXjs973h3x92PwAAAZA"]
[Tue Jul 28 21:53:49.448591 2026] [:error] [pid 31432:tid 140254103140096] [client 104.23.168.92:9365] [client 104.23.168.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amkIzRTJGXjs973h3x92PwAAAZA"]
[Tue Jul 28 21:58:22.846676 2026] [:error] [pid 31659:tid 140254103140096] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amkJ3uJ1c9-ffzxJaaYOdgAAABA"]
[Tue Jul 28 21:58:22.847634 2026] [:error] [pid 31659:tid 140254103140096] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amkJ3uJ1c9-ffzxJaaYOdgAAABA"]
[Tue Jul 28 21:58:22.848312 2026] [:error] [pid 31659:tid 140254103140096] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amkJ3uJ1c9-ffzxJaaYOdgAAABA"]
[Tue Jul 28 21:58:22.848369 2026] [:error] [pid 31659:tid 140254103140096] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amkJ3uJ1c9-ffzxJaaYOdgAAABA"]
[Tue Jul 28 21:58:26.289517 2026] [:error] [pid 31659:tid 140254061176576] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config.env"] [unique_id "amkJ4uJ1c9-ffzxJaaYOeQAAABU"]
[Tue Jul 28 21:58:26.290361 2026] [:error] [pid 31659:tid 140254061176576] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config.env"] [unique_id "amkJ4uJ1c9-ffzxJaaYOeQAAABU"]
[Tue Jul 28 21:58:26.290976 2026] [:error] [pid 31659:tid 140254061176576] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.env"] [unique_id "amkJ4uJ1c9-ffzxJaaYOeQAAABU"]
[Tue Jul 28 21:58:26.291035 2026] [:error] [pid 31659:tid 140254061176576] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config.env"] [unique_id "amkJ4uJ1c9-ffzxJaaYOeQAAABU"]
[Tue Jul 28 21:58:26.753756 2026] [:error] [pid 31659:tid 140254229030656] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amkJ4uJ1c9-ffzxJaaYOewAAAAE"]
[Tue Jul 28 21:58:26.754605 2026] [:error] [pid 31659:tid 140254229030656] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amkJ4uJ1c9-ffzxJaaYOewAAAAE"]
[Tue Jul 28 21:58:26.755287 2026] [:error] [pid 31659:tid 140254229030656] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amkJ4uJ1c9-ffzxJaaYOewAAAAE"]
[Tue Jul 28 21:58:26.755344 2026] [:error] [pid 31659:tid 140254229030656] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amkJ4uJ1c9-ffzxJaaYOewAAAAE"]
[Tue Jul 28 21:58:26.755716 2026] [:error] [pid 31659:tid 140254229030656] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amkJ4uJ1c9-ffzxJaaYOewAAAAE"]
[Tue Jul 28 21:58:26.864410 2026] [:error] [pid 31432:tid 140254187067136] [client 162.158.210.88:9853] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amkJ4hTJGXjs973h3x9-sQAAAYY"]
[Tue Jul 28 21:58:26.865216 2026] [:error] [pid 31432:tid 140254187067136] [client 162.158.210.88:9853] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amkJ4hTJGXjs973h3x9-sQAAAYY"]
[Tue Jul 28 21:58:26.865875 2026] [:error] [pid 31432:tid 140254187067136] [client 162.158.210.88:9853] [client 162.158.210.88] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amkJ4hTJGXjs973h3x9-sQAAAYY"]
[Tue Jul 28 21:58:26.865929 2026] [:error] [pid 31432:tid 140254187067136] [client 162.158.210.88:9853] [client 162.158.210.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amkJ4hTJGXjs973h3x9-sQAAAYY"]
[Tue Jul 28 21:58:26.866253 2026] [:error] [pid 31432:tid 140254187067136] [client 162.158.210.88:9853] [client 162.158.210.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amkJ4hTJGXjs973h3x9-sQAAAYY"]
[Tue Jul 28 21:58:26.871089 2026] [:error] [pid 31431:tid 140254061176576] [client 162.158.210.88:9857] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amkJ4lTL6Zxx7wY924HpEwAAAVU"]
[Tue Jul 28 21:58:26.872036 2026] [:error] [pid 31431:tid 140254061176576] [client 162.158.210.88:9857] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amkJ4lTL6Zxx7wY924HpEwAAAVU"]
[Tue Jul 28 21:58:26.872363 2026] [:error] [pid 4873:tid 140254145103616] [client 162.158.210.88:9859] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/./.env"] [unique_id "amkJ4ke-4ohj6ta8_U5l4wAAAIs"]
[Tue Jul 28 21:58:26.872720 2026] [:error] [pid 31431:tid 140254061176576] [client 162.158.210.88:9857] [client 162.158.210.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amkJ4lTL6Zxx7wY924HpEwAAAVU"]
[Tue Jul 28 21:58:26.873000 2026] [:error] [pid 31431:tid 140254061176576] [client 162.158.210.88:9857] [client 162.158.210.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amkJ4lTL6Zxx7wY924HpEwAAAVU"]
[Tue Jul 28 21:58:26.873050 2026] [:error] [pid 4873:tid 140254145103616] [client 162.158.210.88:9859] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amkJ4ke-4ohj6ta8_U5l4wAAAIs"]
[Tue Jul 28 21:58:26.873607 2026] [:error] [pid 4873:tid 140254145103616] [client 162.158.210.88:9859] [client 162.158.210.88] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amkJ4ke-4ohj6ta8_U5l4wAAAIs"]
[Tue Jul 28 21:58:26.873669 2026] [:error] [pid 4873:tid 140254145103616] [client 162.158.210.88:9859] [client 162.158.210.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amkJ4ke-4ohj6ta8_U5l4wAAAIs"]
[Tue Jul 28 21:58:26.874134 2026] [:error] [pid 4873:tid 140254145103616] [client 162.158.210.88:9859] [client 162.158.210.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amkJ4ke-4ohj6ta8_U5l4wAAAIs"]
[Tue Jul 28 21:58:27.026447 2026] [:error] [pid 31659:tid 140254203852544] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amkJ4-J1c9-ffzxJaaYOfAAAAAQ"]
[Tue Jul 28 21:58:27.027267 2026] [:error] [pid 31659:tid 140254203852544] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amkJ4-J1c9-ffzxJaaYOfAAAAAQ"]
[Tue Jul 28 21:58:27.027789 2026] [:error] [pid 31659:tid 140254203852544] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amkJ4-J1c9-ffzxJaaYOfAAAAAQ"]
[Tue Jul 28 21:58:27.028110 2026] [:error] [pid 31659:tid 140254203852544] [client 162.158.210.88:14026] [client 162.158.210.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amkJ4-J1c9-ffzxJaaYOfAAAAAQ"]
[Tue Jul 28 21:58:27.557343 2026] [:error] [pid 31432:tid 140254035998464] [client 162.158.210.88:9853] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amkJ4xTJGXjs973h3x9-tgAAAZg"]
[Tue Jul 28 21:58:27.558082 2026] [:error] [pid 31432:tid 140254035998464] [client 162.158.210.88:9853] [client 162.158.210.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amkJ4xTJGXjs973h3x9-tgAAAZg"]
[Tue Jul 28 21:58:27.558671 2026] [:error] [pid 31432:tid 140254035998464] [client 162.158.210.88:9853] [client 162.158.210.88] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amkJ4xTJGXjs973h3x9-tgAAAZg"]
[Tue Jul 28 21:58:27.558722 2026] [:error] [pid 31432:tid 140254035998464] [client 162.158.210.88:9853] [client 162.158.210.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amkJ4xTJGXjs973h3x9-tgAAAZg"]
[Tue Jul 28 21:58:27.559135 2026] [:error] [pid 31432:tid 140254035998464] [client 162.158.210.88:9853] [client 162.158.210.88] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amkJ4xTJGXjs973h3x9-tgAAAZg"]
[Tue Jul 28 22:19:09.572172 2026] [:error] [pid 31432:tid 140254136710912] [client 172.69.151.108:10111] [client 172.69.151.108] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amkOvRTJGXjs973h3x-7pQAAAYw"]
[Tue Jul 28 22:19:09.573223 2026] [:error] [pid 31432:tid 140254136710912] [client 172.69.151.108:10111] [client 172.69.151.108] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amkOvRTJGXjs973h3x-7pQAAAYw"]
[Tue Jul 28 22:19:09.573892 2026] [:error] [pid 31432:tid 140254136710912] [client 172.69.151.108:10111] [client 172.69.151.108] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amkOvRTJGXjs973h3x-7pQAAAYw"]
[Tue Jul 28 22:19:34.421280 2026] [:error] [pid 31504:tid 140254128318208] [client 172.71.160.195:10981] [client 172.71.160.195] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkO1r6SJayGrl0sDpH5HAAAAc0"]
[Tue Jul 28 22:19:34.422178 2026] [:error] [pid 31504:tid 140254128318208] [client 172.71.160.195:10981] [client 172.71.160.195] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkO1r6SJayGrl0sDpH5HAAAAc0"]
[Tue Jul 28 22:19:34.422676 2026] [:error] [pid 31504:tid 140254128318208] [client 172.71.160.195:10981] [client 172.71.160.195] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkO1r6SJayGrl0sDpH5HAAAAc0"]
[Tue Jul 28 22:19:37.009620 2026] [:error] [pid 31378:tid 140254128318208] [client 172.71.148.71:11188] [client 172.71.148.71] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/keywords"] [unique_id "amkO2Tps7SmFbinM125N6gAAAE0"]
[Tue Jul 28 22:19:37.010351 2026] [:error] [pid 31378:tid 140254128318208] [client 172.71.148.71:11188] [client 172.71.148.71] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/keywords"] [unique_id "amkO2Tps7SmFbinM125N6gAAAE0"]
[Tue Jul 28 22:19:37.010809 2026] [:error] [pid 31378:tid 140254128318208] [client 172.71.148.71:11188] [client 172.71.148.71] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/keywords"] [unique_id "amkO2Tps7SmFbinM125N6gAAAE0"]
[Tue Jul 28 22:19:37.534918 2026] [:error] [pid 31504:tid 140254052783872] [client 172.71.148.78:9550] [client 172.71.148.78] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/author"] [unique_id "amkO2b6SJayGrl0sDpH5MQAAAdY"]
[Tue Jul 28 22:19:37.535823 2026] [:error] [pid 31504:tid 140254052783872] [client 172.71.148.78:9550] [client 172.71.148.78] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/author"] [unique_id "amkO2b6SJayGrl0sDpH5MQAAAdY"]
[Tue Jul 28 22:19:37.536294 2026] [:error] [pid 31504:tid 140254052783872] [client 172.71.148.78:9550] [client 172.71.148.78] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/author"] [unique_id "amkO2b6SJayGrl0sDpH5MQAAAdY"]
[Tue Jul 28 22:19:37.899801 2026] [:error] [pid 31378:tid 140254187067136] [client 172.71.164.40:9914] [client 172.71.164.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/assets/index-o-9Bhaif.js"] [unique_id "amkO2Tps7SmFbinM125N-AAAAEY"]
[Tue Jul 28 22:19:37.900679 2026] [:error] [pid 31378:tid 140254187067136] [client 172.71.164.40:9914] [client 172.71.164.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/assets/index-o-9Bhaif.js"] [unique_id "amkO2Tps7SmFbinM125N-AAAAEY"]
[Tue Jul 28 22:19:37.901163 2026] [:error] [pid 31378:tid 140254187067136] [client 172.71.164.40:9914] [client 172.71.164.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/assets/index-o-9Bhaif.js"] [unique_id "amkO2Tps7SmFbinM125N-AAAAEY"]
[Tue Jul 28 22:28:13.328814 2026] [:error] [pid 4873:tid 140254178674432] [client 104.23.166.83:12236] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkQ3Ue-4ohj6ta8_U52mwAAAIc"]
[Tue Jul 28 22:28:13.329684 2026] [:error] [pid 4873:tid 140254178674432] [client 104.23.166.83:12236] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkQ3Ue-4ohj6ta8_U52mwAAAIc"]
[Tue Jul 28 22:28:13.330385 2026] [:error] [pid 4873:tid 140254178674432] [client 104.23.166.83:12236] [client 104.23.166.83] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkQ3Ue-4ohj6ta8_U52mwAAAIc"]
[Tue Jul 28 22:28:13.330440 2026] [:error] [pid 4873:tid 140254178674432] [client 104.23.166.83:12236] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkQ3Ue-4ohj6ta8_U52mwAAAIc"]
[Tue Jul 28 22:28:13.417446 2026] [:error] [pid 4873:tid 140254195459840] [client 104.23.170.7:9383] [client 104.23.170.7] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amkQ3Ue-4ohj6ta8_U52nAAAAIU"], referer: http://sbf-consultancy.com/
[Tue Jul 28 22:28:13.418177 2026] [:error] [pid 4873:tid 140254195459840] [client 104.23.170.7:9383] [client 104.23.170.7] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amkQ3Ue-4ohj6ta8_U52nAAAAIU"], referer: http://sbf-consultancy.com/
[Tue Jul 28 22:28:13.418828 2026] [:error] [pid 4873:tid 140254195459840] [client 104.23.170.7:9383] [client 104.23.170.7] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amkQ3Ue-4ohj6ta8_U52nAAAAIU"], referer: http://sbf-consultancy.com/
[Tue Jul 28 22:28:13.418888 2026] [:error] [pid 4873:tid 140254195459840] [client 104.23.170.7:9383] [client 104.23.170.7] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amkQ3Ue-4ohj6ta8_U52nAAAAIU"], referer: http://sbf-consultancy.com/
[Tue Jul 28 22:28:13.626541 2026] [:error] [pid 31432:tid 140254119925504] [client 104.23.170.163:9297] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkQ3RTJGXjs973h3x_TjwAAAY4"]
[Tue Jul 28 22:28:13.627444 2026] [:error] [pid 31432:tid 140254119925504] [client 104.23.170.163:9297] [client 104.23.170.163] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkQ3RTJGXjs973h3x_TjwAAAY4"]
[Tue Jul 28 22:28:13.628289 2026] [:error] [pid 31432:tid 140254119925504] [client 104.23.170.163:9297] [client 104.23.170.163] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkQ3RTJGXjs973h3x_TjwAAAY4"]
[Tue Jul 28 22:28:13.628368 2026] [:error] [pid 31432:tid 140254119925504] [client 104.23.170.163:9297] [client 104.23.170.163] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkQ3RTJGXjs973h3x_TjwAAAY4"]
[Tue Jul 28 22:28:13.891618 2026] [:error] [pid 31659:tid 140254187067136] [client 104.23.170.6:12866] [client 104.23.170.6] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amkQ3eJ1c9-ffzxJaaYnhQAAAAY"], referer: https://sbf-consultancy.com/
[Tue Jul 28 22:28:13.892604 2026] [:error] [pid 31659:tid 140254187067136] [client 104.23.170.6:12866] [client 104.23.170.6] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amkQ3eJ1c9-ffzxJaaYnhQAAAAY"], referer: https://sbf-consultancy.com/
[Tue Jul 28 22:28:13.893450 2026] [:error] [pid 31659:tid 140254187067136] [client 104.23.170.6:12866] [client 104.23.170.6] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amkQ3eJ1c9-ffzxJaaYnhQAAAAY"], referer: https://sbf-consultancy.com/
[Tue Jul 28 22:28:13.893518 2026] [:error] [pid 31659:tid 140254187067136] [client 104.23.170.6:12866] [client 104.23.170.6] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/favicon.ico"] [unique_id "amkQ3eJ1c9-ffzxJaaYnhQAAAAY"], referer: https://sbf-consultancy.com/
[Tue Jul 28 22:41:27.484684 2026] [:error] [pid 31432:tid 140254052783872] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amkT9xTJGXjs973h3x_wWgAAAZY"]
[Tue Jul 28 22:41:27.516433 2026] [:error] [pid 31432:tid 140254052783872] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amkT9xTJGXjs973h3x_wWgAAAZY"]
[Tue Jul 28 22:41:27.516866 2026] [:error] [pid 31432:tid 140254052783872] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-login.php"] [unique_id "amkT9xTJGXjs973h3x_wWgAAAZY"]
[Tue Jul 28 22:41:27.816636 2026] [:error] [pid 31432:tid 140254086354688] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/"] [unique_id "amkT9xTJGXjs973h3x_wXAAAAZI"]
[Tue Jul 28 22:41:27.817571 2026] [:error] [pid 31432:tid 140254086354688] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/"] [unique_id "amkT9xTJGXjs973h3x_wXAAAAZI"]
[Tue Jul 28 22:41:27.818073 2026] [:error] [pid 31432:tid 140254086354688] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/"] [unique_id "amkT9xTJGXjs973h3x_wXAAAAZI"]
[Tue Jul 28 22:41:28.134857 2026] [:error] [pid 31432:tid 140254170281728] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkT-BTJGXjs973h3x_wYAAAAYg"]
[Tue Jul 28 22:41:28.135847 2026] [:error] [pid 31432:tid 140254170281728] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkT-BTJGXjs973h3x_wYAAAAYg"]
[Tue Jul 28 22:41:28.136419 2026] [:error] [pid 31432:tid 140254170281728] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkT-BTJGXjs973h3x_wYAAAAYg"]
[Tue Jul 28 22:41:28.432115 2026] [:error] [pid 31432:tid 140254103140096] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkT-BTJGXjs973h3x_wZAAAAZA"]
[Tue Jul 28 22:41:28.432655 2026] [:error] [pid 31432:tid 140254103140096] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkT-BTJGXjs973h3x_wZAAAAZA"]
[Tue Jul 28 22:41:28.432991 2026] [:error] [pid 31432:tid 140254103140096] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Found 3 byte(s) in ARGS:rest_route outside range: 38,44-46,48-58,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1501"] [id "920273"] [msg "Invalid character in request (outside of very strict set)"] [data "ARGS:rest_route=/wp/v2/users"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkT-BTJGXjs973h3x_wZAAAAZA"]
[Tue Jul 28 22:41:28.433035 2026] [:error] [pid 31432:tid 140254103140096] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkT-BTJGXjs973h3x_wZAAAAZA"]
[Tue Jul 28 22:41:28.733454 2026] [:error] [pid 31432:tid 140254052783872] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/feed"] [unique_id "amkT-BTJGXjs973h3x_wZgAAAZY"]
[Tue Jul 28 22:41:28.734137 2026] [:error] [pid 31432:tid 140254052783872] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/feed"] [unique_id "amkT-BTJGXjs973h3x_wZgAAAZY"]
[Tue Jul 28 22:41:28.734467 2026] [:error] [pid 31432:tid 140254052783872] [client 172.71.191.9:9635] [client 172.71.191.9] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/feed"] [unique_id "amkT-BTJGXjs973h3x_wZgAAAZY"]
[Tue Jul 28 22:54:19.117718 2026] [:error] [pid 31504:tid 140254035998464] [client 172.71.194.241:11808] [client 172.71.194.241] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkW-76SJayGrl0sDpEoyAAAAdg"]
[Tue Jul 28 22:54:19.118422 2026] [:error] [pid 31504:tid 140254035998464] [client 172.71.194.241:11808] [client 172.71.194.241] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkW-76SJayGrl0sDpEoyAAAAdg"]
[Tue Jul 28 22:54:19.118794 2026] [:error] [pid 31504:tid 140254035998464] [client 172.71.194.241:11808] [client 172.71.194.241] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkW-76SJayGrl0sDpEoyAAAAdg"]
[Tue Jul 28 22:55:09.841966 2026] [:error] [pid 4873:tid 140254111532800] [client 104.22.100.89:12654] [client 104.22.100.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkXLUe-4ohj6ta8_U6FvgAAAI8"]
[Tue Jul 28 22:55:09.842606 2026] [:error] [pid 4873:tid 140254111532800] [client 104.22.100.89:12654] [client 104.22.100.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkXLUe-4ohj6ta8_U6FvgAAAI8"]
[Tue Jul 28 22:55:09.843167 2026] [:error] [pid 4873:tid 140254111532800] [client 104.22.100.89:12654] [client 104.22.100.89] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua=\\x22Not)A;Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22138\\x22, \\x22HeadlessChrome\\x22;v=\\x22138\\x22"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkXLUe-4ohj6ta8_U6FvgAAAI8"]
[Tue Jul 28 22:55:09.843232 2026] [:error] [pid 4873:tid 140254111532800] [client 104.22.100.89:12654] [client 104.22.100.89] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkXLUe-4ohj6ta8_U6FvgAAAI8"]
[Tue Jul 28 22:55:09.843265 2026] [:error] [pid 4873:tid 140254111532800] [client 104.22.100.89:12654] [client 104.22.100.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkXLUe-4ohj6ta8_U6FvgAAAI8"]
[Tue Jul 28 23:00:11.651084 2026] [:error] [pid 31432:tid 140254103140096] [client 104.23.243.19:11316] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amkYWxTJGXjs973h3x8PuAAAAZA"]
[Tue Jul 28 23:00:11.652216 2026] [:error] [pid 31432:tid 140254103140096] [client 104.23.243.19:11316] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amkYWxTJGXjs973h3x8PuAAAAZA"]
[Tue Jul 28 23:00:11.652738 2026] [:error] [pid 31432:tid 140254103140096] [client 104.23.243.19:11316] [client 104.23.243.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amkYWxTJGXjs973h3x8PuAAAAZA"]
[Tue Jul 28 23:00:12.093376 2026] [:error] [pid 31378:tid 140254187067136] [client 104.23.197.76:13855] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amkYXDps7SmFbinM125m1AAAAEY"]
[Tue Jul 28 23:00:12.094377 2026] [:error] [pid 31378:tid 140254187067136] [client 104.23.197.76:13855] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amkYXDps7SmFbinM125m1AAAAEY"]
[Tue Jul 28 23:00:12.094970 2026] [:error] [pid 31378:tid 140254187067136] [client 104.23.197.76:13855] [client 104.23.197.76] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amkYXDps7SmFbinM125m1AAAAEY"]
[Tue Jul 28 23:50:18.715017 2026] [:error] [pid 31431:tid 140254237423360] [client 172.70.208.128:11484] [client 172.70.208.128] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkkGlTL6Zxx7wY924EZUgAAAUA"]
[Tue Jul 28 23:50:18.776388 2026] [:error] [pid 31431:tid 140254237423360] [client 172.70.208.128:11484] [client 172.70.208.128] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkkGlTL6Zxx7wY924EZUgAAAUA"]
[Tue Jul 28 23:50:18.777072 2026] [:error] [pid 31431:tid 140254237423360] [client 172.70.208.128:11484] [client 172.70.208.128] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkkGlTL6Zxx7wY924EZUgAAAUA"]
[Tue Jul 28 23:50:22.418464 2026] [:error] [pid 21037:tid 140254052783872] [client 172.71.124.105:11208] [client 172.71.124.105] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkkHtTKmBoMa_7ShhY00wAAARY"]
[Tue Jul 28 23:50:22.419303 2026] [:error] [pid 21037:tid 140254052783872] [client 172.71.124.105:11208] [client 172.71.124.105] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkkHtTKmBoMa_7ShhY00wAAARY"]
[Tue Jul 28 23:50:22.419800 2026] [:error] [pid 21037:tid 140254052783872] [client 172.71.124.105:11208] [client 172.71.124.105] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amkkHtTKmBoMa_7ShhY00wAAARY"]
[Wed Jul 29 00:03:56.426095 2026] [:error] [pid 20768:tid 140254161889024] [client 104.23.223.55:14091] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amknTJjwFipIdqsHCMbfigAAAMk"]
[Wed Jul 29 00:03:56.427319 2026] [:error] [pid 20768:tid 140254161889024] [client 104.23.223.55:14091] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amknTJjwFipIdqsHCMbfigAAAMk"]
[Wed Jul 29 00:03:56.428006 2026] [:error] [pid 20768:tid 140254161889024] [client 104.23.223.55:14091] [client 104.23.223.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amknTJjwFipIdqsHCMbfigAAAMk"]
[Wed Jul 29 00:25:22.544526 2026] [:error] [pid 31659:tid 140254161889024] [client 104.23.166.54:10443] [client 104.23.166.54] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/aws.env"] [unique_id "amksUuJ1c9-ffzxJaaZxoQAAAAk"]
[Wed Jul 29 00:25:22.545638 2026] [:error] [pid 31659:tid 140254161889024] [client 104.23.166.54:10443] [client 104.23.166.54] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/aws.env"] [unique_id "amksUuJ1c9-ffzxJaaZxoQAAAAk"]
[Wed Jul 29 00:25:22.546166 2026] [:error] [pid 31659:tid 140254161889024] [client 104.23.166.54:10443] [client 104.23.166.54] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/aws.env"] [unique_id "amksUuJ1c9-ffzxJaaZxoQAAAAk"]
[Wed Jul 29 00:25:22.546310 2026] [:error] [pid 31659:tid 140254161889024] [client 104.23.166.54:10443] [client 104.23.166.54] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/aws.env"] [unique_id "amksUuJ1c9-ffzxJaaZxoQAAAAk"]
[Wed Jul 29 00:25:22.547435 2026] [:error] [pid 31432:tid 140254153496320] [client 104.23.170.178:11285] [client 104.23.170.178] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amksUhTJGXjs973h3x-W5wAAAYo"]
[Wed Jul 29 00:25:22.548260 2026] [:error] [pid 31432:tid 140254153496320] [client 104.23.170.178:11285] [client 104.23.170.178] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amksUhTJGXjs973h3x-W5wAAAYo"]
[Wed Jul 29 00:25:22.548701 2026] [:error] [pid 31432:tid 140254153496320] [client 104.23.170.178:11285] [client 104.23.170.178] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amksUhTJGXjs973h3x-W5wAAAYo"]
[Wed Jul 29 00:25:22.548805 2026] [:error] [pid 31432:tid 140254153496320] [client 104.23.170.178:11285] [client 104.23.170.178] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amksUhTJGXjs973h3x-W5wAAAYo"]
[Wed Jul 29 00:25:22.549057 2026] [:error] [pid 31432:tid 140254153496320] [client 104.23.170.178:11285] [client 104.23.170.178] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "amksUhTJGXjs973h3x-W5wAAAYo"]
[Wed Jul 29 00:25:22.551373 2026] [:error] [pid 21037:tid 140254220637952] [client 141.101.76.184:12693] [client 141.101.76.184] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amksUtTKmBoMa_7ShhZ1ygAAAQI"]
[Wed Jul 29 00:25:22.552047 2026] [:error] [pid 21037:tid 140254220637952] [client 141.101.76.184:12693] [client 141.101.76.184] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amksUtTKmBoMa_7ShhZ1ygAAAQI"]
[Wed Jul 29 00:25:22.552394 2026] [:error] [pid 21037:tid 140254220637952] [client 141.101.76.184:12693] [client 141.101.76.184] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amksUtTKmBoMa_7ShhZ1ygAAAQI"]
[Wed Jul 29 00:25:22.552506 2026] [:error] [pid 21037:tid 140254220637952] [client 141.101.76.184:12693] [client 141.101.76.184] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amksUtTKmBoMa_7ShhZ1ygAAAQI"]
[Wed Jul 29 00:25:22.552672 2026] [:error] [pid 21037:tid 140254220637952] [client 141.101.76.184:12693] [client 141.101.76.184] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amksUtTKmBoMa_7ShhZ1ygAAAQI"]
[Wed Jul 29 00:52:04.295583 2026] [:error] [pid 20768:tid 140254103140096] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amkylJjwFipIdqsHCMYUwwAAANA"]
[Wed Jul 29 00:52:04.298327 2026] [:error] [pid 20768:tid 140254103140096] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amkylJjwFipIdqsHCMYUwwAAANA"]
[Wed Jul 29 00:52:04.298899 2026] [:error] [pid 20768:tid 140254103140096] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amkylJjwFipIdqsHCMYUwwAAANA"]
[Wed Jul 29 00:52:04.299149 2026] [:error] [pid 20768:tid 140254103140096] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amkylJjwFipIdqsHCMYUwwAAANA"]
[Wed Jul 29 00:52:05.578406 2026] [:error] [pid 20768:tid 140254128318208] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amkylZjwFipIdqsHCMYUyAAAAM0"]
[Wed Jul 29 00:52:05.579193 2026] [:error] [pid 20768:tid 140254128318208] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amkylZjwFipIdqsHCMYUyAAAAM0"]
[Wed Jul 29 00:52:05.579699 2026] [:error] [pid 20768:tid 140254128318208] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amkylZjwFipIdqsHCMYUyAAAAM0"]
[Wed Jul 29 00:52:05.579944 2026] [:error] [pid 20768:tid 140254128318208] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amkylZjwFipIdqsHCMYUyAAAAM0"]
[Wed Jul 29 00:52:05.580163 2026] [:error] [pid 21037:tid 140254128318208] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amkyldTKmBoMa_7ShhakywAAAQ0"]
[Wed Jul 29 00:52:05.580721 2026] [:error] [pid 21037:tid 140254128318208] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amkyldTKmBoMa_7ShhakywAAAQ0"]
[Wed Jul 29 00:52:05.581144 2026] [:error] [pid 21037:tid 140254128318208] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amkyldTKmBoMa_7ShhakywAAAQ0"]
[Wed Jul 29 00:52:05.581598 2026] [:error] [pid 21037:tid 140254128318208] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "amkyldTKmBoMa_7ShhakywAAAQ0"]
[Wed Jul 29 00:52:06.425010 2026] [:error] [pid 20768:tid 140254069569280] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amkylpjwFipIdqsHCMYUzgAAANQ"]
[Wed Jul 29 00:52:06.425936 2026] [:error] [pid 20768:tid 140254069569280] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amkylpjwFipIdqsHCMYUzgAAANQ"]
[Wed Jul 29 00:52:06.426446 2026] [:error] [pid 20768:tid 140254069569280] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amkylpjwFipIdqsHCMYUzgAAANQ"]
[Wed Jul 29 00:52:06.426725 2026] [:error] [pid 20768:tid 140254069569280] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amkylpjwFipIdqsHCMYUzgAAANQ"]
[Wed Jul 29 00:52:06.514586 2026] [:error] [pid 21037:tid 140254195459840] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amkyltTKmBoMa_7Shhak1gAAAQU"]
[Wed Jul 29 00:52:06.515348 2026] [:error] [pid 21037:tid 140254195459840] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amkyltTKmBoMa_7Shhak1gAAAQU"]
[Wed Jul 29 00:52:06.515820 2026] [:error] [pid 21037:tid 140254195459840] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amkyltTKmBoMa_7Shhak1gAAAQU"]
[Wed Jul 29 00:52:06.516067 2026] [:error] [pid 21037:tid 140254195459840] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/HEAD"] [unique_id "amkyltTKmBoMa_7Shhak1gAAAQU"]
[Wed Jul 29 00:52:07.275305 2026] [:error] [pid 20768:tid 140254103140096] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amkyl5jwFipIdqsHCMYU0QAAANA"]
[Wed Jul 29 00:52:07.275899 2026] [:error] [pid 20768:tid 140254103140096] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amkyl5jwFipIdqsHCMYU0QAAANA"]
[Wed Jul 29 00:52:07.276254 2026] [:error] [pid 20768:tid 140254103140096] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amkyl5jwFipIdqsHCMYU0QAAANA"]
[Wed Jul 29 00:52:07.276401 2026] [:error] [pid 20768:tid 140254103140096] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amkyl5jwFipIdqsHCMYU0QAAANA"]
[Wed Jul 29 00:52:07.485029 2026] [:error] [pid 21037:tid 140254229030656] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amkyl9TKmBoMa_7Shhak3wAAAQE"]
[Wed Jul 29 00:52:07.486031 2026] [:error] [pid 21037:tid 140254229030656] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amkyl9TKmBoMa_7Shhak3wAAAQE"]
[Wed Jul 29 00:52:07.486594 2026] [:error] [pid 21037:tid 140254229030656] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amkyl9TKmBoMa_7Shhak3wAAAQE"]
[Wed Jul 29 00:52:07.486879 2026] [:error] [pid 21037:tid 140254229030656] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amkyl9TKmBoMa_7Shhak3wAAAQE"]
[Wed Jul 29 00:52:08.788290 2026] [:error] [pid 20768:tid 140254195459840] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amkymJjwFipIdqsHCMYU3AAAAMU"]
[Wed Jul 29 00:52:08.789093 2026] [:error] [pid 20768:tid 140254195459840] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amkymJjwFipIdqsHCMYU3AAAAMU"]
[Wed Jul 29 00:52:08.789513 2026] [:error] [pid 20768:tid 140254195459840] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amkymJjwFipIdqsHCMYU3AAAAMU"]
[Wed Jul 29 00:52:08.789788 2026] [:error] [pid 20768:tid 140254195459840] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amkymJjwFipIdqsHCMYU3AAAAMU"]
[Wed Jul 29 00:52:08.919418 2026] [:error] [pid 21037:tid 140254153496320] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amkymNTKmBoMa_7Shhak8wAAAQo"]
[Wed Jul 29 00:52:08.920220 2026] [:error] [pid 21037:tid 140254153496320] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amkymNTKmBoMa_7Shhak8wAAAQo"]
[Wed Jul 29 00:52:08.920715 2026] [:error] [pid 21037:tid 140254153496320] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amkymNTKmBoMa_7Shhak8wAAAQo"]
[Wed Jul 29 00:52:08.920957 2026] [:error] [pid 21037:tid 140254153496320] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amkymNTKmBoMa_7Shhak8wAAAQo"]
[Wed Jul 29 00:52:09.632584 2026] [:error] [pid 20768:tid 140254220637952] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amkymZjwFipIdqsHCMYU4QAAAMI"]
[Wed Jul 29 00:52:09.633376 2026] [:error] [pid 20768:tid 140254220637952] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amkymZjwFipIdqsHCMYU4QAAAMI"]
[Wed Jul 29 00:52:09.633905 2026] [:error] [pid 20768:tid 140254220637952] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amkymZjwFipIdqsHCMYU4QAAAMI"]
[Wed Jul 29 00:52:09.634151 2026] [:error] [pid 20768:tid 140254220637952] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amkymZjwFipIdqsHCMYU4QAAAMI"]
[Wed Jul 29 00:52:09.754920 2026] [:error] [pid 21037:tid 140254187067136] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amkymdTKmBoMa_7Shhak_AAAAQY"]
[Wed Jul 29 00:52:09.755723 2026] [:error] [pid 21037:tid 140254187067136] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amkymdTKmBoMa_7Shhak_AAAAQY"]
[Wed Jul 29 00:52:09.756194 2026] [:error] [pid 21037:tid 140254187067136] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amkymdTKmBoMa_7Shhak_AAAAQY"]
[Wed Jul 29 00:52:09.756454 2026] [:error] [pid 21037:tid 140254187067136] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amkymdTKmBoMa_7Shhak_AAAAQY"]
[Wed Jul 29 00:52:10.677393 2026] [:error] [pid 20768:tid 140254128318208] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amkympjwFipIdqsHCMYU5gAAAM0"]
[Wed Jul 29 00:52:10.678179 2026] [:error] [pid 20768:tid 140254128318208] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amkympjwFipIdqsHCMYU5gAAAM0"]
[Wed Jul 29 00:52:10.678642 2026] [:error] [pid 20768:tid 140254128318208] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amkympjwFipIdqsHCMYU5gAAAM0"]
[Wed Jul 29 00:52:10.678876 2026] [:error] [pid 20768:tid 140254128318208] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amkympjwFipIdqsHCMYU5gAAAM0"]
[Wed Jul 29 00:52:10.755929 2026] [:error] [pid 21037:tid 140254229030656] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amkymtTKmBoMa_7ShhalBwAAAQE"]
[Wed Jul 29 00:52:10.757012 2026] [:error] [pid 21037:tid 140254229030656] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amkymtTKmBoMa_7ShhalBwAAAQE"]
[Wed Jul 29 00:52:10.757578 2026] [:error] [pid 21037:tid 140254229030656] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amkymtTKmBoMa_7ShhalBwAAAQE"]
[Wed Jul 29 00:52:10.757810 2026] [:error] [pid 21037:tid 140254229030656] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amkymtTKmBoMa_7ShhalBwAAAQE"]
[Wed Jul 29 00:52:11.819096 2026] [:error] [pid 20768:tid 140254170281728] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amkym5jwFipIdqsHCMYU7QAAAMg"]
[Wed Jul 29 00:52:11.820056 2026] [:error] [pid 20768:tid 140254170281728] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amkym5jwFipIdqsHCMYU7QAAAMg"]
[Wed Jul 29 00:52:11.820601 2026] [:error] [pid 20768:tid 140254170281728] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amkym5jwFipIdqsHCMYU7QAAAMg"]
[Wed Jul 29 00:52:11.820865 2026] [:error] [pid 20768:tid 140254170281728] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amkym5jwFipIdqsHCMYU7QAAAMg"]
[Wed Jul 29 00:52:12.745862 2026] [:error] [pid 20768:tid 140254153496320] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amkynJjwFipIdqsHCMYU8gAAAMo"]
[Wed Jul 29 00:52:12.749894 2026] [:error] [pid 20768:tid 140254153496320] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amkynJjwFipIdqsHCMYU8gAAAMo"]
[Wed Jul 29 00:52:12.750376 2026] [:error] [pid 20768:tid 140254153496320] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amkynJjwFipIdqsHCMYU8gAAAMo"]
[Wed Jul 29 00:52:12.750632 2026] [:error] [pid 20768:tid 140254153496320] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amkynJjwFipIdqsHCMYU8gAAAMo"]
[Wed Jul 29 00:52:12.848321 2026] [:error] [pid 21037:tid 140254086354688] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amkynNTKmBoMa_7ShhalGQAAARI"]
[Wed Jul 29 00:52:12.849017 2026] [:error] [pid 21037:tid 140254086354688] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amkynNTKmBoMa_7ShhalGQAAARI"]
[Wed Jul 29 00:52:12.849399 2026] [:error] [pid 21037:tid 140254086354688] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amkynNTKmBoMa_7ShhalGQAAARI"]
[Wed Jul 29 00:52:12.849653 2026] [:error] [pid 21037:tid 140254086354688] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amkynNTKmBoMa_7ShhalGQAAARI"]
[Wed Jul 29 00:52:13.494827 2026] [:error] [pid 20768:tid 140254195459840] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amkynZjwFipIdqsHCMYU9wAAAMU"]
[Wed Jul 29 00:52:13.495477 2026] [:error] [pid 20768:tid 140254195459840] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amkynZjwFipIdqsHCMYU9wAAAMU"]
[Wed Jul 29 00:52:13.495898 2026] [:error] [pid 20768:tid 140254195459840] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amkynZjwFipIdqsHCMYU9wAAAMU"]
[Wed Jul 29 00:52:13.496078 2026] [:error] [pid 20768:tid 140254195459840] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amkynZjwFipIdqsHCMYU9wAAAMU"]
[Wed Jul 29 00:52:13.723958 2026] [:error] [pid 21037:tid 140254119925504] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amkyndTKmBoMa_7ShhalIgAAAQ4"]
[Wed Jul 29 00:52:13.725052 2026] [:error] [pid 21037:tid 140254119925504] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amkyndTKmBoMa_7ShhalIgAAAQ4"]
[Wed Jul 29 00:52:13.725658 2026] [:error] [pid 21037:tid 140254119925504] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amkyndTKmBoMa_7ShhalIgAAAQ4"]
[Wed Jul 29 00:52:13.725965 2026] [:error] [pid 21037:tid 140254119925504] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amkyndTKmBoMa_7ShhalIgAAAQ4"]
[Wed Jul 29 00:52:14.497484 2026] [:error] [pid 20768:tid 140254145103616] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amkynpjwFipIdqsHCMYU_wAAAMs"]
[Wed Jul 29 00:52:14.498197 2026] [:error] [pid 20768:tid 140254145103616] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amkynpjwFipIdqsHCMYU_wAAAMs"]
[Wed Jul 29 00:52:14.498620 2026] [:error] [pid 20768:tid 140254145103616] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amkynpjwFipIdqsHCMYU_wAAAMs"]
[Wed Jul 29 00:52:14.498795 2026] [:error] [pid 20768:tid 140254145103616] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.live"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amkynpjwFipIdqsHCMYU_wAAAMs"]
[Wed Jul 29 00:52:14.635008 2026] [:error] [pid 21037:tid 140254212245248] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amkyntTKmBoMa_7ShhalKgAAAQM"]
[Wed Jul 29 00:52:14.635846 2026] [:error] [pid 21037:tid 140254212245248] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amkyntTKmBoMa_7ShhalKgAAAQM"]
[Wed Jul 29 00:52:14.636331 2026] [:error] [pid 21037:tid 140254212245248] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amkyntTKmBoMa_7ShhalKgAAAQM"]
[Wed Jul 29 00:52:14.636591 2026] [:error] [pid 21037:tid 140254212245248] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amkyntTKmBoMa_7ShhalKgAAAQM"]
[Wed Jul 29 00:52:15.448789 2026] [:error] [pid 20768:tid 140254128318208] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amkyn5jwFipIdqsHCMYVBQAAAM0"]
[Wed Jul 29 00:52:15.449643 2026] [:error] [pid 20768:tid 140254128318208] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amkyn5jwFipIdqsHCMYVBQAAAM0"]
[Wed Jul 29 00:52:15.450239 2026] [:error] [pid 20768:tid 140254128318208] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amkyn5jwFipIdqsHCMYVBQAAAM0"]
[Wed Jul 29 00:52:15.450534 2026] [:error] [pid 20768:tid 140254128318208] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amkyn5jwFipIdqsHCMYVBQAAAM0"]
[Wed Jul 29 00:52:16.707415 2026] [:error] [pid 20768:tid 140254161889024] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amkyoJjwFipIdqsHCMYVDgAAAMk"]
[Wed Jul 29 00:52:16.708169 2026] [:error] [pid 20768:tid 140254161889024] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amkyoJjwFipIdqsHCMYVDgAAAMk"]
[Wed Jul 29 00:52:16.708609 2026] [:error] [pid 20768:tid 140254161889024] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amkyoJjwFipIdqsHCMYVDgAAAMk"]
[Wed Jul 29 00:52:16.708787 2026] [:error] [pid 20768:tid 140254161889024] [client 172.71.183.36:11936] [client 172.71.183.36] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amkyoJjwFipIdqsHCMYVDgAAAMk"]
[Wed Jul 29 00:52:16.795803 2026] [:error] [pid 21037:tid 140254035998464] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amkyoNTKmBoMa_7ShhalPQAAARg"]
[Wed Jul 29 00:52:16.796376 2026] [:error] [pid 21037:tid 140254035998464] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amkyoNTKmBoMa_7ShhalPQAAARg"]
[Wed Jul 29 00:52:16.796828 2026] [:error] [pid 21037:tid 140254035998464] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amkyoNTKmBoMa_7ShhalPQAAARg"]
[Wed Jul 29 00:52:16.797060 2026] [:error] [pid 21037:tid 140254035998464] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amkyoNTKmBoMa_7ShhalPQAAARg"]
[Wed Jul 29 00:52:17.604218 2026] [:error] [pid 21037:tid 140254061176576] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amkyodTKmBoMa_7ShhalQwAAARU"]
[Wed Jul 29 00:52:17.604754 2026] [:error] [pid 21037:tid 140254061176576] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amkyodTKmBoMa_7ShhalQwAAARU"]
[Wed Jul 29 00:52:17.605133 2026] [:error] [pid 21037:tid 140254061176576] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amkyodTKmBoMa_7ShhalQwAAARU"]
[Wed Jul 29 00:52:17.605352 2026] [:error] [pid 21037:tid 140254061176576] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.live"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amkyodTKmBoMa_7ShhalQwAAARU"]
[Wed Jul 29 00:52:18.440525 2026] [:error] [pid 21037:tid 140254077961984] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amkyotTKmBoMa_7ShhalSQAAARM"]
[Wed Jul 29 00:52:18.441321 2026] [:error] [pid 21037:tid 140254077961984] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amkyotTKmBoMa_7ShhalSQAAARM"]
[Wed Jul 29 00:52:18.441838 2026] [:error] [pid 21037:tid 140254077961984] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amkyotTKmBoMa_7ShhalSQAAARM"]
[Wed Jul 29 00:52:18.442083 2026] [:error] [pid 21037:tid 140254077961984] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amkyotTKmBoMa_7ShhalSQAAARM"]
[Wed Jul 29 00:52:19.260682 2026] [:error] [pid 31659:tid 140254086354688] [client 104.23.168.4:10452] [client 104.23.168.4] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amkyo-J1c9-ffzxJaaZ5XgAAABI"]
[Wed Jul 29 00:52:19.261617 2026] [:error] [pid 31659:tid 140254086354688] [client 104.23.168.4:10452] [client 104.23.168.4] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amkyo-J1c9-ffzxJaaZ5XgAAABI"]
[Wed Jul 29 00:52:19.262117 2026] [:error] [pid 31659:tid 140254086354688] [client 104.23.168.4:10452] [client 104.23.168.4] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amkyo-J1c9-ffzxJaaZ5XgAAABI"]
[Wed Jul 29 00:52:19.262342 2026] [:error] [pid 31659:tid 140254086354688] [client 104.23.168.4:10452] [client 104.23.168.4] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amkyo-J1c9-ffzxJaaZ5XgAAABI"]
[Wed Jul 29 00:52:19.466928 2026] [:error] [pid 21037:tid 140254111532800] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amkyo9TKmBoMa_7ShhalTwAAAQ8"]
[Wed Jul 29 00:52:19.467915 2026] [:error] [pid 21037:tid 140254111532800] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amkyo9TKmBoMa_7ShhalTwAAAQ8"]
[Wed Jul 29 00:52:19.468424 2026] [:error] [pid 21037:tid 140254111532800] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amkyo9TKmBoMa_7ShhalTwAAAQ8"]
[Wed Jul 29 00:52:19.468714 2026] [:error] [pid 21037:tid 140254111532800] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amkyo9TKmBoMa_7ShhalTwAAAQ8"]
[Wed Jul 29 00:52:20.405902 2026] [:error] [pid 31432:tid 140254069569280] [client 104.23.168.14:13774] [client 104.23.168.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amkypBTJGXjs973h3x-jdwAAAZQ"]
[Wed Jul 29 00:52:20.406862 2026] [:error] [pid 31432:tid 140254069569280] [client 104.23.168.14:13774] [client 104.23.168.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amkypBTJGXjs973h3x-jdwAAAZQ"]
[Wed Jul 29 00:52:20.407362 2026] [:error] [pid 31432:tid 140254069569280] [client 104.23.168.14:13774] [client 104.23.168.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amkypBTJGXjs973h3x-jdwAAAZQ"]
[Wed Jul 29 00:52:20.407633 2026] [:error] [pid 31432:tid 140254069569280] [client 104.23.168.14:13774] [client 104.23.168.14] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amkypBTJGXjs973h3x-jdwAAAZQ"]
[Wed Jul 29 00:52:21.807501 2026] [:error] [pid 21037:tid 140254220637952] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env"] [unique_id "amkypdTKmBoMa_7ShhalWwAAAQI"]
[Wed Jul 29 00:52:21.808201 2026] [:error] [pid 21037:tid 140254220637952] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env"] [unique_id "amkypdTKmBoMa_7ShhalWwAAAQI"]
[Wed Jul 29 00:52:21.808644 2026] [:error] [pid 21037:tid 140254220637952] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/env"] [unique_id "amkypdTKmBoMa_7ShhalWwAAAQI"]
[Wed Jul 29 00:52:22.783576 2026] [:error] [pid 21037:tid 140254035998464] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amkyptTKmBoMa_7ShhalYgAAARg"]
[Wed Jul 29 00:52:22.784345 2026] [:error] [pid 21037:tid 140254035998464] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amkyptTKmBoMa_7ShhalYgAAARg"]
[Wed Jul 29 00:52:22.784840 2026] [:error] [pid 21037:tid 140254035998464] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amkyptTKmBoMa_7ShhalYgAAARg"]
[Wed Jul 29 00:52:22.785085 2026] [:error] [pid 21037:tid 140254035998464] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amkyptTKmBoMa_7ShhalYgAAARg"]
[Wed Jul 29 00:52:24.050861 2026] [:error] [pid 21037:tid 140254178674432] [client 172.70.46.164:9314] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amkyqNTKmBoMa_7ShhalagAAAQc"]
[Wed Jul 29 00:52:24.051624 2026] [:error] [pid 21037:tid 140254178674432] [client 172.70.46.164:9314] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amkyqNTKmBoMa_7ShhalagAAAQc"]
[Wed Jul 29 00:52:24.052075 2026] [:error] [pid 21037:tid 140254178674432] [client 172.70.46.164:9314] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amkyqNTKmBoMa_7ShhalagAAAQc"]
[Wed Jul 29 00:52:24.052291 2026] [:error] [pid 21037:tid 140254178674432] [client 172.70.46.164:9314] [client 172.70.46.164] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amkyqNTKmBoMa_7ShhalagAAAQc"]
[Wed Jul 29 00:52:24.380823 2026] [:error] [pid 21037:tid 140254052783872] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amkyqNTKmBoMa_7ShhalbgAAARY"]
[Wed Jul 29 00:52:24.381540 2026] [:error] [pid 21037:tid 140254052783872] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amkyqNTKmBoMa_7ShhalbgAAARY"]
[Wed Jul 29 00:52:24.381974 2026] [:error] [pid 21037:tid 140254052783872] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amkyqNTKmBoMa_7ShhalbgAAARY"]
[Wed Jul 29 00:52:24.382131 2026] [:error] [pid 21037:tid 140254052783872] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amkyqNTKmBoMa_7ShhalbgAAARY"]
[Wed Jul 29 00:52:24.871953 2026] [:error] [pid 21037:tid 140254187067136] [client 172.70.47.6:12519] [client 172.70.47.6] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amkyqNTKmBoMa_7ShhalcQAAAQY"]
[Wed Jul 29 00:52:24.872543 2026] [:error] [pid 21037:tid 140254187067136] [client 172.70.47.6:12519] [client 172.70.47.6] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amkyqNTKmBoMa_7ShhalcQAAAQY"]
[Wed Jul 29 00:52:24.872918 2026] [:error] [pid 21037:tid 140254187067136] [client 172.70.47.6:12519] [client 172.70.47.6] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amkyqNTKmBoMa_7ShhalcQAAAQY"]
[Wed Jul 29 00:52:24.873130 2026] [:error] [pid 21037:tid 140254187067136] [client 172.70.47.6:12519] [client 172.70.47.6] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amkyqNTKmBoMa_7ShhalcQAAAQY"]
[Wed Jul 29 00:52:25.589422 2026] [:error] [pid 21037:tid 140254195459840] [client 172.70.46.164:9314] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/functions/.env"] [unique_id "amkyqdTKmBoMa_7ShhaldgAAAQU"]
[Wed Jul 29 00:52:25.590094 2026] [:error] [pid 21037:tid 140254195459840] [client 172.70.46.164:9314] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/functions/.env"] [unique_id "amkyqdTKmBoMa_7ShhaldgAAAQU"]
[Wed Jul 29 00:52:25.590446 2026] [:error] [pid 21037:tid 140254195459840] [client 172.70.46.164:9314] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/functions/.env"] [unique_id "amkyqdTKmBoMa_7ShhaldgAAAQU"]
[Wed Jul 29 00:52:25.590636 2026] [:error] [pid 21037:tid 140254195459840] [client 172.70.46.164:9314] [client 172.70.46.164] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /functions/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/functions/.env"] [unique_id "amkyqdTKmBoMa_7ShhaldgAAAQU"]
[Wed Jul 29 00:52:25.886030 2026] [:error] [pid 21037:tid 140254178674432] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amkyqdTKmBoMa_7ShhaleAAAAQc"]
[Wed Jul 29 00:52:25.886982 2026] [:error] [pid 21037:tid 140254178674432] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amkyqdTKmBoMa_7ShhaleAAAAQc"]
[Wed Jul 29 00:52:25.887505 2026] [:error] [pid 21037:tid 140254178674432] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amkyqdTKmBoMa_7ShhaleAAAAQc"]
[Wed Jul 29 00:52:25.887787 2026] [:error] [pid 21037:tid 140254178674432] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amkyqdTKmBoMa_7ShhaleAAAAQc"]
[Wed Jul 29 00:52:26.868736 2026] [:error] [pid 21037:tid 140254103140096] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amkyqtTKmBoMa_7ShhalfgAAARA"]
[Wed Jul 29 00:52:26.869822 2026] [:error] [pid 21037:tid 140254103140096] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amkyqtTKmBoMa_7ShhalfgAAARA"]
[Wed Jul 29 00:52:26.870355 2026] [:error] [pid 21037:tid 140254103140096] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amkyqtTKmBoMa_7ShhalfgAAARA"]
[Wed Jul 29 00:52:26.870625 2026] [:error] [pid 21037:tid 140254103140096] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amkyqtTKmBoMa_7ShhalfgAAARA"]
[Wed Jul 29 00:52:28.218260 2026] [:error] [pid 21037:tid 140254094747392] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amkyrNTKmBoMa_7ShhalhAAAARE"]
[Wed Jul 29 00:52:28.219119 2026] [:error] [pid 21037:tid 140254094747392] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amkyrNTKmBoMa_7ShhalhAAAARE"]
[Wed Jul 29 00:52:28.219541 2026] [:error] [pid 21037:tid 140254094747392] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amkyrNTKmBoMa_7ShhalhAAAARE"]
[Wed Jul 29 00:52:28.219737 2026] [:error] [pid 21037:tid 140254094747392] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amkyrNTKmBoMa_7ShhalhAAAARE"]
[Wed Jul 29 00:52:29.130208 2026] [:error] [pid 21037:tid 140254145103616] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/functions/.env"] [unique_id "amkyrdTKmBoMa_7ShhaliQAAAQs"]
[Wed Jul 29 00:52:29.131022 2026] [:error] [pid 21037:tid 140254145103616] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/functions/.env"] [unique_id "amkyrdTKmBoMa_7ShhaliQAAAQs"]
[Wed Jul 29 00:52:29.131527 2026] [:error] [pid 21037:tid 140254145103616] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/functions/.env"] [unique_id "amkyrdTKmBoMa_7ShhaliQAAAQs"]
[Wed Jul 29 00:52:29.131813 2026] [:error] [pid 21037:tid 140254145103616] [client 104.23.166.83:9777] [client 104.23.166.83] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /functions/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/functions/.env"] [unique_id "amkyrdTKmBoMa_7ShhaliQAAAQs"]
[Wed Jul 29 01:00:18.838544 2026] [:error] [pid 4873:tid 140254061176576] [client 104.23.243.18:10303] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amk0gke-4ohj6ta8_U65JAAAAJU"]
[Wed Jul 29 01:00:18.839459 2026] [:error] [pid 4873:tid 140254061176576] [client 104.23.243.18:10303] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amk0gke-4ohj6ta8_U65JAAAAJU"]
[Wed Jul 29 01:00:18.839937 2026] [:error] [pid 4873:tid 140254061176576] [client 104.23.243.18:10303] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amk0gke-4ohj6ta8_U65JAAAAJU"]
[Wed Jul 29 01:00:19.270092 2026] [:error] [pid 21037:tid 140254203852544] [client 104.23.243.181:14025] [client 104.23.243.181] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amk0g9TKmBoMa_7Shha06QAAAQQ"]
[Wed Jul 29 01:00:19.270888 2026] [:error] [pid 21037:tid 140254203852544] [client 104.23.243.181:14025] [client 104.23.243.181] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amk0g9TKmBoMa_7Shha06QAAAQQ"]
[Wed Jul 29 01:00:19.271401 2026] [:error] [pid 21037:tid 140254203852544] [client 104.23.243.181:14025] [client 104.23.243.181] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amk0g9TKmBoMa_7Shha06QAAAQQ"]
[Wed Jul 29 01:28:56.774330 2026] [:error] [pid 31432:tid 140254044391168] [client 141.101.76.32:10508] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amk7OBTJGXjs973h3x-10gAAAZc"]
[Wed Jul 29 01:28:56.775225 2026] [:error] [pid 31432:tid 140254044391168] [client 141.101.76.32:10508] [client 141.101.76.32] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amk7OBTJGXjs973h3x-10gAAAZc"]
[Wed Jul 29 01:28:56.775740 2026] [:error] [pid 31432:tid 140254044391168] [client 141.101.76.32:10508] [client 141.101.76.32] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amk7OBTJGXjs973h3x-10gAAAZc"]
[Wed Jul 29 01:28:58.102415 2026] [:error] [pid 4873:tid 140254153496320] [client 104.22.17.81:9912] [client 104.22.17.81] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amk7Oke-4ohj6ta8_U7ReQAAAIo"]
[Wed Jul 29 01:28:58.103429 2026] [:error] [pid 4873:tid 140254153496320] [client 104.22.17.81:9912] [client 104.22.17.81] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amk7Oke-4ohj6ta8_U7ReQAAAIo"]
[Wed Jul 29 01:28:58.104131 2026] [:error] [pid 4873:tid 140254153496320] [client 104.22.17.81:9912] [client 104.22.17.81] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amk7Oke-4ohj6ta8_U7ReQAAAIo"]
[Wed Jul 29 01:33:44.325762 2026] [:error] [pid 4873:tid 140254220637952] [client 172.71.118.246:10598] [client 172.71.118.246] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amk8WEe-4ohj6ta8_U7ZjAAAAII"]
[Wed Jul 29 01:33:44.330634 2026] [:error] [pid 4873:tid 140254220637952] [client 172.71.118.246:10598] [client 172.71.118.246] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amk8WEe-4ohj6ta8_U7ZjAAAAII"]
[Wed Jul 29 01:33:44.330762 2026] [:error] [pid 4873:tid 140254220637952] [client 172.71.118.246:10598] [client 172.71.118.246] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "176"] [id "913102"] [msg "Found User-Agent associated with web crawler/bot"] [data "Matched Data: MJ12bot found within REQUEST_HEADERS:User-Agent: mozilla/5.0 (compatible; mj12bot/v2.0.5; http://mj12bot.com/)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-crawler"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amk8WEe-4ohj6ta8_U7ZjAAAAII"]
[Wed Jul 29 01:33:44.331050 2026] [:error] [pid 4873:tid 140254220637952] [client 172.71.118.246:10598] [client 172.71.118.246] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amk8WEe-4ohj6ta8_U7ZjAAAAII"]
[Wed Jul 29 01:46:31.000226 2026] [:error] [pid 4873:tid 140254212245248] [client 104.23.243.181:12840] [client 104.23.243.181] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amk_Vke-4ohj6ta8_U7tQAAAAIM"]
[Wed Jul 29 01:46:31.001002 2026] [:error] [pid 4873:tid 140254212245248] [client 104.23.243.181:12840] [client 104.23.243.181] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amk_Vke-4ohj6ta8_U7tQAAAAIM"]
[Wed Jul 29 01:46:31.001432 2026] [:error] [pid 4873:tid 140254212245248] [client 104.23.243.181:12840] [client 104.23.243.181] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amk_Vke-4ohj6ta8_U7tQAAAAIM"]
[Wed Jul 29 01:52:47.923291 2026] [:error] [pid 20768:tid 140254153496320] [client 104.23.223.55:10166] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amlAz5jwFipIdqsHCMZIFgAAAMo"]
[Wed Jul 29 01:52:47.924262 2026] [:error] [pid 20768:tid 140254153496320] [client 104.23.223.55:10166] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amlAz5jwFipIdqsHCMZIFgAAAMo"]
[Wed Jul 29 01:52:47.924966 2026] [:error] [pid 20768:tid 140254153496320] [client 104.23.223.55:10166] [client 104.23.223.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amlAz5jwFipIdqsHCMZIFgAAAMo"]
[Wed Jul 29 02:00:12.675453 2026] [:error] [pid 31504:tid 140254069569280] [client 104.23.172.124:10365] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amlCjL6SJayGrl0sDpGbAgAAAdQ"]
[Wed Jul 29 02:00:12.676456 2026] [:error] [pid 31504:tid 140254069569280] [client 104.23.172.124:10365] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amlCjL6SJayGrl0sDpGbAgAAAdQ"]
[Wed Jul 29 02:00:12.676986 2026] [:error] [pid 31504:tid 140254069569280] [client 104.23.172.124:10365] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amlCjL6SJayGrl0sDpGbAgAAAdQ"]
[Wed Jul 29 02:00:12.677252 2026] [:error] [pid 31504:tid 140254069569280] [client 104.23.172.124:10365] [client 104.23.172.124] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amlCjL6SJayGrl0sDpGbAgAAAdQ"]
[Wed Jul 29 02:22:57.389409 2026] [:error] [pid 4873:tid 140254086354688] [client 104.23.217.117:13761] [client 104.23.217.117] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlH4Ue-4ohj6ta8_U4oowAAAJI"]
[Wed Jul 29 02:22:57.390297 2026] [:error] [pid 4873:tid 140254086354688] [client 104.23.217.117:13761] [client 104.23.217.117] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlH4Ue-4ohj6ta8_U4oowAAAJI"]
[Wed Jul 29 02:22:57.390825 2026] [:error] [pid 4873:tid 140254086354688] [client 104.23.217.117:13761] [client 104.23.217.117] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlH4Ue-4ohj6ta8_U4oowAAAJI"]
[Wed Jul 29 02:23:57.181798 2026] [:error] [pid 21037:tid 140254187067136] [client 172.69.11.132:14038] [client 172.69.11.132] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amlIHdTKmBoMa_7ShhYbuwAAAQY"]
[Wed Jul 29 02:23:57.182672 2026] [:error] [pid 21037:tid 140254187067136] [client 172.69.11.132:14038] [client 172.69.11.132] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amlIHdTKmBoMa_7ShhYbuwAAAQY"]
[Wed Jul 29 02:23:57.183252 2026] [:error] [pid 21037:tid 140254187067136] [client 172.69.11.132:14038] [client 172.69.11.132] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amlIHdTKmBoMa_7ShhYbuwAAAQY"]
[Wed Jul 29 02:30:28.505011 2026] [:error] [pid 31378:tid 140254161889024] [client 172.70.174.68:14178] [client 172.70.174.68] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlJpDps7SmFbinM126WkgAAAEk"]
[Wed Jul 29 02:30:28.505932 2026] [:error] [pid 31378:tid 140254161889024] [client 172.70.174.68:14178] [client 172.70.174.68] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlJpDps7SmFbinM126WkgAAAEk"]
[Wed Jul 29 02:30:28.506657 2026] [:error] [pid 31378:tid 140254161889024] [client 172.70.174.68:14178] [client 172.70.174.68] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-Ch-Ua-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-Ch-Ua-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlJpDps7SmFbinM126WkgAAAEk"]
[Wed Jul 29 02:30:28.506734 2026] [:error] [pid 31378:tid 140254161889024] [client 172.70.174.68:14178] [client 172.70.174.68] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlJpDps7SmFbinM126WkgAAAEk"]
[Wed Jul 29 03:13:08.228775 2026] [:error] [pid 16566:tid 140254069569280] [client 162.158.91.152:9425] [client 162.158.91.152] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlTpIBrVrQDTXXS_cGO4gAAAhQ"]
[Wed Jul 29 03:13:08.262296 2026] [:error] [pid 16566:tid 140254069569280] [client 162.158.91.152:9425] [client 162.158.91.152] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlTpIBrVrQDTXXS_cGO4gAAAhQ"]
[Wed Jul 29 03:13:08.262760 2026] [:error] [pid 16566:tid 140254069569280] [client 162.158.91.152:9425] [client 162.158.91.152] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlTpIBrVrQDTXXS_cGO4gAAAhQ"]
[Wed Jul 29 03:13:08.262873 2026] [:error] [pid 16566:tid 140254069569280] [client 162.158.91.152:9425] [client 162.158.91.152] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlTpIBrVrQDTXXS_cGO4gAAAhQ"]
[Wed Jul 29 03:38:28.051543 2026] [:error] [pid 27113:tid 140324978525952] [client 104.23.243.18:13191] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amlZlF8XA5PRYKcr6_Xd2QAAAMk"]
[Wed Jul 29 03:38:28.086125 2026] [:error] [pid 27113:tid 140324978525952] [client 104.23.243.18:13191] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amlZlF8XA5PRYKcr6_Xd2QAAAMk"]
[Wed Jul 29 03:38:28.086614 2026] [:error] [pid 27113:tid 140324978525952] [client 104.23.243.18:13191] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amlZlF8XA5PRYKcr6_Xd2QAAAMk"]
[Wed Jul 29 03:38:42.456571 2026] [:error] [pid 27308:tid 140324902991616] [client 162.158.86.142:11825] [client 162.158.86.142] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amlZonwMP69UgRRVHucoMAAAARI"]
[Wed Jul 29 03:38:42.457388 2026] [:error] [pid 27308:tid 140324902991616] [client 162.158.86.142:11825] [client 162.158.86.142] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amlZonwMP69UgRRVHucoMAAAARI"]
[Wed Jul 29 03:38:42.457997 2026] [:error] [pid 27308:tid 140324902991616] [client 162.158.86.142:11825] [client 162.158.86.142] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amlZonwMP69UgRRVHucoMAAAARI"]
[Wed Jul 29 04:22:49.038680 2026] [:error] [pid 1735:tid 140324978525952] [client 104.23.197.77:12193] [client 104.23.197.77] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amlj-X8s9KvqQrPFEa-vqAAAAgk"]
[Wed Jul 29 04:22:49.039767 2026] [:error] [pid 1735:tid 140324978525952] [client 104.23.197.77:12193] [client 104.23.197.77] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amlj-X8s9KvqQrPFEa-vqAAAAgk"]
[Wed Jul 29 04:22:49.040279 2026] [:error] [pid 1735:tid 140324978525952] [client 104.23.197.77:12193] [client 104.23.197.77] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amlj-X8s9KvqQrPFEa-vqAAAAgk"]
[Wed Jul 29 04:37:02.451471 2026] [:error] [pid 26678:tid 140324902991616] [client 104.23.168.4:9683] [client 104.23.168.4] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlnTvshvKXjXs_N_WF_qAAAABI"]
[Wed Jul 29 04:37:02.456285 2026] [:error] [pid 26678:tid 140324902991616] [client 104.23.168.4:9683] [client 104.23.168.4] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlnTvshvKXjXs_N_WF_qAAAABI"]
[Wed Jul 29 04:37:02.544165 2026] [:error] [pid 26678:tid 140324902991616] [client 104.23.168.4:9683] [client 104.23.168.4] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlnTvshvKXjXs_N_WF_qAAAABI"]
[Wed Jul 29 04:48:08.081652 2026] [:error] [pid 27113:tid 140324978525952] [client 172.71.194.241:13074] [client 172.71.194.241] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlp6F8XA5PRYKcr6_UPVAAAAMk"]
[Wed Jul 29 04:48:08.082279 2026] [:error] [pid 27113:tid 140324978525952] [client 172.71.194.241:13074] [client 172.71.194.241] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlp6F8XA5PRYKcr6_UPVAAAAMk"]
[Wed Jul 29 04:48:08.082625 2026] [:error] [pid 27113:tid 140324978525952] [client 172.71.194.241:13074] [client 172.71.194.241] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlp6F8XA5PRYKcr6_UPVAAAAMk"]
[Wed Jul 29 04:49:06.970956 2026] [:error] [pid 27308:tid 140324861028096] [client 172.70.174.69:12154] [client 172.70.174.69] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlqInwMP69UgRRVHudsYwAAARc"]
[Wed Jul 29 04:49:06.971826 2026] [:error] [pid 27308:tid 140324861028096] [client 172.70.174.69:12154] [client 172.70.174.69] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlqInwMP69UgRRVHudsYwAAARc"]
[Wed Jul 29 04:49:06.972629 2026] [:error] [pid 27308:tid 140324861028096] [client 172.70.174.69:12154] [client 172.70.174.69] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua=\\x22Not)A;Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22138\\x22, \\x22HeadlessChrome\\x22;v=\\x22138\\x22"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlqInwMP69UgRRVHudsYwAAARc"]
[Wed Jul 29 04:49:06.972701 2026] [:error] [pid 27308:tid 140324861028096] [client 172.70.174.69:12154] [client 172.70.174.69] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlqInwMP69UgRRVHudsYwAAARc"]
[Wed Jul 29 04:49:06.972756 2026] [:error] [pid 27308:tid 140324861028096] [client 172.70.174.69:12154] [client 172.70.174.69] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amlqInwMP69UgRRVHudsYwAAARc"]
[Wed Jul 29 05:24:02.012800 2026] [:error] [pid 26678:tid 140324978525952] [client 104.23.172.125:13453] [client 104.23.172.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amlyUvshvKXjXs_N_WGpdwAAAAk"]
[Wed Jul 29 05:24:02.041771 2026] [:error] [pid 26678:tid 140324978525952] [client 104.23.172.125:13453] [client 104.23.172.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amlyUvshvKXjXs_N_WGpdwAAAAk"]
[Wed Jul 29 05:24:02.042534 2026] [:error] [pid 26678:tid 140324978525952] [client 104.23.172.125:13453] [client 104.23.172.125] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amlyUvshvKXjXs_N_WGpdwAAAAk"]
[Wed Jul 29 05:32:58.370341 2026] [:error] [pid 27309:tid 140324911384320] [client 104.23.197.185:11355] [client 104.23.197.185] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "aml0av024PfLVsfk9MYIogAAAVE"]
[Wed Jul 29 05:32:58.371246 2026] [:error] [pid 27309:tid 140324911384320] [client 104.23.197.185:11355] [client 104.23.197.185] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "aml0av024PfLVsfk9MYIogAAAVE"]
[Wed Jul 29 05:32:58.371728 2026] [:error] [pid 27309:tid 140324911384320] [client 104.23.197.185:11355] [client 104.23.197.185] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "aml0av024PfLVsfk9MYIogAAAVE"]
[Wed Jul 29 05:36:07.235998 2026] [:error] [pid 27308:tid 140324869420800] [client 172.70.174.68:9992] [client 172.70.174.68] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "aml1J3wMP69UgRRVHue2yAAAARY"]
[Wed Jul 29 05:36:07.245019 2026] [:error] [pid 27308:tid 140324869420800] [client 172.70.174.68:9992] [client 172.70.174.68] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "aml1J3wMP69UgRRVHue2yAAAARY"]
[Wed Jul 29 05:36:07.245609 2026] [:error] [pid 27308:tid 140324869420800] [client 172.70.174.68:9992] [client 172.70.174.68] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua=\\x22Chromium\\x22;v=\\x22148\\x22, \\x22Google Chrome\\x22;v=\\x22148\\x22, \\x22Not/A)Brand\\x22;v=\\x2299\\x22"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "aml1J3wMP69UgRRVHue2yAAAARY"]
[Wed Jul 29 05:36:07.245662 2026] [:error] [pid 27308:tid 140324869420800] [client 172.70.174.68:9992] [client 172.70.174.68] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "aml1J3wMP69UgRRVHue2yAAAARY"]
[Wed Jul 29 05:36:07.245691 2026] [:error] [pid 27308:tid 140324869420800] [client 172.70.174.68:9992] [client 172.70.174.68] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "aml1J3wMP69UgRRVHue2yAAAARY"]
[Wed Jul 29 05:42:49.841268 2026] [:error] [pid 27308:tid 140324961740544] [client 172.71.158.124:10963] [client 172.71.158.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml2uXwMP69UgRRVHue7_gAAAQs"]
[Wed Jul 29 05:42:49.843842 2026] [:error] [pid 27308:tid 140324961740544] [client 172.71.158.124:10963] [client 172.71.158.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml2uXwMP69UgRRVHue7_gAAAQs"]
[Wed Jul 29 05:42:49.844292 2026] [:error] [pid 27308:tid 140324961740544] [client 172.71.158.124:10963] [client 172.71.158.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml2uXwMP69UgRRVHue7_gAAAQs"]
[Wed Jul 29 05:42:49.846539 2026] [:error] [pid 26678:tid 140324986918656] [client 172.71.155.153:12090] [client 172.71.155.153] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml2ufshvKXjXs_N_WGyhQAAAAg"]
[Wed Jul 29 05:42:49.847204 2026] [:error] [pid 26678:tid 140324986918656] [client 172.71.155.153:12090] [client 172.71.155.153] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml2ufshvKXjXs_N_WGyhQAAAAg"]
[Wed Jul 29 05:42:49.847660 2026] [:error] [pid 26678:tid 140324986918656] [client 172.71.155.153:12090] [client 172.71.155.153] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml2ufshvKXjXs_N_WGyhQAAAAg"]
[Wed Jul 29 05:42:49.948985 2026] [:error] [pid 1734:tid 140324861028096] [client 172.71.154.26:13071] [client 172.71.154.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml2uYN9TgZBr6otIXoypAAAAdc"]
[Wed Jul 29 05:42:49.949725 2026] [:error] [pid 1734:tid 140324861028096] [client 172.71.154.26:13071] [client 172.71.154.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml2uYN9TgZBr6otIXoypAAAAdc"]
[Wed Jul 29 05:42:49.950179 2026] [:error] [pid 1734:tid 140324861028096] [client 172.71.154.26:13071] [client 172.71.154.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml2uYN9TgZBr6otIXoypAAAAdc"]
[Wed Jul 29 05:42:49.991907 2026] [:error] [pid 27308:tid 140324869420800] [client 162.158.167.48:13719] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml2uXwMP69UgRRVHue8AAAAARY"]
[Wed Jul 29 05:42:49.992824 2026] [:error] [pid 27308:tid 140324869420800] [client 162.158.167.48:13719] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml2uXwMP69UgRRVHue8AAAAARY"]
[Wed Jul 29 05:42:49.993216 2026] [:error] [pid 27308:tid 140324869420800] [client 162.158.167.48:13719] [client 162.158.167.48] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml2uXwMP69UgRRVHue8AAAAARY"]
[Wed Jul 29 05:43:21.036417 2026] [:error] [pid 27113:tid 140324894598912] [client 162.158.167.19:12907] [client 162.158.167.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml22V8XA5PRYKcr6_U1MwAAANM"]
[Wed Jul 29 05:43:21.037054 2026] [:error] [pid 27113:tid 140324894598912] [client 162.158.167.19:12907] [client 162.158.167.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml22V8XA5PRYKcr6_U1MwAAANM"]
[Wed Jul 29 05:43:21.037408 2026] [:error] [pid 27113:tid 140324894598912] [client 162.158.167.19:12907] [client 162.158.167.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml22V8XA5PRYKcr6_U1MwAAANM"]
[Wed Jul 29 05:43:21.039084 2026] [:error] [pid 27113:tid 140324894598912] [client 172.71.155.154:11545] [client 172.71.155.154] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml22V8XA5PRYKcr6_U1NAAAANM"]
[Wed Jul 29 05:43:21.039422 2026] [:error] [pid 27113:tid 140324894598912] [client 172.71.155.154:11545] [client 172.71.155.154] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml22V8XA5PRYKcr6_U1NAAAANM"]
[Wed Jul 29 05:43:21.039686 2026] [:error] [pid 27113:tid 140324894598912] [client 172.71.155.154:11545] [client 172.71.155.154] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml22V8XA5PRYKcr6_U1NAAAANM"]
[Wed Jul 29 05:43:21.585409 2026] [:error] [pid 27309:tid 140324911384320] [client 172.71.158.54:10082] [client 172.71.158.54] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml22f024PfLVsfk9MYLPwAAAVE"]
[Wed Jul 29 05:43:21.586051 2026] [:error] [pid 27309:tid 140324911384320] [client 172.71.158.54:10082] [client 172.71.158.54] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml22f024PfLVsfk9MYLPwAAAVE"]
[Wed Jul 29 05:43:21.586408 2026] [:error] [pid 27309:tid 140324911384320] [client 172.71.158.54:10082] [client 172.71.158.54] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml22f024PfLVsfk9MYLPwAAAVE"]
[Wed Jul 29 05:43:21.596616 2026] [:error] [pid 26678:tid 140324911384320] [client 162.158.167.48:10661] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml22fshvKXjXs_N_WGyuwAAABE"]
[Wed Jul 29 05:43:21.597383 2026] [:error] [pid 26678:tid 140324911384320] [client 162.158.167.48:10661] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml22fshvKXjXs_N_WGyuwAAABE"]
[Wed Jul 29 05:43:21.597771 2026] [:error] [pid 26678:tid 140324911384320] [client 162.158.167.48:10661] [client 162.158.167.48] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml22fshvKXjXs_N_WGyuwAAABE"]
[Wed Jul 29 05:44:22.541336 2026] [:error] [pid 27309:tid 140324911384320] [client 104.22.17.162:10733] [client 104.22.17.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3Fv024PfLVsfk9MYLdQAAAVE"]
[Wed Jul 29 05:44:22.541922 2026] [:error] [pid 27309:tid 140324911384320] [client 104.22.17.162:10733] [client 104.22.17.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3Fv024PfLVsfk9MYLdQAAAVE"]
[Wed Jul 29 05:44:22.542240 2026] [:error] [pid 27309:tid 140324911384320] [client 104.22.17.162:10733] [client 104.22.17.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3Fv024PfLVsfk9MYLdQAAAVE"]
[Wed Jul 29 05:44:22.543629 2026] [:error] [pid 27309:tid 140324911384320] [client 104.22.17.163:12983] [client 104.22.17.163] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3Fv024PfLVsfk9MYLdgAAAVE"]
[Wed Jul 29 05:44:22.543923 2026] [:error] [pid 27309:tid 140324911384320] [client 104.22.17.163:12983] [client 104.22.17.163] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3Fv024PfLVsfk9MYLdgAAAVE"]
[Wed Jul 29 05:44:22.544163 2026] [:error] [pid 27309:tid 140324911384320] [client 104.22.17.163:12983] [client 104.22.17.163] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3Fv024PfLVsfk9MYLdgAAAVE"]
[Wed Jul 29 05:44:22.796848 2026] [:error] [pid 27113:tid 140324861028096] [client 172.69.22.193:11799] [client 172.69.22.193] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3Fl8XA5PRYKcr6_U1XwAAANc"]
[Wed Jul 29 05:44:22.798411 2026] [:error] [pid 27308:tid 140325037274880] [client 172.71.158.55:9392] [client 172.71.158.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3FnwMP69UgRRVHue9qgAAAQI"]
[Wed Jul 29 05:44:22.798938 2026] [:error] [pid 27308:tid 140325037274880] [client 172.71.158.55:9392] [client 172.71.158.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3FnwMP69UgRRVHue9qgAAAQI"]
[Wed Jul 29 05:44:22.799306 2026] [:error] [pid 27308:tid 140325037274880] [client 172.71.158.55:9392] [client 172.71.158.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3FnwMP69UgRRVHue9qgAAAQI"]
[Wed Jul 29 05:44:22.855743 2026] [:error] [pid 27113:tid 140324861028096] [client 172.69.22.193:11799] [client 172.69.22.193] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3Fl8XA5PRYKcr6_U1XwAAANc"]
[Wed Jul 29 05:44:22.865081 2026] [:error] [pid 27113:tid 140324861028096] [client 172.69.22.193:11799] [client 172.69.22.193] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3Fl8XA5PRYKcr6_U1XwAAANc"]
[Wed Jul 29 05:46:23.884788 2026] [:error] [pid 27308:tid 140324886206208] [client 104.22.17.162:13803] [client 104.22.17.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3j3wMP69UgRRVHue_lQAAARQ"]
[Wed Jul 29 05:46:23.885479 2026] [:error] [pid 27308:tid 140324886206208] [client 104.22.17.162:13803] [client 104.22.17.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3j3wMP69UgRRVHue_lQAAARQ"]
[Wed Jul 29 05:46:23.885852 2026] [:error] [pid 27308:tid 140324886206208] [client 104.22.17.162:13803] [client 104.22.17.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3j3wMP69UgRRVHue_lQAAARQ"]
[Wed Jul 29 05:46:23.892105 2026] [:error] [pid 26682:tid 140324970133248] [client 104.22.20.116:10534] [client 104.22.20.116] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3jz2k5Z2B9bmhwGQjwQAAAIo"]
[Wed Jul 29 05:46:23.892935 2026] [:error] [pid 26682:tid 140324970133248] [client 104.22.20.116:10534] [client 104.22.20.116] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3jz2k5Z2B9bmhwGQjwQAAAIo"]
[Wed Jul 29 05:46:23.893451 2026] [:error] [pid 26682:tid 140324970133248] [client 104.22.20.116:10534] [client 104.22.20.116] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3jz2k5Z2B9bmhwGQjwQAAAIo"]
[Wed Jul 29 05:46:24.245479 2026] [:error] [pid 27309:tid 140324894598912] [client 162.158.167.48:14087] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3kP024PfLVsfk9MYMFgAAAVM"]
[Wed Jul 29 05:46:24.246024 2026] [:error] [pid 27309:tid 140324894598912] [client 162.158.167.48:14087] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3kP024PfLVsfk9MYMFgAAAVM"]
[Wed Jul 29 05:46:24.246351 2026] [:error] [pid 27309:tid 140324894598912] [client 162.158.167.48:14087] [client 162.158.167.48] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3kP024PfLVsfk9MYMFgAAAVM"]
[Wed Jul 29 05:46:24.336099 2026] [:error] [pid 26678:tid 140324877813504] [client 104.22.20.127:10038] [client 104.22.20.127] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3kPshvKXjXs_N_WG0dwAAABU"]
[Wed Jul 29 05:46:24.337091 2026] [:error] [pid 26678:tid 140324877813504] [client 104.22.20.127:10038] [client 104.22.20.127] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3kPshvKXjXs_N_WG0dwAAABU"]
[Wed Jul 29 05:46:24.337657 2026] [:error] [pid 26678:tid 140324877813504] [client 104.22.20.127:10038] [client 104.22.20.127] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml3kPshvKXjXs_N_WG0dwAAABU"]
[Wed Jul 29 05:49:05.275699 2026] [:error] [pid 1735:tid 140324902991616] [client 172.68.18.148:11686] [client 172.68.18.148] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "aml4MX8s9KvqQrPFEa_cwQAAAhI"]
[Wed Jul 29 05:49:05.276699 2026] [:error] [pid 1735:tid 140324902991616] [client 172.68.18.148:11686] [client 172.68.18.148] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "aml4MX8s9KvqQrPFEa_cwQAAAhI"]
[Wed Jul 29 05:49:05.286303 2026] [:error] [pid 1735:tid 140324902991616] [client 172.68.18.148:11686] [client 172.68.18.148] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "aml4MX8s9KvqQrPFEa_cwQAAAhI"]
[Wed Jul 29 05:51:25.185560 2026] [:error] [pid 26682:tid 140324986918656] [client 172.71.158.124:12532] [client 172.71.158.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml4vT2k5Z2B9bmhwGQlcwAAAIg"]
[Wed Jul 29 05:51:25.185597 2026] [:error] [pid 26682:tid 140325028882176] [client 172.71.158.125:12337] [client 172.71.158.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml4vT2k5Z2B9bmhwGQldAAAAIM"]
[Wed Jul 29 05:51:25.186449 2026] [:error] [pid 26682:tid 140324986918656] [client 172.71.158.124:12532] [client 172.71.158.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml4vT2k5Z2B9bmhwGQlcwAAAIg"]
[Wed Jul 29 05:51:25.186543 2026] [:error] [pid 26682:tid 140325028882176] [client 172.71.158.125:12337] [client 172.71.158.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml4vT2k5Z2B9bmhwGQldAAAAIM"]
[Wed Jul 29 05:51:25.186975 2026] [:error] [pid 26682:tid 140324986918656] [client 172.71.158.124:12532] [client 172.71.158.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml4vT2k5Z2B9bmhwGQlcwAAAIg"]
[Wed Jul 29 05:51:25.187070 2026] [:error] [pid 26682:tid 140325028882176] [client 172.71.158.125:12337] [client 172.71.158.125] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml4vT2k5Z2B9bmhwGQldAAAAIM"]
[Wed Jul 29 05:51:25.543842 2026] [:error] [pid 1734:tid 140325116811008] [client 172.71.158.55:12233] [client 172.71.158.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml4vYN9TgZBr6otIXo1qAAAAcE"]
[Wed Jul 29 05:51:25.544746 2026] [:error] [pid 1734:tid 140325116811008] [client 172.71.158.55:12233] [client 172.71.158.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml4vYN9TgZBr6otIXo1qAAAAcE"]
[Wed Jul 29 05:51:25.545234 2026] [:error] [pid 1734:tid 140325116811008] [client 172.71.158.55:12233] [client 172.71.158.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml4vYN9TgZBr6otIXo1qAAAAcE"]
[Wed Jul 29 05:51:25.545338 2026] [:error] [pid 1675:tid 140324886206208] [client 162.158.167.47:10853] [client 162.158.167.47] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml4ve65UVt70kUvq9u17wAAAZQ"]
[Wed Jul 29 05:51:25.545820 2026] [:error] [pid 1675:tid 140324886206208] [client 162.158.167.47:10853] [client 162.158.167.47] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml4ve65UVt70kUvq9u17wAAAZQ"]
[Wed Jul 29 05:51:25.546204 2026] [:error] [pid 1675:tid 140324886206208] [client 162.158.167.47:10853] [client 162.158.167.47] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml4ve65UVt70kUvq9u17wAAAZQ"]
[Wed Jul 29 06:01:26.735698 2026] [:error] [pid 27978:tid 140324978525952] [client 162.158.167.19:9779] [client 162.158.167.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml7FkFLBUDT-r-ADO3aWAAAAkk"]
[Wed Jul 29 06:01:26.736599 2026] [:error] [pid 27978:tid 140324978525952] [client 162.158.167.19:9779] [client 162.158.167.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml7FkFLBUDT-r-ADO3aWAAAAkk"]
[Wed Jul 29 06:01:26.737057 2026] [:error] [pid 27978:tid 140324978525952] [client 162.158.167.19:9779] [client 162.158.167.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml7FkFLBUDT-r-ADO3aWAAAAkk"]
[Wed Jul 29 06:01:26.756507 2026] [:error] [pid 27978:tid 140324919777024] [client 172.71.155.154:12743] [client 172.71.155.154] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml7FkFLBUDT-r-ADO3aWQAAAlA"]
[Wed Jul 29 06:01:26.757166 2026] [:error] [pid 27978:tid 140324919777024] [client 172.71.155.154:12743] [client 172.71.155.154] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml7FkFLBUDT-r-ADO3aWQAAAlA"]
[Wed Jul 29 06:01:26.757519 2026] [:error] [pid 27978:tid 140324919777024] [client 172.71.155.154:12743] [client 172.71.155.154] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml7FkFLBUDT-r-ADO3aWQAAAlA"]
[Wed Jul 29 06:01:26.895890 2026] [:error] [pid 27113:tid 140324961740544] [client 104.22.20.127:9780] [client 104.22.20.127] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml7Fl8XA5PRYKcr6_U6NgAAAMs"]
[Wed Jul 29 06:01:26.896427 2026] [:error] [pid 27113:tid 140324961740544] [client 104.22.20.127:9780] [client 104.22.20.127] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml7Fl8XA5PRYKcr6_U6NgAAAMs"]
[Wed Jul 29 06:01:26.896754 2026] [:error] [pid 27113:tid 140324961740544] [client 104.22.20.127:9780] [client 104.22.20.127] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml7Fl8XA5PRYKcr6_U6NgAAAMs"]
[Wed Jul 29 06:01:26.936230 2026] [:error] [pid 27978:tid 140324886206208] [client 172.69.22.193:11622] [client 172.69.22.193] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml7FkFLBUDT-r-ADO3aWgAAAlQ"]
[Wed Jul 29 06:01:26.936794 2026] [:error] [pid 27978:tid 140324886206208] [client 172.69.22.193:11622] [client 172.69.22.193] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml7FkFLBUDT-r-ADO3aWgAAAlQ"]
[Wed Jul 29 06:01:26.937128 2026] [:error] [pid 27978:tid 140324886206208] [client 172.69.22.193:11622] [client 172.69.22.193] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "aml7FkFLBUDT-r-ADO3aWgAAAlQ"]
[Wed Jul 29 06:23:03.443538 2026] [:error] [pid 26678:tid 140325012096768] [client 104.22.104.224:12175] [client 104.22.104.224] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ammAJ_shvKXjXs_N_WG_AAAAAAU"]
[Wed Jul 29 06:23:03.444516 2026] [:error] [pid 26678:tid 140325012096768] [client 104.22.104.224:12175] [client 104.22.104.224] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ammAJ_shvKXjXs_N_WG_AAAAAAU"]
[Wed Jul 29 06:23:03.445270 2026] [:error] [pid 26678:tid 140325012096768] [client 104.22.104.224:12175] [client 104.22.104.224] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ammAJ_shvKXjXs_N_WG_AAAAAAU"]
[Wed Jul 29 06:23:03.445339 2026] [:error] [pid 26678:tid 140325012096768] [client 104.22.104.224:12175] [client 104.22.104.224] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua=\\x22Chromium\\x22;v=\\x22148\\x22, \\x22Google Chrome\\x22;v=\\x22148\\x22, \\x22Not/A)Brand\\x22;v=\\x2299\\x22"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ammAJ_shvKXjXs_N_WG_AAAAAAU"]
[Wed Jul 29 06:23:03.445390 2026] [:error] [pid 26678:tid 140325012096768] [client 104.22.104.224:12175] [client 104.22.104.224] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ammAJ_shvKXjXs_N_WG_AAAAAAU"]
[Wed Jul 29 06:27:16.351961 2026] [:error] [pid 26678:tid 140324953347840] [client 104.23.243.252:12025] [client 104.23.243.252] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ammBJPshvKXjXs_N_WHAXAAAAAw"]
[Wed Jul 29 06:27:16.352822 2026] [:error] [pid 26678:tid 140324953347840] [client 104.23.243.252:12025] [client 104.23.243.252] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ammBJPshvKXjXs_N_WHAXAAAAAw"]
[Wed Jul 29 06:27:16.353241 2026] [:error] [pid 26678:tid 140324953347840] [client 104.23.243.252:12025] [client 104.23.243.252] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ammBJPshvKXjXs_N_WHAXAAAAAw"]
[Wed Jul 29 06:30:43.494624 2026] [:error] [pid 26682:tid 140324953347840] [client 172.68.164.94:10281] [client 172.68.164.94] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ammB8z2k5Z2B9bmhwGREKAAAAIw"]
[Wed Jul 29 06:30:43.495449 2026] [:error] [pid 26682:tid 140324953347840] [client 172.68.164.94:10281] [client 172.68.164.94] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ammB8z2k5Z2B9bmhwGREKAAAAIw"]
[Wed Jul 29 06:30:43.496008 2026] [:error] [pid 26682:tid 140324953347840] [client 172.68.164.94:10281] [client 172.68.164.94] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "ammB8z2k5Z2B9bmhwGREKAAAAIw"]
[Wed Jul 29 06:45:11.284608 2026] [:error] [pid 29913:tid 139879065302784] [client 104.23.172.124:12528] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ammFVwVDiGi-ktKYT-JrJQAAAMY"]
[Wed Jul 29 06:45:11.335674 2026] [:error] [pid 29913:tid 139879065302784] [client 104.23.172.124:12528] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ammFVwVDiGi-ktKYT-JrJQAAAMY"]
[Wed Jul 29 06:45:11.336193 2026] [:error] [pid 29913:tid 139879065302784] [client 104.23.172.124:12528] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ammFVwVDiGi-ktKYT-JrJQAAAMY"]
[Wed Jul 29 06:45:11.336418 2026] [:error] [pid 29913:tid 139879065302784] [client 104.23.172.124:12528] [client 104.23.172.124] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ammFVwVDiGi-ktKYT-JrJQAAAMY"]
[Wed Jul 29 07:11:19.056059 2026] [:error] [pid 29816:tid 139879177004800] [client 172.69.224.25:13401] [client 172.69.224.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ammLd7iIh7LJBqOi9DxUBwAAAAE"]
[Wed Jul 29 07:11:19.057308 2026] [:error] [pid 29816:tid 139879177004800] [client 172.69.224.25:13401] [client 172.69.224.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ammLd7iIh7LJBqOi9DxUBwAAAAE"]
[Wed Jul 29 07:11:19.057928 2026] [:error] [pid 29816:tid 139879177004800] [client 172.69.224.25:13401] [client 172.69.224.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ammLd7iIh7LJBqOi9DxUBwAAAAE"]
[Wed Jul 29 07:21:21.276910 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.223.55:10173] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammN0aGf2ExAGdIXvjMkYwAAAQ8"]
[Wed Jul 29 07:21:21.278057 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.223.55:10173] [client 104.23.223.55] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammN0aGf2ExAGdIXvjMkYwAAAQ8"]
[Wed Jul 29 07:21:21.278877 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.223.55:10173] [client 104.23.223.55] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammN0aGf2ExAGdIXvjMkYwAAAQ8"]
[Wed Jul 29 07:21:21.278977 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.223.55:10173] [client 104.23.223.55] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammN0aGf2ExAGdIXvjMkYwAAAQ8"]
[Wed Jul 29 07:33:20.445511 2026] [:error] [pid 29913:tid 139879098873600] [client 104.23.243.19:9732] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ammQoAVDiGi-ktKYT-KRPgAAAMI"]
[Wed Jul 29 07:33:20.498081 2026] [:error] [pid 29913:tid 139879098873600] [client 104.23.243.19:9732] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ammQoAVDiGi-ktKYT-KRPgAAAMI"]
[Wed Jul 29 07:33:20.498507 2026] [:error] [pid 29913:tid 139879098873600] [client 104.23.243.19:9732] [client 104.23.243.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ammQoAVDiGi-ktKYT-KRPgAAAMI"]
[Wed Jul 29 07:41:05.767276 2026] [:error] [pid 29913:tid 139878922626816] [client 172.71.154.27:10590] [client 172.71.154.27] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammScQVDiGi-ktKYT-KVwAAAANc"]
[Wed Jul 29 07:41:05.767367 2026] [:error] [pid 29913:tid 139879031731968] [client 172.69.22.192:12194] [client 172.69.22.192] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammScQVDiGi-ktKYT-KVvwAAAMo"]
[Wed Jul 29 07:41:05.781210 2026] [:error] [pid 29913:tid 139878922626816] [client 172.71.154.27:10590] [client 172.71.154.27] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammScQVDiGi-ktKYT-KVwAAAANc"]
[Wed Jul 29 07:41:05.781796 2026] [:error] [pid 29913:tid 139878922626816] [client 172.71.154.27:10590] [client 172.71.154.27] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammScQVDiGi-ktKYT-KVwAAAANc"]
[Wed Jul 29 07:41:05.784197 2026] [:error] [pid 29913:tid 139879031731968] [client 172.69.22.192:12194] [client 172.69.22.192] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammScQVDiGi-ktKYT-KVvwAAAMo"]
[Wed Jul 29 07:41:05.784711 2026] [:error] [pid 29913:tid 139879031731968] [client 172.69.22.192:12194] [client 172.69.22.192] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammScQVDiGi-ktKYT-KVvwAAAMo"]
[Wed Jul 29 07:41:06.049247 2026] [:error] [pid 29818:tid 139879056910080] [client 172.71.158.125:11760] [client 172.71.158.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammScsNm_eEjUiZv2_ih5AAAAIc"]
[Wed Jul 29 07:41:06.050112 2026] [:error] [pid 29818:tid 139879056910080] [client 172.71.158.125:11760] [client 172.71.158.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammScsNm_eEjUiZv2_ih5AAAAIc"]
[Wed Jul 29 07:41:06.050483 2026] [:error] [pid 29818:tid 139879056910080] [client 172.71.158.125:11760] [client 172.71.158.125] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammScsNm_eEjUiZv2_ih5AAAAIc"]
[Wed Jul 29 07:41:06.052417 2026] [:error] [pid 32190:tid 139878939412224] [client 172.69.135.36:14009] [client 172.69.135.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammScqGf2ExAGdIXvjM4vgAAARU"]
[Wed Jul 29 07:41:06.053053 2026] [:error] [pid 32190:tid 139878939412224] [client 172.69.135.36:14009] [client 172.69.135.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammScqGf2ExAGdIXvjM4vgAAARU"]
[Wed Jul 29 07:41:06.053515 2026] [:error] [pid 32190:tid 139878939412224] [client 172.69.135.36:14009] [client 172.69.135.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammScqGf2ExAGdIXvjM4vgAAARU"]
[Wed Jul 29 07:41:36.941223 2026] [:error] [pid 32190:tid 139879073695488] [client 162.158.167.48:11339] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSkKGf2ExAGdIXvjM5IQAAAQU"]
[Wed Jul 29 07:41:36.942545 2026] [:error] [pid 32190:tid 139879073695488] [client 162.158.167.48:11339] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSkKGf2ExAGdIXvjM5IQAAAQU"]
[Wed Jul 29 07:41:36.943000 2026] [:error] [pid 32190:tid 139878981375744] [client 172.71.154.27:10599] [client 172.71.154.27] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSkKGf2ExAGdIXvjM5IgAAARA"]
[Wed Jul 29 07:41:36.943269 2026] [:error] [pid 32190:tid 139879073695488] [client 162.158.167.48:11339] [client 162.158.167.48] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSkKGf2ExAGdIXvjM5IQAAAQU"]
[Wed Jul 29 07:41:36.943965 2026] [:error] [pid 32190:tid 139878981375744] [client 172.71.154.27:10599] [client 172.71.154.27] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSkKGf2ExAGdIXvjM5IgAAARA"]
[Wed Jul 29 07:41:36.944398 2026] [:error] [pid 32190:tid 139878981375744] [client 172.71.154.27:10599] [client 172.71.154.27] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSkKGf2ExAGdIXvjM5IgAAARA"]
[Wed Jul 29 07:41:37.764983 2026] [:error] [pid 12728:tid 139878914234112] [client 172.71.158.125:12636] [client 172.71.158.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSkTqdFZ1TNKvQdY1ZAgAAAVg"]
[Wed Jul 29 07:41:37.765904 2026] [:error] [pid 12728:tid 139878914234112] [client 172.71.158.125:12636] [client 172.71.158.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSkTqdFZ1TNKvQdY1ZAgAAAVg"]
[Wed Jul 29 07:41:37.766443 2026] [:error] [pid 12728:tid 139878914234112] [client 172.71.158.125:12636] [client 172.71.158.125] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSkTqdFZ1TNKvQdY1ZAgAAAVg"]
[Wed Jul 29 07:41:37.769780 2026] [:error] [pid 32190:tid 139879040124672] [client 172.69.23.92:10121] [client 172.69.23.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSkaGf2ExAGdIXvjM5JQAAAQk"]
[Wed Jul 29 07:41:37.770660 2026] [:error] [pid 32190:tid 139879040124672] [client 172.69.23.92:10121] [client 172.69.23.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSkaGf2ExAGdIXvjM5JQAAAQk"]
[Wed Jul 29 07:41:37.771193 2026] [:error] [pid 32190:tid 139879040124672] [client 172.69.23.92:10121] [client 172.69.23.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSkaGf2ExAGdIXvjM5JQAAAQk"]
[Wed Jul 29 07:42:38.945819 2026] [:error] [pid 12781:tid 139879185397504] [client 104.22.17.233:11723] [client 104.22.17.233] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSzmwejwALtycjqdrAigAAAYA"]
[Wed Jul 29 07:42:38.945997 2026] [:error] [pid 12781:tid 139879006553856] [client 104.22.20.126:13531] [client 104.22.20.126] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSzmwejwALtycjqdrAiwAAAY0"]
[Wed Jul 29 07:42:38.946510 2026] [:error] [pid 12781:tid 139879185397504] [client 104.22.17.233:11723] [client 104.22.17.233] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSzmwejwALtycjqdrAigAAAYA"]
[Wed Jul 29 07:42:38.946795 2026] [:error] [pid 12781:tid 139879006553856] [client 104.22.20.126:13531] [client 104.22.20.126] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSzmwejwALtycjqdrAiwAAAY0"]
[Wed Jul 29 07:42:38.946944 2026] [:error] [pid 12781:tid 139879185397504] [client 104.22.17.233:11723] [client 104.22.17.233] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSzmwejwALtycjqdrAigAAAYA"]
[Wed Jul 29 07:42:38.947160 2026] [:error] [pid 12781:tid 139879006553856] [client 104.22.20.126:13531] [client 104.22.20.126] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSzmwejwALtycjqdrAiwAAAY0"]
[Wed Jul 29 07:42:39.037460 2026] [:error] [pid 12782:tid 139879177004800] [client 104.22.20.116:9443] [client 104.22.20.116] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSz0FdlBZRl6Abom12wwAAAcE"]
[Wed Jul 29 07:42:39.038309 2026] [:error] [pid 12782:tid 139879177004800] [client 104.22.20.116:9443] [client 104.22.20.116] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSz0FdlBZRl6Abom12wwAAAcE"]
[Wed Jul 29 07:42:39.038852 2026] [:error] [pid 12782:tid 139879177004800] [client 104.22.20.116:9443] [client 104.22.20.116] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSz0FdlBZRl6Abom12wwAAAcE"]
[Wed Jul 29 07:42:39.063774 2026] [:error] [pid 12781:tid 139878956197632] [client 104.22.20.117:13550] [client 104.22.20.117] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSzmwejwALtycjqdrAjAAAAZM"]
[Wed Jul 29 07:42:39.064682 2026] [:error] [pid 12781:tid 139878956197632] [client 104.22.20.117:13550] [client 104.22.20.117] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSzmwejwALtycjqdrAjAAAAZM"]
[Wed Jul 29 07:42:39.065214 2026] [:error] [pid 12781:tid 139878956197632] [client 104.22.20.117:13550] [client 104.22.20.117] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammSzmwejwALtycjqdrAjAAAAZM"]
[Wed Jul 29 07:44:31.645019 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.38.128:14154] [client 172.70.38.128] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammTP6Gf2ExAGdIXvjM7UQAAAQM"]
[Wed Jul 29 07:44:31.664628 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.38.128:14154] [client 172.70.38.128] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammTP6Gf2ExAGdIXvjM7UQAAAQM"]
[Wed Jul 29 07:44:31.665220 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.38.128:14154] [client 172.70.38.128] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammTP6Gf2ExAGdIXvjM7UQAAAQM"]
[Wed Jul 29 07:44:31.665257 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.38.128:14154] [client 172.70.38.128] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammTP6Gf2ExAGdIXvjM7UQAAAQM"]
[Wed Jul 29 07:44:31.735690 2026] [:error] [pid 12781:tid 139879065302784] [client 104.22.101.172:13422] [client 104.22.101.172] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammTP2wejwALtycjqdrBiAAAAYY"]
[Wed Jul 29 07:44:31.736322 2026] [:error] [pid 12781:tid 139879065302784] [client 104.22.101.172:13422] [client 104.22.101.172] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammTP2wejwALtycjqdrBiAAAAYY"]
[Wed Jul 29 07:44:31.736864 2026] [:error] [pid 12781:tid 139879065302784] [client 104.22.101.172:13422] [client 104.22.101.172] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammTP2wejwALtycjqdrBiAAAAYY"]
[Wed Jul 29 07:44:31.736901 2026] [:error] [pid 12781:tid 139879065302784] [client 104.22.101.172:13422] [client 104.22.101.172] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammTP2wejwALtycjqdrBiAAAAYY"]
[Wed Jul 29 07:44:40.135956 2026] [:error] [pid 29817:tid 139878989768448] [client 172.69.22.193:9339] [client 172.69.22.193] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammTSIpuIafV02klyJLvCwAAAE8"]
[Wed Jul 29 07:44:40.136567 2026] [:error] [pid 29817:tid 139878989768448] [client 172.69.22.193:9339] [client 172.69.22.193] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammTSIpuIafV02klyJLvCwAAAE8"]
[Wed Jul 29 07:44:40.136900 2026] [:error] [pid 29817:tid 139878989768448] [client 172.69.22.193:9339] [client 172.69.22.193] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammTSIpuIafV02klyJLvCwAAAE8"]
[Wed Jul 29 07:44:40.138193 2026] [:error] [pid 29817:tid 139878989768448] [client 104.22.20.127:9866] [client 104.22.20.127] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammTSIpuIafV02klyJLvDAAAAE8"]
[Wed Jul 29 07:44:40.138420 2026] [:error] [pid 29817:tid 139878989768448] [client 104.22.20.127:9866] [client 104.22.20.127] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammTSIpuIafV02klyJLvDAAAAE8"]
[Wed Jul 29 07:44:40.138633 2026] [:error] [pid 29817:tid 139878989768448] [client 104.22.20.127:9866] [client 104.22.20.127] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammTSIpuIafV02klyJLvDAAAAE8"]
[Wed Jul 29 07:44:40.547564 2026] [:error] [pid 29817:tid 139879065302784] [client 172.69.135.36:13584] [client 172.69.135.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammTSIpuIafV02klyJLvDgAAAEY"]
[Wed Jul 29 07:44:40.548415 2026] [:error] [pid 29817:tid 139879065302784] [client 172.69.135.36:13584] [client 172.69.135.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammTSIpuIafV02klyJLvDgAAAEY"]
[Wed Jul 29 07:44:40.548948 2026] [:error] [pid 29817:tid 139879065302784] [client 172.69.135.36:13584] [client 172.69.135.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammTSIpuIafV02klyJLvDgAAAEY"]
[Wed Jul 29 07:44:40.568927 2026] [:error] [pid 29913:tid 139879185397504] [client 172.71.158.124:11615] [client 172.71.158.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammTSAVDiGi-ktKYT-KXNAAAAMA"]
[Wed Jul 29 07:44:40.569633 2026] [:error] [pid 29913:tid 139879185397504] [client 172.71.158.124:11615] [client 172.71.158.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammTSAVDiGi-ktKYT-KXNAAAAMA"]
[Wed Jul 29 07:44:40.570029 2026] [:error] [pid 29913:tid 139879185397504] [client 172.71.158.124:11615] [client 172.71.158.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammTSAVDiGi-ktKYT-KXNAAAAMA"]
[Wed Jul 29 07:49:41.792446 2026] [:error] [pid 32190:tid 139879073695488] [client 104.22.17.233:11330] [client 104.22.17.233] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammUdaGf2ExAGdIXvjNBtwAAAQU"]
[Wed Jul 29 07:49:41.835382 2026] [:error] [pid 32190:tid 139878947804928] [client 172.69.134.203:11743] [client 172.69.134.203] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammUdaGf2ExAGdIXvjNBuAAAARQ"]
[Wed Jul 29 07:49:41.852484 2026] [:error] [pid 32190:tid 139879073695488] [client 104.22.17.233:11330] [client 104.22.17.233] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammUdaGf2ExAGdIXvjNBtwAAAQU"]
[Wed Jul 29 07:49:41.852871 2026] [:error] [pid 32190:tid 139878947804928] [client 172.69.134.203:11743] [client 172.69.134.203] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammUdaGf2ExAGdIXvjNBuAAAARQ"]
[Wed Jul 29 07:49:41.852933 2026] [:error] [pid 32190:tid 139879073695488] [client 104.22.17.233:11330] [client 104.22.17.233] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammUdaGf2ExAGdIXvjNBtwAAAQU"]
[Wed Jul 29 07:49:41.853494 2026] [:error] [pid 32190:tid 139878947804928] [client 172.69.134.203:11743] [client 172.69.134.203] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammUdaGf2ExAGdIXvjNBuAAAARQ"]
[Wed Jul 29 07:49:41.994297 2026] [:error] [pid 29913:tid 139879031731968] [client 172.69.135.36:11928] [client 172.69.135.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammUdQVDiGi-ktKYT-KZyQAAAMo"]
[Wed Jul 29 07:49:41.994456 2026] [:error] [pid 29818:tid 139878947804928] [client 172.71.158.124:14073] [client 172.71.158.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammUdcNm_eEjUiZv2_iloAAAAJQ"]
[Wed Jul 29 07:49:41.995064 2026] [:error] [pid 29818:tid 139878947804928] [client 172.71.158.124:14073] [client 172.71.158.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammUdcNm_eEjUiZv2_iloAAAAJQ"]
[Wed Jul 29 07:49:41.995107 2026] [:error] [pid 29913:tid 139879031731968] [client 172.69.135.36:11928] [client 172.69.135.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammUdQVDiGi-ktKYT-KZyQAAAMo"]
[Wed Jul 29 07:49:41.995420 2026] [:error] [pid 29818:tid 139878947804928] [client 172.71.158.124:14073] [client 172.71.158.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammUdcNm_eEjUiZv2_iloAAAAJQ"]
[Wed Jul 29 07:49:41.995573 2026] [:error] [pid 29913:tid 139879031731968] [client 172.69.135.36:11928] [client 172.69.135.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammUdQVDiGi-ktKYT-KZyQAAAMo"]
[Wed Jul 29 07:52:17.666416 2026] [:error] [pid 29818:tid 139879098873600] [client 172.71.144.54:9609] [client 172.71.144.54] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammVEcNm_eEjUiZv2_inDAAAAII"]
[Wed Jul 29 07:52:17.667207 2026] [:error] [pid 29818:tid 139879098873600] [client 172.71.144.54:9609] [client 172.71.144.54] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammVEcNm_eEjUiZv2_inDAAAAII"]
[Wed Jul 29 07:52:17.667851 2026] [:error] [pid 29818:tid 139879098873600] [client 172.71.144.54:9609] [client 172.71.144.54] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammVEcNm_eEjUiZv2_inDAAAAII"]
[Wed Jul 29 07:52:17.667908 2026] [:error] [pid 29818:tid 139879098873600] [client 172.71.144.54:9609] [client 172.71.144.54] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammVEcNm_eEjUiZv2_inDAAAAII"]
[Wed Jul 29 07:54:16.286183 2026] [:error] [pid 32190:tid 139878981375744] [client 172.68.151.129:12623] [client 172.68.151.129] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammViKGf2ExAGdIXvjNIpQAAARA"]
[Wed Jul 29 07:54:16.287160 2026] [:error] [pid 32190:tid 139878981375744] [client 172.68.151.129:12623] [client 172.68.151.129] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammViKGf2ExAGdIXvjNIpQAAARA"]
[Wed Jul 29 07:54:16.287793 2026] [:error] [pid 32190:tid 139878981375744] [client 172.68.151.129:12623] [client 172.68.151.129] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammViKGf2ExAGdIXvjNIpQAAARA"]
[Wed Jul 29 07:59:43.244432 2026] [:error] [pid 29913:tid 139878947804928] [client 172.69.134.202:10440] [client 172.69.134.202] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammWzwVDiGi-ktKYT-Kf7AAAANQ"]
[Wed Jul 29 07:59:43.244743 2026] [:error] [pid 12728:tid 139879073695488] [client 172.71.154.26:12990] [client 172.71.154.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammWzzqdFZ1TNKvQdY1f6AAAAUU"]
[Wed Jul 29 07:59:43.245177 2026] [:error] [pid 29913:tid 139878947804928] [client 172.69.134.202:10440] [client 172.69.134.202] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammWzwVDiGi-ktKYT-Kf7AAAANQ"]
[Wed Jul 29 07:59:43.245522 2026] [:error] [pid 29913:tid 139878947804928] [client 172.69.134.202:10440] [client 172.69.134.202] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammWzwVDiGi-ktKYT-Kf7AAAANQ"]
[Wed Jul 29 07:59:43.245533 2026] [:error] [pid 12728:tid 139879073695488] [client 172.71.154.26:12990] [client 172.71.154.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammWzzqdFZ1TNKvQdY1f6AAAAUU"]
[Wed Jul 29 07:59:43.246002 2026] [:error] [pid 12728:tid 139879073695488] [client 172.71.154.26:12990] [client 172.71.154.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammWzzqdFZ1TNKvQdY1f6AAAAUU"]
[Wed Jul 29 07:59:43.335824 2026] [:error] [pid 32190:tid 139879185397504] [client 104.22.20.116:14084] [client 104.22.20.116] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammWz6Gf2ExAGdIXvjNOAQAAAQA"]
[Wed Jul 29 07:59:43.337145 2026] [:error] [pid 32190:tid 139879185397504] [client 104.22.20.116:14084] [client 104.22.20.116] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammWz6Gf2ExAGdIXvjNOAQAAAQA"]
[Wed Jul 29 07:59:43.337840 2026] [:error] [pid 32190:tid 139879185397504] [client 104.22.20.116:14084] [client 104.22.20.116] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammWz6Gf2ExAGdIXvjNOAQAAAQA"]
[Wed Jul 29 07:59:43.372046 2026] [:error] [pid 32190:tid 139879185397504] [client 104.22.17.17:11281] [client 104.22.17.17] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammWz6Gf2ExAGdIXvjNOAgAAAQA"]
[Wed Jul 29 07:59:43.372759 2026] [:error] [pid 32190:tid 139879185397504] [client 104.22.17.17:11281] [client 104.22.17.17] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammWz6Gf2ExAGdIXvjNOAgAAAQA"]
[Wed Jul 29 07:59:43.373129 2026] [:error] [pid 32190:tid 139879185397504] [client 104.22.17.17:11281] [client 104.22.17.17] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammWz6Gf2ExAGdIXvjNOAgAAAQA"]
[Wed Jul 29 08:06:51.445047 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammYe8Nm_eEjUiZv2_irrAAAAJM"]
[Wed Jul 29 08:06:51.985289 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammYe8Nm_eEjUiZv2_irrAAAAJM"]
[Wed Jul 29 08:06:51.985645 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammYe8Nm_eEjUiZv2_irrAAAAJM"]
[Wed Jul 29 08:06:52.334840 2026] [:error] [pid 29818:tid 139879090480896] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "ammYfMNm_eEjUiZv2_irrwAAAIM"]
[Wed Jul 29 08:06:52.335778 2026] [:error] [pid 29818:tid 139879090480896] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "ammYfMNm_eEjUiZv2_irrwAAAIM"]
[Wed Jul 29 08:06:52.336323 2026] [:error] [pid 29818:tid 139879090480896] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "ammYfMNm_eEjUiZv2_irrwAAAIM"]
[Wed Jul 29 08:06:52.336577 2026] [:error] [pid 29818:tid 139879090480896] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "ammYfMNm_eEjUiZv2_irrwAAAIM"]
[Wed Jul 29 08:06:52.777982 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammYfMNm_eEjUiZv2_irsQAAAJc"]
[Wed Jul 29 08:06:52.778917 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammYfMNm_eEjUiZv2_irsQAAAJc"]
[Wed Jul 29 08:06:52.779239 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/x-www-form-urlencoded|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammYfMNm_eEjUiZv2_irsQAAAJc"]
[Wed Jul 29 08:06:52.779593 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammYfMNm_eEjUiZv2_irsQAAAJc"]
[Wed Jul 29 08:06:52.846274 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ammYfMNm_eEjUiZv2_irswAAAI0"]
[Wed Jul 29 08:06:52.846893 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ammYfMNm_eEjUiZv2_irswAAAI0"]
[Wed Jul 29 08:06:52.847325 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ammYfMNm_eEjUiZv2_irswAAAI0"]
[Wed Jul 29 08:06:52.847573 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env"] [unique_id "ammYfMNm_eEjUiZv2_irswAAAI0"]
[Wed Jul 29 08:06:53.068683 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "ammYfcNm_eEjUiZv2_irtAAAAIo"]
[Wed Jul 29 08:06:53.069594 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "ammYfcNm_eEjUiZv2_irtAAAAIo"]
[Wed Jul 29 08:06:53.070176 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "ammYfcNm_eEjUiZv2_irtAAAAIo"]
[Wed Jul 29 08:06:53.070444 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.local"] [unique_id "ammYfcNm_eEjUiZv2_irtAAAAIo"]
[Wed Jul 29 08:06:53.246915 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "ammYfcNm_eEjUiZv2_irtgAAAIE"]
[Wed Jul 29 08:06:53.247575 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "ammYfcNm_eEjUiZv2_irtgAAAIE"]
[Wed Jul 29 08:06:53.247993 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "ammYfcNm_eEjUiZv2_irtgAAAIE"]
[Wed Jul 29 08:06:53.248143 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.production"] [unique_id "ammYfcNm_eEjUiZv2_irtgAAAIE"]
[Wed Jul 29 08:06:53.334218 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "ammYfcNm_eEjUiZv2_irtwAAAJY"]
[Wed Jul 29 08:06:53.334928 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "ammYfcNm_eEjUiZv2_irtwAAAJY"]
[Wed Jul 29 08:06:53.335330 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "ammYfcNm_eEjUiZv2_irtwAAAJY"]
[Wed Jul 29 08:06:53.335565 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "ammYfcNm_eEjUiZv2_irtwAAAJY"]
[Wed Jul 29 08:06:53.534252 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "ammYfcNm_eEjUiZv2_iruQAAAI8"]
[Wed Jul 29 08:06:53.534704 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "ammYfcNm_eEjUiZv2_iruQAAAI8"]
[Wed Jul 29 08:06:53.535062 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "ammYfcNm_eEjUiZv2_iruQAAAI8"]
[Wed Jul 29 08:06:53.535210 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.development"] [unique_id "ammYfcNm_eEjUiZv2_iruQAAAI8"]
[Wed Jul 29 08:06:53.742769 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "ammYfcNm_eEjUiZv2_iruwAAAJg"]
[Wed Jul 29 08:06:53.743643 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "ammYfcNm_eEjUiZv2_iruwAAAJg"]
[Wed Jul 29 08:06:53.744198 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "ammYfcNm_eEjUiZv2_iruwAAAJg"]
[Wed Jul 29 08:06:53.744453 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.test"] [unique_id "ammYfcNm_eEjUiZv2_iruwAAAJg"]
[Wed Jul 29 08:06:53.851118 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "ammYfcNm_eEjUiZv2_irvAAAAJA"]
[Wed Jul 29 08:06:53.851795 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "ammYfcNm_eEjUiZv2_irvAAAAJA"]
[Wed Jul 29 08:06:53.852246 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "ammYfcNm_eEjUiZv2_irvAAAAJA"]
[Wed Jul 29 08:06:53.852429 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "ammYfcNm_eEjUiZv2_irvAAAAJA"]
[Wed Jul 29 08:06:53.938581 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "ammYfcNm_eEjUiZv2_irvQAAAII"]
[Wed Jul 29 08:06:53.939486 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "ammYfcNm_eEjUiZv2_irvQAAAII"]
[Wed Jul 29 08:06:53.940108 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "ammYfcNm_eEjUiZv2_irvQAAAII"]
[Wed Jul 29 08:06:53.940340 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "ammYfcNm_eEjUiZv2_irvQAAAII"]
[Wed Jul 29 08:06:53.996599 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "ammYfcNm_eEjUiZv2_irvgAAAJU"]
[Wed Jul 29 08:06:54.144399 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "ammYfcNm_eEjUiZv2_irvgAAAJU"]
[Wed Jul 29 08:06:54.144962 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "ammYfcNm_eEjUiZv2_irvgAAAJU"]
[Wed Jul 29 08:06:54.147847 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "ammYfcNm_eEjUiZv2_irvgAAAJU"]
[Wed Jul 29 08:06:54.248363 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "ammYfsNm_eEjUiZv2_irwAAAAIg"]
[Wed Jul 29 08:06:54.249384 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "ammYfsNm_eEjUiZv2_irwAAAAIg"]
[Wed Jul 29 08:06:54.250004 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "ammYfsNm_eEjUiZv2_irwAAAAIg"]
[Wed Jul 29 08:06:54.250269 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.save"] [unique_id "ammYfsNm_eEjUiZv2_irwAAAAIg"]
[Wed Jul 29 08:06:54.344389 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "ammYfsNm_eEjUiZv2_irwgAAAI4"]
[Wed Jul 29 08:06:54.345283 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "ammYfsNm_eEjUiZv2_irwgAAAI4"]
[Wed Jul 29 08:06:54.345785 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "ammYfsNm_eEjUiZv2_irwgAAAI4"]
[Wed Jul 29 08:06:54.346056 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.old"] [unique_id "ammYfsNm_eEjUiZv2_irwgAAAI4"]
[Wed Jul 29 08:06:54.434014 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "ammYfsNm_eEjUiZv2_irwwAAAJM"]
[Wed Jul 29 08:06:54.434606 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "ammYfsNm_eEjUiZv2_irwwAAAJM"]
[Wed Jul 29 08:06:54.435084 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "ammYfsNm_eEjUiZv2_irwwAAAJM"]
[Wed Jul 29 08:06:54.435243 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "ammYfsNm_eEjUiZv2_irwwAAAJM"]
[Wed Jul 29 08:06:54.491328 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "ammYfsNm_eEjUiZv2_irxAAAAIk"]
[Wed Jul 29 08:06:54.491915 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "ammYfsNm_eEjUiZv2_irxAAAAIk"]
[Wed Jul 29 08:06:54.492279 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "ammYfsNm_eEjUiZv2_irxAAAAIk"]
[Wed Jul 29 08:06:54.492428 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.example"] [unique_id "ammYfsNm_eEjUiZv2_irxAAAAIk"]
[Wed Jul 29 08:06:54.551475 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "ammYfsNm_eEjUiZv2_irxQAAAIA"]
[Wed Jul 29 08:06:54.552269 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "ammYfsNm_eEjUiZv2_irxQAAAIA"]
[Wed Jul 29 08:06:54.552750 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "ammYfsNm_eEjUiZv2_irxQAAAIA"]
[Wed Jul 29 08:06:54.553012 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "ammYfsNm_eEjUiZv2_irxQAAAIA"]
[Wed Jul 29 08:06:54.634144 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "ammYfsNm_eEjUiZv2_irxwAAAIw"]
[Wed Jul 29 08:06:54.634773 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "ammYfsNm_eEjUiZv2_irxwAAAIw"]
[Wed Jul 29 08:06:54.635255 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "ammYfsNm_eEjUiZv2_irxwAAAIw"]
[Wed Jul 29 08:06:54.635482 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "ammYfsNm_eEjUiZv2_irxwAAAIw"]
[Wed Jul 29 08:06:54.699386 2026] [:error] [pid 29818:tid 139879090480896] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "ammYfsNm_eEjUiZv2_iryAAAAIM"]
[Wed Jul 29 08:06:54.700010 2026] [:error] [pid 29818:tid 139879090480896] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "ammYfsNm_eEjUiZv2_iryAAAAIM"]
[Wed Jul 29 08:06:54.700352 2026] [:error] [pid 29818:tid 139879090480896] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "ammYfsNm_eEjUiZv2_iryAAAAIM"]
[Wed Jul 29 08:06:54.700520 2026] [:error] [pid 29818:tid 139879090480896] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "ammYfsNm_eEjUiZv2_iryAAAAIM"]
[Wed Jul 29 08:06:54.791255 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "ammYfsNm_eEjUiZv2_iryQAAAIs"]
[Wed Jul 29 08:06:54.791842 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "ammYfsNm_eEjUiZv2_iryQAAAIs"]
[Wed Jul 29 08:06:54.792228 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "ammYfsNm_eEjUiZv2_iryQAAAIs"]
[Wed Jul 29 08:06:54.792377 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.ci"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "ammYfsNm_eEjUiZv2_iryQAAAIs"]
[Wed Jul 29 08:06:54.859188 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "ammYfsNm_eEjUiZv2_irygAAAJc"]
[Wed Jul 29 08:06:54.860120 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "ammYfsNm_eEjUiZv2_irygAAAJc"]
[Wed Jul 29 08:06:54.860639 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "ammYfsNm_eEjUiZv2_irygAAAJc"]
[Wed Jul 29 08:06:54.860926 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.docker"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "ammYfsNm_eEjUiZv2_irygAAAJc"]
[Wed Jul 29 08:06:54.934091 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "ammYfsNm_eEjUiZv2_irywAAAIY"]
[Wed Jul 29 08:06:54.934767 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "ammYfsNm_eEjUiZv2_irywAAAIY"]
[Wed Jul 29 08:06:54.935185 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "ammYfsNm_eEjUiZv2_irywAAAIY"]
[Wed Jul 29 08:06:54.935336 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.live"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.live"] [unique_id "ammYfsNm_eEjUiZv2_irywAAAIY"]
[Wed Jul 29 08:06:55.039223 2026] [:error] [pid 29818:tid 139879073695488] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "ammYf8Nm_eEjUiZv2_irzQAAAIU"]
[Wed Jul 29 08:06:55.040009 2026] [:error] [pid 29818:tid 139879073695488] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "ammYf8Nm_eEjUiZv2_irzQAAAIU"]
[Wed Jul 29 08:06:55.040600 2026] [:error] [pid 29818:tid 139879073695488] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "ammYf8Nm_eEjUiZv2_irzQAAAIU"]
[Wed Jul 29 08:06:55.040840 2026] [:error] [pid 29818:tid 139879073695488] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.preprod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "ammYf8Nm_eEjUiZv2_irzQAAAIU"]
[Wed Jul 29 08:06:55.172106 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "ammYf8Nm_eEjUiZv2_irzgAAAIE"]
[Wed Jul 29 08:06:55.172691 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "ammYf8Nm_eEjUiZv2_irzgAAAIE"]
[Wed Jul 29 08:06:55.173064 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "ammYf8Nm_eEjUiZv2_irzgAAAIE"]
[Wed Jul 29 08:06:55.173213 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.uat"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "ammYf8Nm_eEjUiZv2_irzgAAAIE"]
[Wed Jul 29 08:06:55.244291 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "ammYf8Nm_eEjUiZv2_ir0AAAAIc"]
[Wed Jul 29 08:06:55.244922 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "ammYf8Nm_eEjUiZv2_ir0AAAAIc"]
[Wed Jul 29 08:06:55.245315 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "ammYf8Nm_eEjUiZv2_ir0AAAAIc"]
[Wed Jul 29 08:06:55.245505 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "ammYf8Nm_eEjUiZv2_ir0AAAAIc"]
[Wed Jul 29 08:06:55.334538 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "ammYf8Nm_eEjUiZv2_ir0QAAAI8"]
[Wed Jul 29 08:06:55.335373 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "ammYf8Nm_eEjUiZv2_ir0QAAAI8"]
[Wed Jul 29 08:06:55.335907 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "ammYf8Nm_eEjUiZv2_ir0QAAAI8"]
[Wed Jul 29 08:06:55.336164 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "ammYf8Nm_eEjUiZv2_ir0QAAAI8"]
[Wed Jul 29 08:06:55.388624 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "ammYf8Nm_eEjUiZv2_ir0gAAAJg"]
[Wed Jul 29 08:06:55.389222 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "ammYf8Nm_eEjUiZv2_ir0gAAAJg"]
[Wed Jul 29 08:06:55.389437 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Pattern match "\\\\.[^.~]+~(?:/.*|)$" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1060"] [id "920500"] [msg "Attempt to access a backup or working file"] [data ".env~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "ammYf8Nm_eEjUiZv2_ir0gAAAJg"]
[Wed Jul 29 08:06:55.389618 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "ammYf8Nm_eEjUiZv2_ir0gAAAJg"]
[Wed Jul 29 08:06:55.389767 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env~"] [unique_id "ammYf8Nm_eEjUiZv2_ir0gAAAJg"]
[Wed Jul 29 08:06:55.448113 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env1"] [unique_id "ammYf8Nm_eEjUiZv2_ir0wAAAIQ"]
[Wed Jul 29 08:06:55.448732 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env1"] [unique_id "ammYf8Nm_eEjUiZv2_ir0wAAAIQ"]
[Wed Jul 29 08:06:55.449161 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env1"] [unique_id "ammYf8Nm_eEjUiZv2_ir0wAAAIQ"]
[Wed Jul 29 08:06:55.449300 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env1"] [unique_id "ammYf8Nm_eEjUiZv2_ir0wAAAIQ"]
[Wed Jul 29 08:06:55.544122 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env2"] [unique_id "ammYf8Nm_eEjUiZv2_ir1gAAAII"]
[Wed Jul 29 08:06:55.544506 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env2"] [unique_id "ammYf8Nm_eEjUiZv2_ir1gAAAII"]
[Wed Jul 29 08:06:55.576190 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env2"] [unique_id "ammYf8Nm_eEjUiZv2_ir1gAAAII"]
[Wed Jul 29 08:06:55.576408 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env2"] [unique_id "ammYf8Nm_eEjUiZv2_ir1gAAAII"]
[Wed Jul 29 08:06:55.644660 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "ammYf8Nm_eEjUiZv2_ir1wAAAJI"]
[Wed Jul 29 08:06:55.645420 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "ammYf8Nm_eEjUiZv2_ir1wAAAJI"]
[Wed Jul 29 08:06:55.645934 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "ammYf8Nm_eEjUiZv2_ir1wAAAJI"]
[Wed Jul 29 08:06:55.646088 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_copy"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "ammYf8Nm_eEjUiZv2_ir1wAAAJI"]
[Wed Jul 29 08:06:55.740429 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "ammYf8Nm_eEjUiZv2_ir2QAAAJU"]
[Wed Jul 29 08:06:55.740958 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "ammYf8Nm_eEjUiZv2_ir2QAAAJU"]
[Wed Jul 29 08:06:55.741377 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "ammYf8Nm_eEjUiZv2_ir2QAAAJU"]
[Wed Jul 29 08:06:55.741629 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.txt"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "ammYf8Nm_eEjUiZv2_ir2QAAAJU"]
[Wed Jul 29 08:06:55.834629 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.json"] [unique_id "ammYf8Nm_eEjUiZv2_ir2gAAAJQ"]
[Wed Jul 29 08:06:55.835665 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.json"] [unique_id "ammYf8Nm_eEjUiZv2_ir2gAAAJQ"]
[Wed Jul 29 08:06:55.836331 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.json"] [unique_id "ammYf8Nm_eEjUiZv2_ir2gAAAJQ"]
[Wed Jul 29 08:06:55.836597 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.json"] [unique_id "ammYf8Nm_eEjUiZv2_ir2gAAAJQ"]
[Wed Jul 29 08:06:55.934898 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "ammYf8Nm_eEjUiZv2_ir2wAAAI4"]
[Wed Jul 29 08:06:55.935877 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "ammYf8Nm_eEjUiZv2_ir2wAAAI4"]
[Wed Jul 29 08:06:55.936642 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "ammYf8Nm_eEjUiZv2_ir2wAAAI4"]
[Wed Jul 29 08:06:55.936941 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yaml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "ammYf8Nm_eEjUiZv2_ir2wAAAI4"]
[Wed Jul 29 08:06:56.044487 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "ammYgMNm_eEjUiZv2_ir3QAAAJM"]
[Wed Jul 29 08:06:56.044918 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "ammYgMNm_eEjUiZv2_ir3QAAAJM"]
[Wed Jul 29 08:06:56.045299 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "ammYgMNm_eEjUiZv2_ir3QAAAJM"]
[Wed Jul 29 08:06:56.045494 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "ammYgMNm_eEjUiZv2_ir3QAAAJM"]
[Wed Jul 29 08:06:56.145258 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir3gAAAIA"]
[Wed Jul 29 08:06:56.145858 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir3gAAAIA"]
[Wed Jul 29 08:06:56.146266 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir3gAAAIA"]
[Wed Jul 29 08:06:56.146421 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/app/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir3gAAAIA"]
[Wed Jul 29 08:06:56.244991 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir3wAAAJE"]
[Wed Jul 29 08:06:56.245851 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir3wAAAJE"]
[Wed Jul 29 08:06:56.246455 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir3wAAAJE"]
[Wed Jul 29 08:06:56.246725 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir3wAAAJE"]
[Wed Jul 29 08:06:56.341023 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir4QAAAIw"]
[Wed Jul 29 08:06:56.344015 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir4QAAAIw"]
[Wed Jul 29 08:06:56.344840 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir4QAAAIw"]
[Wed Jul 29 08:06:56.345757 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir4QAAAIw"]
[Wed Jul 29 08:06:56.434346 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir4gAAAIs"]
[Wed Jul 29 08:06:56.435050 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir4gAAAIs"]
[Wed Jul 29 08:06:56.435420 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir4gAAAIs"]
[Wed Jul 29 08:06:56.435634 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/web/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir4gAAAIs"]
[Wed Jul 29 08:06:56.489020 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/site/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir4wAAAJc"]
[Wed Jul 29 08:06:56.489569 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/site/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir4wAAAJc"]
[Wed Jul 29 08:06:56.489965 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/site/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir4wAAAJc"]
[Wed Jul 29 08:06:56.490118 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/site/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir4wAAAJc"]
[Wed Jul 29 08:06:56.539477 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/public/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir5AAAAI0"]
[Wed Jul 29 08:06:56.540186 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/public/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir5AAAAI0"]
[Wed Jul 29 08:06:56.540610 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/public/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir5AAAAI0"]
[Wed Jul 29 08:06:56.540792 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/public/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir5AAAAI0"]
[Wed Jul 29 08:06:56.599788 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir5QAAAIo"]
[Wed Jul 29 08:06:56.733926 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir5QAAAIo"]
[Wed Jul 29 08:06:56.734334 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir5QAAAIo"]
[Wed Jul 29 08:06:56.734519 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.15:13348] [client 162.158.49.15] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir5QAAAIo"]
[Wed Jul 29 08:06:56.795426 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir5wAAAIE"]
[Wed Jul 29 08:06:56.855986 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir5wAAAIE"]
[Wed Jul 29 08:06:56.856423 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir5wAAAIE"]
[Wed Jul 29 08:06:56.856602 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir5wAAAIE"]
[Wed Jul 29 08:06:56.934662 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir6AAAAJY"]
[Wed Jul 29 08:06:56.935327 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir6AAAAJY"]
[Wed Jul 29 08:06:56.935757 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir6AAAAJY"]
[Wed Jul 29 08:06:56.935924 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/server/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir6AAAAJY"]
[Wed Jul 29 08:06:56.988536 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir6QAAAIc"]
[Wed Jul 29 08:06:56.989206 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir6QAAAIc"]
[Wed Jul 29 08:06:56.989610 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir6QAAAIc"]
[Wed Jul 29 08:06:56.989765 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /frontend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "ammYgMNm_eEjUiZv2_ir6QAAAIc"]
[Wed Jul 29 08:06:57.055491 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir6wAAAJg"]
[Wed Jul 29 08:06:57.056161 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir6wAAAJg"]
[Wed Jul 29 08:06:57.056655 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir6wAAAJg"]
[Wed Jul 29 08:06:57.056926 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/src/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir6wAAAJg"]
[Wed Jul 29 08:06:57.145710 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir7AAAAIQ"]
[Wed Jul 29 08:06:57.146338 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir7AAAAIQ"]
[Wed Jul 29 08:06:57.146779 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir7AAAAIQ"]
[Wed Jul 29 08:06:57.147001 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/core/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir7AAAAIQ"]
[Wed Jul 29 08:06:57.253336 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir7QAAAJA"]
[Wed Jul 29 08:06:57.254131 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir7QAAAJA"]
[Wed Jul 29 08:06:57.254516 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir7QAAAJA"]
[Wed Jul 29 08:06:57.254688 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir7QAAAJA"]
[Wed Jul 29 08:06:57.337229 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir7wAAAII"]
[Wed Jul 29 08:06:57.337806 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir7wAAAII"]
[Wed Jul 29 08:06:57.338237 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir7wAAAII"]
[Wed Jul 29 08:06:57.338464 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/config/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir7wAAAII"]
[Wed Jul 29 08:06:57.391790 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/private/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir8AAAAJU"]
[Wed Jul 29 08:06:57.392424 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/private/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir8AAAAJU"]
[Wed Jul 29 08:06:57.392931 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/private/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir8AAAAJU"]
[Wed Jul 29 08:06:57.393123 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /private/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/private/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir8AAAAJU"]
[Wed Jul 29 08:06:57.443976 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir8QAAAIg"]
[Wed Jul 29 08:06:57.444591 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir8QAAAIg"]
[Wed Jul 29 08:06:57.445007 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir8QAAAIg"]
[Wed Jul 29 08:06:57.445169 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/application/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir8QAAAIg"]
[Wed Jul 29 08:06:57.542295 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir8gAAAJQ"]
[Wed Jul 29 08:06:57.542878 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir8gAAAJQ"]
[Wed Jul 29 08:06:57.543277 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir8gAAAJQ"]
[Wed Jul 29 08:06:57.543452 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /bootstrap/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir8gAAAJQ"]
[Wed Jul 29 08:06:57.634787 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/database/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9AAAAJM"]
[Wed Jul 29 08:06:57.635463 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/database/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9AAAAJM"]
[Wed Jul 29 08:06:57.635890 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/database/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9AAAAJM"]
[Wed Jul 29 08:06:57.636073 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/database/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9AAAAJM"]
[Wed Jul 29 08:06:57.689567 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9QAAAIk"]
[Wed Jul 29 08:06:57.690358 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9QAAAIk"]
[Wed Jul 29 08:06:57.690816 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9QAAAIk"]
[Wed Jul 29 08:06:57.691043 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9QAAAIk"]
[Wed Jul 29 08:06:57.752646 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9gAAAIA"]
[Wed Jul 29 08:06:57.753456 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9gAAAIA"]
[Wed Jul 29 08:06:57.753932 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9gAAAIA"]
[Wed Jul 29 08:06:57.754088 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /var/www/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9gAAAIA"]
[Wed Jul 29 08:06:57.835009 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9wAAAJE"]
[Wed Jul 29 08:06:57.835849 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9wAAAJE"]
[Wed Jul 29 08:06:57.836358 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9wAAAJE"]
[Wed Jul 29 08:06:57.836634 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /var/www/html/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir9wAAAJE"]
[Wed Jul 29 08:06:57.888656 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/current/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir-QAAAIw"]
[Wed Jul 29 08:06:57.889116 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/current/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir-QAAAIw"]
[Wed Jul 29 08:06:57.889465 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/current/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir-QAAAIw"]
[Wed Jul 29 08:06:57.889702 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /current/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/current/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir-QAAAIw"]
[Wed Jul 29 08:06:57.941679 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/release/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir-gAAAIs"]
[Wed Jul 29 08:06:57.942218 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/release/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir-gAAAIs"]
[Wed Jul 29 08:06:57.942574 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/release/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir-gAAAIs"]
[Wed Jul 29 08:06:57.942751 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /release/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/release/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir-gAAAIs"]
[Wed Jul 29 08:06:58.081141 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir-wAAAJc"]
[Wed Jul 29 08:06:58.081799 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir-wAAAJc"]
[Wed Jul 29 08:06:58.082167 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir-wAAAJc"]
[Wed Jul 29 08:06:58.082320 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /releases/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "ammYgcNm_eEjUiZv2_ir-wAAAJc"]
[Wed Jul 29 08:06:58.136268 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "ammYgsNm_eEjUiZv2_ir_QAAAIo"]
[Wed Jul 29 08:06:58.136877 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "ammYgsNm_eEjUiZv2_ir_QAAAIo"]
[Wed Jul 29 08:06:58.137237 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "ammYgsNm_eEjUiZv2_ir_QAAAIo"]
[Wed Jul 29 08:06:58.137388 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /shared/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "ammYgsNm_eEjUiZv2_ir_QAAAIo"]
[Wed Jul 29 08:06:58.234284 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "ammYgsNm_eEjUiZv2_ir_gAAAIY"]
[Wed Jul 29 08:06:58.234991 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "ammYgsNm_eEjUiZv2_ir_gAAAIY"]
[Wed Jul 29 08:06:58.235370 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "ammYgsNm_eEjUiZv2_ir_gAAAIY"]
[Wed Jul 29 08:06:58.235630 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /deploy/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "ammYgsNm_eEjUiZv2_ir_gAAAIY"]
[Wed Jul 29 08:06:58.284400 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/build/.env"] [unique_id "ammYgsNm_eEjUiZv2_ir_wAAAIE"]
[Wed Jul 29 08:06:58.284916 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/build/.env"] [unique_id "ammYgsNm_eEjUiZv2_ir_wAAAIE"]
[Wed Jul 29 08:06:58.285255 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/build/.env"] [unique_id "ammYgsNm_eEjUiZv2_ir_wAAAIE"]
[Wed Jul 29 08:06:58.285417 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /build/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/build/.env"] [unique_id "ammYgsNm_eEjUiZv2_ir_wAAAIE"]
[Wed Jul 29 08:06:58.344313 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "ammYgsNm_eEjUiZv2_isAAAAAJY"]
[Wed Jul 29 08:06:58.344898 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "ammYgsNm_eEjUiZv2_isAAAAAJY"]
[Wed Jul 29 08:06:58.345297 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "ammYgsNm_eEjUiZv2_isAAAAAJY"]
[Wed Jul 29 08:06:58.345505 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /dist/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "ammYgsNm_eEjUiZv2_isAAAAAJY"]
[Wed Jul 29 08:06:58.395273 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "ammYgsNm_eEjUiZv2_isAgAAAI8"]
[Wed Jul 29 08:06:58.395854 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "ammYgsNm_eEjUiZv2_isAgAAAI8"]
[Wed Jul 29 08:06:58.396201 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "ammYgsNm_eEjUiZv2_isAgAAAI8"]
[Wed Jul 29 08:06:58.396349 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public_html/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "ammYgsNm_eEjUiZv2_isAgAAAI8"]
[Wed Jul 29 08:06:58.462193 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "ammYgsNm_eEjUiZv2_isAwAAAJg"]
[Wed Jul 29 08:06:58.462748 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "ammYgsNm_eEjUiZv2_isAwAAAJg"]
[Wed Jul 29 08:06:58.463100 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "ammYgsNm_eEjUiZv2_isAwAAAJg"]
[Wed Jul 29 08:06:58.463248 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /htdocs/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "ammYgsNm_eEjUiZv2_isAwAAAJg"]
[Wed Jul 29 08:06:58.534152 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/www/.env"] [unique_id "ammYgsNm_eEjUiZv2_isBAAAAIQ"]
[Wed Jul 29 08:06:58.534795 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/www/.env"] [unique_id "ammYgsNm_eEjUiZv2_isBAAAAIQ"]
[Wed Jul 29 08:06:58.535166 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/www/.env"] [unique_id "ammYgsNm_eEjUiZv2_isBAAAAIQ"]
[Wed Jul 29 08:06:58.535362 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /www/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/www/.env"] [unique_id "ammYgsNm_eEjUiZv2_isBAAAAIQ"]
[Wed Jul 29 08:06:58.643636 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/html/.env"] [unique_id "ammYgsNm_eEjUiZv2_isBQAAAJA"]
[Wed Jul 29 08:06:58.644504 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/html/.env"] [unique_id "ammYgsNm_eEjUiZv2_isBQAAAJA"]
[Wed Jul 29 08:06:58.645028 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/html/.env"] [unique_id "ammYgsNm_eEjUiZv2_isBQAAAJA"]
[Wed Jul 29 08:06:58.645273 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /html/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/html/.env"] [unique_id "ammYgsNm_eEjUiZv2_isBQAAAJA"]
[Wed Jul 29 08:06:58.771159 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/live/.env"] [unique_id "ammYgsNm_eEjUiZv2_isBwAAAJI"]
[Wed Jul 29 08:06:58.771748 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/live/.env"] [unique_id "ammYgsNm_eEjUiZv2_isBwAAAJI"]
[Wed Jul 29 08:06:58.772103 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/live/.env"] [unique_id "ammYgsNm_eEjUiZv2_isBwAAAJI"]
[Wed Jul 29 08:06:58.772264 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /live/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/live/.env"] [unique_id "ammYgsNm_eEjUiZv2_isBwAAAJI"]
[Wed Jul 29 08:06:58.844342 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "ammYgsNm_eEjUiZv2_isCAAAAJU"]
[Wed Jul 29 08:06:58.845012 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "ammYgsNm_eEjUiZv2_isCAAAAJU"]
[Wed Jul 29 08:06:58.845425 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "ammYgsNm_eEjUiZv2_isCAAAAJU"]
[Wed Jul 29 08:06:58.845597 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prod/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "ammYgsNm_eEjUiZv2_isCAAAAJU"]
[Wed Jul 29 08:06:58.934091 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "ammYgsNm_eEjUiZv2_isCQAAAIg"]
[Wed Jul 29 08:06:58.934906 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "ammYgsNm_eEjUiZv2_isCQAAAIg"]
[Wed Jul 29 08:06:58.935360 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "ammYgsNm_eEjUiZv2_isCQAAAIg"]
[Wed Jul 29 08:06:58.935601 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /dev/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "ammYgsNm_eEjUiZv2_isCQAAAIg"]
[Wed Jul 29 08:06:59.034468 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isCwAAAI4"]
[Wed Jul 29 08:06:59.035337 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isCwAAAI4"]
[Wed Jul 29 08:06:59.035911 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isCwAAAI4"]
[Wed Jul 29 08:06:59.036164 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /staging/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isCwAAAI4"]
[Wed Jul 29 08:06:59.087312 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isDAAAAJM"]
[Wed Jul 29 08:06:59.087872 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isDAAAAJM"]
[Wed Jul 29 08:06:59.088245 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isDAAAAJM"]
[Wed Jul 29 08:06:59.088397 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /opt/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isDAAAAJM"]
[Wed Jul 29 08:06:59.142512 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isDQAAAIk"]
[Wed Jul 29 08:06:59.143331 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isDQAAAIk"]
[Wed Jul 29 08:06:59.143892 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isDQAAAIk"]
[Wed Jul 29 08:06:59.144132 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isDQAAAIk"]
[Wed Jul 29 08:06:59.194655 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isDwAAAJE"]
[Wed Jul 29 08:06:59.195003 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isDwAAAJE"]
[Wed Jul 29 08:06:59.195248 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isDwAAAJE"]
[Wed Jul 29 08:06:59.195385 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /symfony/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isDwAAAJE"]
[Wed Jul 29 08:06:59.255359 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isEAAAAIw"]
[Wed Jul 29 08:06:59.256003 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isEAAAAIw"]
[Wed Jul 29 08:06:59.256470 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isEAAAAIw"]
[Wed Jul 29 08:06:59.256753 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wordpress/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isEAAAAIw"]
[Wed Jul 29 08:06:59.344421 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isEQAAAIs"]
[Wed Jul 29 08:06:59.345165 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isEQAAAIs"]
[Wed Jul 29 08:06:59.345712 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isEQAAAIs"]
[Wed Jul 29 08:06:59.345961 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isEQAAAIs"]
[Wed Jul 29 08:06:59.461521 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isEwAAAI0"]
[Wed Jul 29 08:06:59.462245 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isEwAAAI0"]
[Wed Jul 29 08:06:59.462708 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isEwAAAI0"]
[Wed Jul 29 08:06:59.462872 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cms/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isEwAAAI0"]
[Wed Jul 29 08:06:59.541350 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isFQAAAIo"]
[Wed Jul 29 08:06:59.542167 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isFQAAAIo"]
[Wed Jul 29 08:06:59.542707 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isFQAAAIo"]
[Wed Jul 29 08:06:59.542936 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /drupal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isFQAAAIo"]
[Wed Jul 29 08:06:59.634781 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isFgAAAIY"]
[Wed Jul 29 08:06:59.635475 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isFgAAAIY"]
[Wed Jul 29 08:06:59.636079 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isFgAAAIY"]
[Wed Jul 29 08:06:59.636265 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /joomla/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isFgAAAIY"]
[Wed Jul 29 08:06:59.694986 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isFwAAAIE"]
[Wed Jul 29 08:06:59.695535 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isFwAAAIE"]
[Wed Jul 29 08:06:59.695927 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isFwAAAIE"]
[Wed Jul 29 08:06:59.696079 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /magento/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isFwAAAIE"]
[Wed Jul 29 08:06:59.770370 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isGQAAAIc"]
[Wed Jul 29 08:06:59.771004 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isGQAAAIc"]
[Wed Jul 29 08:06:59.771397 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isGQAAAIc"]
[Wed Jul 29 08:06:59.771565 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /shopify/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isGQAAAIc"]
[Wed Jul 29 08:06:59.834745 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isGgAAAI8"]
[Wed Jul 29 08:06:59.835445 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isGgAAAI8"]
[Wed Jul 29 08:06:59.835917 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isGgAAAI8"]
[Wed Jul 29 08:06:59.836093 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prestashop/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isGgAAAI8"]
[Wed Jul 29 08:06:59.890185 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isGwAAAJg"]
[Wed Jul 29 08:06:59.890864 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isGwAAAJg"]
[Wed Jul 29 08:06:59.891244 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isGwAAAJg"]
[Wed Jul 29 08:06:59.891395 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /codeigniter/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isGwAAAJg"]
[Wed Jul 29 08:06:59.948674 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isHAAAAIQ"]
[Wed Jul 29 08:06:59.949690 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isHAAAAIQ"]
[Wed Jul 29 08:06:59.950248 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isHAAAAIQ"]
[Wed Jul 29 08:06:59.950505 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cakephp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "ammYg8Nm_eEjUiZv2_isHAAAAIQ"]
[Wed Jul 29 08:07:00.044991 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "ammYhMNm_eEjUiZv2_isHgAAAII"]
[Wed Jul 29 08:07:00.045883 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "ammYhMNm_eEjUiZv2_isHgAAAII"]
[Wed Jul 29 08:07:00.046437 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "ammYhMNm_eEjUiZv2_isHgAAAII"]
[Wed Jul 29 08:07:00.046684 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /zend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "ammYhMNm_eEjUiZv2_isHgAAAII"]
[Wed Jul 29 08:07:00.147006 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "ammYhMNm_eEjUiZv2_isHwAAAJI"]
[Wed Jul 29 08:07:00.147894 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "ammYhMNm_eEjUiZv2_isHwAAAJI"]
[Wed Jul 29 08:07:00.148457 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "ammYhMNm_eEjUiZv2_isHwAAAJI"]
[Wed Jul 29 08:07:00.148750 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /yii/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "ammYhMNm_eEjUiZv2_isHwAAAJI"]
[Wed Jul 29 08:07:00.234427 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "ammYhMNm_eEjUiZv2_isIAAAAJU"]
[Wed Jul 29 08:07:00.235301 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "ammYhMNm_eEjUiZv2_isIAAAAJU"]
[Wed Jul 29 08:07:00.235800 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "ammYhMNm_eEjUiZv2_isIAAAAJU"]
[Wed Jul 29 08:07:00.236034 2026] [:error] [pid 29818:tid 139878939412224] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel5/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "ammYhMNm_eEjUiZv2_isIAAAAJU"]
[Wed Jul 29 08:07:00.290045 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "ammYhMNm_eEjUiZv2_isIgAAAJQ"]
[Wed Jul 29 08:07:00.290989 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "ammYhMNm_eEjUiZv2_isIgAAAJQ"]
[Wed Jul 29 08:07:00.291543 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "ammYhMNm_eEjUiZv2_isIgAAAJQ"]
[Wed Jul 29 08:07:00.291795 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "ammYhMNm_eEjUiZv2_isIgAAAJQ"]
[Wed Jul 29 08:07:00.364652 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "ammYhMNm_eEjUiZv2_isIwAAAI4"]
[Wed Jul 29 08:07:00.365519 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "ammYhMNm_eEjUiZv2_isIwAAAI4"]
[Wed Jul 29 08:07:00.366092 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "ammYhMNm_eEjUiZv2_isIwAAAI4"]
[Wed Jul 29 08:07:00.366351 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "ammYhMNm_eEjUiZv2_isIwAAAI4"]
[Wed Jul 29 08:07:00.442642 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "ammYhMNm_eEjUiZv2_isJAAAAJM"]
[Wed Jul 29 08:07:00.443516 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "ammYhMNm_eEjUiZv2_isJAAAAJM"]
[Wed Jul 29 08:07:00.444076 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "ammYhMNm_eEjUiZv2_isJAAAAJM"]
[Wed Jul 29 08:07:00.444338 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v3/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "ammYhMNm_eEjUiZv2_isJAAAAJM"]
[Wed Jul 29 08:07:00.538796 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "ammYhMNm_eEjUiZv2_isJQAAAIk"]
[Wed Jul 29 08:07:00.539608 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "ammYhMNm_eEjUiZv2_isJQAAAIk"]
[Wed Jul 29 08:07:00.540149 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "ammYhMNm_eEjUiZv2_isJQAAAIk"]
[Wed Jul 29 08:07:00.540391 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "ammYhMNm_eEjUiZv2_isJQAAAIk"]
[Wed Jul 29 08:07:00.634274 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "ammYhMNm_eEjUiZv2_isJwAAAJE"]
[Wed Jul 29 08:07:00.635108 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "ammYhMNm_eEjUiZv2_isJwAAAJE"]
[Wed Jul 29 08:07:00.635667 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "ammYhMNm_eEjUiZv2_isJwAAAJE"]
[Wed Jul 29 08:07:00.635929 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "ammYhMNm_eEjUiZv2_isJwAAAJE"]
[Wed Jul 29 08:07:00.693019 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "ammYhMNm_eEjUiZv2_isKAAAAIw"]
[Wed Jul 29 08:07:00.693902 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "ammYhMNm_eEjUiZv2_isKAAAAIw"]
[Wed Jul 29 08:07:00.694520 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "ammYhMNm_eEjUiZv2_isKAAAAIw"]
[Wed Jul 29 08:07:00.694787 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /rest/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "ammYhMNm_eEjUiZv2_isKAAAAIw"]
[Wed Jul 29 08:07:00.751452 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "ammYhMNm_eEjUiZv2_isKQAAAIs"]
[Wed Jul 29 08:07:00.752339 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "ammYhMNm_eEjUiZv2_isKQAAAIs"]
[Wed Jul 29 08:07:00.752915 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "ammYhMNm_eEjUiZv2_isKQAAAIs"]
[Wed Jul 29 08:07:00.753179 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /graphql/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "ammYhMNm_eEjUiZv2_isKQAAAIs"]
[Wed Jul 29 08:07:00.844667 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "ammYhMNm_eEjUiZv2_isKgAAAJc"]
[Wed Jul 29 08:07:00.845497 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "ammYhMNm_eEjUiZv2_isKgAAAJc"]
[Wed Jul 29 08:07:00.846045 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "ammYhMNm_eEjUiZv2_isKgAAAJc"]
[Wed Jul 29 08:07:00.846299 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /gateway/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "ammYhMNm_eEjUiZv2_isKgAAAJc"]
[Wed Jul 29 08:07:00.937284 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "ammYhMNm_eEjUiZv2_isLAAAAIo"]
[Wed Jul 29 08:07:00.938013 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "ammYhMNm_eEjUiZv2_isLAAAAIo"]
[Wed Jul 29 08:07:00.938440 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "ammYhMNm_eEjUiZv2_isLAAAAIo"]
[Wed Jul 29 08:07:00.938642 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /microservice/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "ammYhMNm_eEjUiZv2_isLAAAAIo"]
[Wed Jul 29 08:07:00.995252 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/service/.env"] [unique_id "ammYhMNm_eEjUiZv2_isLQAAAIY"]
[Wed Jul 29 08:07:00.995809 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/service/.env"] [unique_id "ammYhMNm_eEjUiZv2_isLQAAAIY"]
[Wed Jul 29 08:07:00.996177 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/service/.env"] [unique_id "ammYhMNm_eEjUiZv2_isLQAAAIY"]
[Wed Jul 29 08:07:00.996325 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /service/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/service/.env"] [unique_id "ammYhMNm_eEjUiZv2_isLQAAAIY"]
[Wed Jul 29 08:07:01.197395 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "ammYhcNm_eEjUiZv2_isLwAAAIE"]
[Wed Jul 29 08:07:01.197952 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "ammYhcNm_eEjUiZv2_isLwAAAIE"]
[Wed Jul 29 08:07:01.198382 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "ammYhcNm_eEjUiZv2_isLwAAAIE"]
[Wed Jul 29 08:07:01.198644 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/v3/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "ammYhcNm_eEjUiZv2_isLwAAAIE"]
[Wed Jul 29 08:07:01.289663 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "ammYhcNm_eEjUiZv2_isMAAAAIc"]
[Wed Jul 29 08:07:01.290484 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "ammYhcNm_eEjUiZv2_isMAAAAIc"]
[Wed Jul 29 08:07:01.291014 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "ammYhcNm_eEjUiZv2_isMAAAAIc"]
[Wed Jul 29 08:07:01.291249 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/dev/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "ammYhcNm_eEjUiZv2_isMAAAAIc"]
[Wed Jul 29 08:07:01.347623 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "ammYhcNm_eEjUiZv2_isMQAAAI8"]
[Wed Jul 29 08:07:01.348446 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "ammYhcNm_eEjUiZv2_isMQAAAI8"]
[Wed Jul 29 08:07:01.348984 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "ammYhcNm_eEjUiZv2_isMQAAAI8"]
[Wed Jul 29 08:07:01.349247 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/staging/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "ammYhcNm_eEjUiZv2_isMQAAAI8"]
[Wed Jul 29 08:07:01.400114 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "ammYhcNm_eEjUiZv2_isMgAAAJg"]
[Wed Jul 29 08:07:01.400713 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "ammYhcNm_eEjUiZv2_isMgAAAJg"]
[Wed Jul 29 08:07:01.462693 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "ammYhcNm_eEjUiZv2_isMgAAAJg"]
[Wed Jul 29 08:07:01.462891 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /vendor/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "ammYhcNm_eEjUiZv2_isMgAAAJg"]
[Wed Jul 29 08:07:01.534579 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNAAAAJA"]
[Wed Jul 29 08:07:01.535244 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNAAAAJA"]
[Wed Jul 29 08:07:01.535735 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNAAAAJA"]
[Wed Jul 29 08:07:01.535979 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lib/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNAAAAJA"]
[Wed Jul 29 08:07:01.586266 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNQAAAII"]
[Wed Jul 29 08:07:01.586984 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNQAAAII"]
[Wed Jul 29 08:07:01.587455 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNQAAAII"]
[Wed Jul 29 08:07:01.587646 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /resources/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNQAAAII"]
[Wed Jul 29 08:07:01.643304 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNgAAAJI"]
[Wed Jul 29 08:07:01.644145 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNgAAAJI"]
[Wed Jul 29 08:07:01.644599 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNgAAAJI"]
[Wed Jul 29 08:07:01.644801 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNgAAAJI"]
[Wed Jul 29 08:07:01.743986 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNwAAAIg"]
[Wed Jul 29 08:07:01.744881 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNwAAAIg"]
[Wed Jul 29 08:07:01.745416 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNwAAAIg"]
[Wed Jul 29 08:07:01.745699 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "ammYhcNm_eEjUiZv2_isNwAAAIg"]
[Wed Jul 29 08:07:01.801005 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "ammYhcNm_eEjUiZv2_isOQAAAJM"]
[Wed Jul 29 08:07:01.801864 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "ammYhcNm_eEjUiZv2_isOQAAAJM"]
[Wed Jul 29 08:07:01.802365 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "ammYhcNm_eEjUiZv2_isOQAAAJM"]
[Wed Jul 29 08:07:01.859938 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /internal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "ammYhcNm_eEjUiZv2_isOQAAAJM"]
[Wed Jul 29 08:07:01.953794 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "ammYhcNm_eEjUiZv2_isOgAAAIk"]
[Wed Jul 29 08:07:01.954929 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "ammYhcNm_eEjUiZv2_isOgAAAIk"]
[Wed Jul 29 08:07:01.955465 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "ammYhcNm_eEjUiZv2_isOgAAAIk"]
[Wed Jul 29 08:07:01.955738 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "ammYhcNm_eEjUiZv2_isOgAAAIk"]
[Wed Jul 29 08:07:02.043635 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPAAAAJE"]
[Wed Jul 29 08:07:02.044544 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPAAAAJE"]
[Wed Jul 29 08:07:02.045113 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPAAAAJE"]
[Wed Jul 29 08:07:02.045371 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /scripts/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPAAAAJE"]
[Wed Jul 29 08:07:02.135850 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPQAAAIw"]
[Wed Jul 29 08:07:02.136755 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPQAAAIw"]
[Wed Jul 29 08:07:02.137377 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPQAAAIw"]
[Wed Jul 29 08:07:02.137679 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /bin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPQAAAIw"]
[Wed Jul 29 08:07:02.212518 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPgAAAIs"]
[Wed Jul 29 08:07:02.213352 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPgAAAIs"]
[Wed Jul 29 08:07:02.213880 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPgAAAIs"]
[Wed Jul 29 08:07:02.214145 2026] [:error] [pid 29818:tid 139879023339264] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sbin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPgAAAIs"]
[Wed Jul 29 08:07:02.279244 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/local/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPwAAAJc"]
[Wed Jul 29 08:07:02.279800 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/local/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPwAAAJc"]
[Wed Jul 29 08:07:02.280177 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/local/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPwAAAJc"]
[Wed Jul 29 08:07:02.280380 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/local/.env"] [unique_id "ammYhsNm_eEjUiZv2_isPwAAAJc"]
[Wed Jul 29 08:07:02.338764 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "ammYhsNm_eEjUiZv2_isQQAAAI0"]
[Wed Jul 29 08:07:02.339537 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "ammYhsNm_eEjUiZv2_isQQAAAI0"]
[Wed Jul 29 08:07:02.340220 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "ammYhsNm_eEjUiZv2_isQQAAAI0"]
[Wed Jul 29 08:07:02.340477 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /portal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "ammYhsNm_eEjUiZv2_isQQAAAI0"]
[Wed Jul 29 08:07:02.392074 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "ammYhsNm_eEjUiZv2_isQgAAAJY"]
[Wed Jul 29 08:07:02.392645 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "ammYhsNm_eEjUiZv2_isQgAAAJY"]
[Wed Jul 29 08:07:02.393054 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "ammYhsNm_eEjUiZv2_isQgAAAJY"]
[Wed Jul 29 08:07:02.393206 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /dashboard/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "ammYhsNm_eEjUiZv2_isQgAAAJY"]
[Wed Jul 29 08:07:02.462239 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "ammYhsNm_eEjUiZv2_isQwAAAIY"]
[Wed Jul 29 08:07:02.462809 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "ammYhsNm_eEjUiZv2_isQwAAAIY"]
[Wed Jul 29 08:07:02.463171 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "ammYhsNm_eEjUiZv2_isQwAAAIY"]
[Wed Jul 29 08:07:02.463352 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "ammYhsNm_eEjUiZv2_isQwAAAIY"]
[Wed Jul 29 08:07:02.535124 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "ammYhsNm_eEjUiZv2_isRAAAAIE"]
[Wed Jul 29 08:07:02.535958 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "ammYhsNm_eEjUiZv2_isRAAAAIE"]
[Wed Jul 29 08:07:02.536472 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "ammYhsNm_eEjUiZv2_isRAAAAIE"]
[Wed Jul 29 08:07:02.536743 2026] [:error] [pid 29818:tid 139879177004800] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /crm/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "ammYhsNm_eEjUiZv2_isRAAAAIE"]
[Wed Jul 29 08:07:02.637748 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "ammYhsNm_eEjUiZv2_isRgAAAIc"]
[Wed Jul 29 08:07:02.638440 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "ammYhsNm_eEjUiZv2_isRgAAAIc"]
[Wed Jul 29 08:07:02.638954 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "ammYhsNm_eEjUiZv2_isRgAAAIc"]
[Wed Jul 29 08:07:02.639189 2026] [:error] [pid 29818:tid 139879056910080] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /erp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "ammYhsNm_eEjUiZv2_isRgAAAIc"]
[Wed Jul 29 08:07:02.735423 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "ammYhsNm_eEjUiZv2_isRwAAAIQ"]
[Wed Jul 29 08:07:02.736364 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "ammYhsNm_eEjUiZv2_isRwAAAIQ"]
[Wed Jul 29 08:07:02.736970 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "ammYhsNm_eEjUiZv2_isRwAAAIQ"]
[Wed Jul 29 08:07:02.737234 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /shop/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "ammYhsNm_eEjUiZv2_isRwAAAIQ"]
[Wed Jul 29 08:07:02.796395 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/store/.env"] [unique_id "ammYhsNm_eEjUiZv2_isSAAAAJg"]
[Wed Jul 29 08:07:02.936156 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/store/.env"] [unique_id "ammYhsNm_eEjUiZv2_isSAAAAJg"]
[Wed Jul 29 08:07:02.936767 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/store/.env"] [unique_id "ammYhsNm_eEjUiZv2_isSAAAAJg"]
[Wed Jul 29 08:07:02.936980 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /store/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/store/.env"] [unique_id "ammYhsNm_eEjUiZv2_isSAAAAJg"]
[Wed Jul 29 08:07:03.036287 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isSgAAAII"]
[Wed Jul 29 08:07:03.037172 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isSgAAAII"]
[Wed Jul 29 08:07:03.037725 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isSgAAAII"]
[Wed Jul 29 08:07:03.038008 2026] [:error] [pid 29818:tid 139879098873600] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isSgAAAII"]
[Wed Jul 29 08:07:03.092668 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/client/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isSwAAAJI"]
[Wed Jul 29 08:07:03.147001 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/client/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isSwAAAJI"]
[Wed Jul 29 08:07:03.147330 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/client/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isSwAAAJI"]
[Wed Jul 29 08:07:03.147497 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /client/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/client/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isSwAAAJI"]
[Wed Jul 29 08:07:03.236390 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/project/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isTQAAAIg"]
[Wed Jul 29 08:07:03.237258 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/project/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isTQAAAIg"]
[Wed Jul 29 08:07:03.237814 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/project/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isTQAAAIg"]
[Wed Jul 29 08:07:03.238076 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /project/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/project/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isTQAAAIg"]
[Wed Jul 29 08:07:03.289286 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isTgAAAJQ"]
[Wed Jul 29 08:07:03.289869 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isTgAAAJQ"]
[Wed Jul 29 08:07:03.290239 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isTgAAAJQ"]
[Wed Jul 29 08:07:03.290389 2026] [:error] [pid 29818:tid 139878947804928] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin-panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isTgAAAJQ"]
[Wed Jul 29 08:07:03.345365 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isTwAAAI4"]
[Wed Jul 29 08:07:03.346268 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isTwAAAI4"]
[Wed Jul 29 08:07:03.346830 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isTwAAAI4"]
[Wed Jul 29 08:07:03.347095 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /control-panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isTwAAAI4"]
[Wed Jul 29 08:07:03.434368 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isUAAAAIk"]
[Wed Jul 29 08:07:03.435005 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isUAAAAIk"]
[Wed Jul 29 08:07:03.435452 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isUAAAAIk"]
[Wed Jul 29 08:07:03.435692 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /user-panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isUAAAAIk"]
[Wed Jul 29 08:07:03.486049 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/node/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isUgAAAIA"]
[Wed Jul 29 08:07:03.486638 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/node/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isUgAAAIA"]
[Wed Jul 29 08:07:03.487016 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/node/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isUgAAAIA"]
[Wed Jul 29 08:07:03.487170 2026] [:error] [pid 29818:tid 139879185397504] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/node/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isUgAAAIA"]
[Wed Jul 29 08:07:03.545214 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/express/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isUwAAAJE"]
[Wed Jul 29 08:07:03.545764 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/express/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isUwAAAJE"]
[Wed Jul 29 08:07:03.546082 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/express/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isUwAAAJE"]
[Wed Jul 29 08:07:03.546231 2026] [:error] [pid 29818:tid 139878972983040] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /express/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/express/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isUwAAAJE"]
[Wed Jul 29 08:07:03.681139 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/next/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isVAAAAIw"]
[Wed Jul 29 08:07:03.682001 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/next/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isVAAAAIw"]
[Wed Jul 29 08:07:03.682503 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/next/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isVAAAAIw"]
[Wed Jul 29 08:07:03.682765 2026] [:error] [pid 29818:tid 139879014946560] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /next/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/next/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isVAAAAIw"]
[Wed Jul 29 08:07:03.745332 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isVgAAAJc"]
[Wed Jul 29 08:07:03.745992 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isVgAAAJc"]
[Wed Jul 29 08:07:03.746398 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isVgAAAJc"]
[Wed Jul 29 08:07:03.746590 2026] [:error] [pid 29818:tid 139878922626816] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nuxt/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isVgAAAJc"]
[Wed Jul 29 08:07:03.834235 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isVwAAAI0"]
[Wed Jul 29 08:07:03.834921 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isVwAAAI0"]
[Wed Jul 29 08:07:03.835432 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isVwAAAI0"]
[Wed Jul 29 08:07:03.835669 2026] [:error] [pid 29818:tid 139879006553856] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nest/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isVwAAAI0"]
[Wed Jul 29 08:07:03.893546 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/react/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isWAAAAIo"]
[Wed Jul 29 08:07:03.894360 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/react/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isWAAAAIo"]
[Wed Jul 29 08:07:03.894858 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/react/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isWAAAAIo"]
[Wed Jul 29 08:07:03.895089 2026] [:error] [pid 29818:tid 139879031731968] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/react/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isWAAAAIo"]
[Wed Jul 29 08:07:03.952322 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isWQAAAJY"]
[Wed Jul 29 08:07:03.953194 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isWQAAAJY"]
[Wed Jul 29 08:07:03.953759 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isWQAAAJY"]
[Wed Jul 29 08:07:03.954188 2026] [:error] [pid 29818:tid 139878931019520] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /vue/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "ammYh8Nm_eEjUiZv2_isWQAAAJY"]
[Wed Jul 29 08:07:04.042586 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "ammYiMNm_eEjUiZv2_isWgAAAIY"]
[Wed Jul 29 08:07:04.043543 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "ammYiMNm_eEjUiZv2_isWgAAAIY"]
[Wed Jul 29 08:07:04.044014 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "ammYiMNm_eEjUiZv2_isWgAAAIY"]
[Wed Jul 29 08:07:04.044177 2026] [:error] [pid 29818:tid 139879065302784] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /angular/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "ammYiMNm_eEjUiZv2_isWgAAAIY"]
[Wed Jul 29 08:07:04.136194 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "ammYiMNm_eEjUiZv2_isXAAAAI8"]
[Wed Jul 29 08:07:04.137013 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "ammYiMNm_eEjUiZv2_isXAAAAI8"]
[Wed Jul 29 08:07:04.137527 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "ammYiMNm_eEjUiZv2_isXAAAAI8"]
[Wed Jul 29 08:07:04.137776 2026] [:error] [pid 29818:tid 139878989768448] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /svelte/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "ammYiMNm_eEjUiZv2_isXAAAAI8"]
[Wed Jul 29 08:07:04.190696 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "ammYiMNm_eEjUiZv2_isXQAAAIQ"]
[Wed Jul 29 08:07:04.191286 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "ammYiMNm_eEjUiZv2_isXQAAAIQ"]
[Wed Jul 29 08:07:04.191832 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "ammYiMNm_eEjUiZv2_isXQAAAIQ"]
[Wed Jul 29 08:07:04.192086 2026] [:error] [pid 29818:tid 139879082088192] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /vite/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "ammYiMNm_eEjUiZv2_isXQAAAIQ"]
[Wed Jul 29 08:07:04.267694 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "ammYiMNm_eEjUiZv2_isXgAAAJA"]
[Wed Jul 29 08:07:04.268506 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "ammYiMNm_eEjUiZv2_isXgAAAJA"]
[Wed Jul 29 08:07:04.269043 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "ammYiMNm_eEjUiZv2_isXgAAAJA"]
[Wed Jul 29 08:07:04.269294 2026] [:error] [pid 29818:tid 139878981375744] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backup/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "ammYiMNm_eEjUiZv2_isXgAAAJA"]
[Wed Jul 29 08:07:04.338109 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "ammYiMNm_eEjUiZv2_isYAAAAJg"]
[Wed Jul 29 08:07:04.338733 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "ammYiMNm_eEjUiZv2_isYAAAAJg"]
[Wed Jul 29 08:07:04.339205 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "ammYiMNm_eEjUiZv2_isYAAAAJg"]
[Wed Jul 29 08:07:04.339445 2026] [:error] [pid 29818:tid 139878914234112] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backups/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "ammYiMNm_eEjUiZv2_isYAAAAJg"]
[Wed Jul 29 08:07:04.434298 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/old/.env"] [unique_id "ammYiMNm_eEjUiZv2_isYgAAAJI"]
[Wed Jul 29 08:07:04.435384 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/old/.env"] [unique_id "ammYiMNm_eEjUiZv2_isYgAAAJI"]
[Wed Jul 29 08:07:04.435975 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/old/.env"] [unique_id "ammYiMNm_eEjUiZv2_isYgAAAJI"]
[Wed Jul 29 08:07:04.436234 2026] [:error] [pid 29818:tid 139878964590336] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /old/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/old/.env"] [unique_id "ammYiMNm_eEjUiZv2_isYgAAAJI"]
[Wed Jul 29 08:07:04.544783 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "ammYiMNm_eEjUiZv2_isYwAAAIg"]
[Wed Jul 29 08:07:04.545584 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "ammYiMNm_eEjUiZv2_isYwAAAIg"]
[Wed Jul 29 08:07:04.546121 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "ammYiMNm_eEjUiZv2_isYwAAAIg"]
[Wed Jul 29 08:07:04.546374 2026] [:error] [pid 29818:tid 139879048517376] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tmp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "ammYiMNm_eEjUiZv2_isYwAAAIg"]
[Wed Jul 29 08:07:04.634266 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "ammYiMNm_eEjUiZv2_isZQAAAI4"]
[Wed Jul 29 08:07:04.635174 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "ammYiMNm_eEjUiZv2_isZQAAAI4"]
[Wed Jul 29 08:07:04.635712 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "ammYiMNm_eEjUiZv2_isZQAAAI4"]
[Wed Jul 29 08:07:04.635981 2026] [:error] [pid 29818:tid 139878998161152] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /temp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "ammYiMNm_eEjUiZv2_isZQAAAI4"]
[Wed Jul 29 08:07:04.694774 2026] [:error] [pid 29818:tid 139879073695488] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "ammYiMNm_eEjUiZv2_isZgAAAIU"]
[Wed Jul 29 08:07:04.695399 2026] [:error] [pid 29818:tid 139879073695488] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "ammYiMNm_eEjUiZv2_isZgAAAIU"]
[Wed Jul 29 08:07:04.763006 2026] [:error] [pid 29818:tid 139879073695488] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "ammYiMNm_eEjUiZv2_isZgAAAIU"]
[Wed Jul 29 08:07:04.763327 2026] [:error] [pid 29818:tid 139879073695488] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "ammYiMNm_eEjUiZv2_isZgAAAIU"]
[Wed Jul 29 08:07:04.834254 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "ammYiMNm_eEjUiZv2_isZwAAAIk"]
[Wed Jul 29 08:07:04.834898 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "ammYiMNm_eEjUiZv2_isZwAAAIk"]
[Wed Jul 29 08:07:04.835255 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "ammYiMNm_eEjUiZv2_isZwAAAIk"]
[Wed Jul 29 08:07:04.835421 2026] [:error] [pid 29818:tid 139879040124672] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "ammYiMNm_eEjUiZv2_isZwAAAIk"]
[Wed Jul 29 08:07:04.973947 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "ammYiMNm_eEjUiZv2_isaQAAAJM"]
[Wed Jul 29 08:07:04.974491 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "ammYiMNm_eEjUiZv2_isaQAAAJM"]
[Wed Jul 29 08:07:04.974883 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "ammYiMNm_eEjUiZv2_isaQAAAJM"]
[Wed Jul 29 08:07:04.975053 2026] [:error] [pid 29818:tid 139878956197632] [client 162.158.49.89:13453] [client 162.158.49.89] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "ammYiMNm_eEjUiZv2_isaQAAAJM"]
[Wed Jul 29 08:07:05.134364 2026] [:error] [pid 12728:tid 139878998161152] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/en/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jbwAAAU4"]
[Wed Jul 29 08:07:05.135020 2026] [:error] [pid 12728:tid 139878998161152] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/en/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jbwAAAU4"]
[Wed Jul 29 08:07:05.135490 2026] [:error] [pid 12728:tid 139878998161152] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/en/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jbwAAAU4"]
[Wed Jul 29 08:07:05.135675 2026] [:error] [pid 12728:tid 139878998161152] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/en/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jbwAAAU4"]
[Wed Jul 29 08:07:05.254676 2026] [:error] [pid 12728:tid 139879056910080] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jcQAAAUc"]
[Wed Jul 29 08:07:05.255406 2026] [:error] [pid 12728:tid 139879056910080] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jcQAAAUc"]
[Wed Jul 29 08:07:05.255906 2026] [:error] [pid 12728:tid 139879056910080] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jcQAAAUc"]
[Wed Jul 29 08:07:05.256064 2026] [:error] [pid 12728:tid 139879056910080] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jcQAAAUc"]
[Wed Jul 29 08:07:05.342373 2026] [:error] [pid 12728:tid 139878914234112] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jcgAAAVg"]
[Wed Jul 29 08:07:05.343379 2026] [:error] [pid 12728:tid 139878914234112] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jcgAAAVg"]
[Wed Jul 29 08:07:05.343991 2026] [:error] [pid 12728:tid 139878914234112] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jcgAAAVg"]
[Wed Jul 29 08:07:05.344233 2026] [:error] [pid 12728:tid 139878914234112] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jcgAAAVg"]
[Wed Jul 29 08:07:05.434652 2026] [:error] [pid 12728:tid 139878931019520] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jcwAAAVY"]
[Wed Jul 29 08:07:05.435347 2026] [:error] [pid 12728:tid 139878931019520] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jcwAAAVY"]
[Wed Jul 29 08:07:05.435900 2026] [:error] [pid 12728:tid 139878931019520] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jcwAAAVY"]
[Wed Jul 29 08:07:05.436145 2026] [:error] [pid 12728:tid 139878931019520] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jcwAAAVY"]
[Wed Jul 29 08:07:05.487695 2026] [:error] [pid 12728:tid 139879073695488] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jdAAAAUU"]
[Wed Jul 29 08:07:05.488541 2026] [:error] [pid 12728:tid 139879073695488] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jdAAAAUU"]
[Wed Jul 29 08:07:05.489135 2026] [:error] [pid 12728:tid 139879073695488] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jdAAAAUU"]
[Wed Jul 29 08:07:05.489387 2026] [:error] [pid 12728:tid 139879073695488] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jdAAAAUU"]
[Wed Jul 29 08:07:05.554742 2026] [:error] [pid 12728:tid 139878989768448] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "ammYiTqdFZ1TNKvQdY1jdQAAAU8"]
[Wed Jul 29 08:07:05.555519 2026] [:error] [pid 12728:tid 139878989768448] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "ammYiTqdFZ1TNKvQdY1jdQAAAU8"]
[Wed Jul 29 08:07:05.556038 2026] [:error] [pid 12728:tid 139878989768448] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "ammYiTqdFZ1TNKvQdY1jdQAAAU8"]
[Wed Jul 29 08:07:05.556197 2026] [:error] [pid 12728:tid 139878989768448] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "ammYiTqdFZ1TNKvQdY1jdQAAAU8"]
[Wed Jul 29 08:07:05.644372 2026] [:error] [pid 12728:tid 139879006553856] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "ammYiTqdFZ1TNKvQdY1jdgAAAU0"]
[Wed Jul 29 08:07:05.644987 2026] [:error] [pid 12728:tid 139879006553856] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "ammYiTqdFZ1TNKvQdY1jdgAAAU0"]
[Wed Jul 29 08:07:05.645440 2026] [:error] [pid 12728:tid 139879006553856] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "ammYiTqdFZ1TNKvQdY1jdgAAAU0"]
[Wed Jul 29 08:07:05.645631 2026] [:error] [pid 12728:tid 139879006553856] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "ammYiTqdFZ1TNKvQdY1jdgAAAU0"]
[Wed Jul 29 08:07:05.740763 2026] [:error] [pid 12728:tid 139878922626816] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jeAAAAVc"]
[Wed Jul 29 08:07:05.741628 2026] [:error] [pid 12728:tid 139878922626816] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jeAAAAVc"]
[Wed Jul 29 08:07:05.742137 2026] [:error] [pid 12728:tid 139878922626816] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jeAAAAVc"]
[Wed Jul 29 08:07:05.742326 2026] [:error] [pid 12728:tid 139878922626816] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /logs/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jeAAAAVc"]
[Wed Jul 29 08:07:05.839027 2026] [:error] [pid 12728:tid 139879098873600] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jeQAAAUI"]
[Wed Jul 29 08:07:05.839513 2026] [:error] [pid 12728:tid 139879098873600] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jeQAAAUI"]
[Wed Jul 29 08:07:05.839926 2026] [:error] [pid 12728:tid 139879098873600] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jeQAAAUI"]
[Wed Jul 29 08:07:05.840070 2026] [:error] [pid 12728:tid 139879098873600] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cache/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jeQAAAUI"]
[Wed Jul 29 08:07:05.895905 2026] [:error] [pid 12728:tid 139878981375744] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jegAAAVA"]
[Wed Jul 29 08:07:05.896789 2026] [:error] [pid 12728:tid 139878981375744] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jegAAAVA"]
[Wed Jul 29 08:07:05.897401 2026] [:error] [pid 12728:tid 139878981375744] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jegAAAVA"]
[Wed Jul 29 08:07:05.897662 2026] [:error] [pid 12728:tid 139878981375744] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailer/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jegAAAVA"]
[Wed Jul 29 08:07:05.964689 2026] [:error] [pid 12728:tid 139878964590336] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jewAAAVI"]
[Wed Jul 29 08:07:05.965594 2026] [:error] [pid 12728:tid 139878964590336] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jewAAAVI"]
[Wed Jul 29 08:07:05.966153 2026] [:error] [pid 12728:tid 139878964590336] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jewAAAVI"]
[Wed Jul 29 08:07:05.966406 2026] [:error] [pid 12728:tid 139878964590336] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mail/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "ammYiTqdFZ1TNKvQdY1jewAAAVI"]
[Wed Jul 29 08:07:06.048564 2026] [:error] [pid 12728:tid 139879177004800] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/email/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jfAAAAUE"]
[Wed Jul 29 08:07:06.049393 2026] [:error] [pid 12728:tid 139879177004800] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/email/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jfAAAAUE"]
[Wed Jul 29 08:07:06.049976 2026] [:error] [pid 12728:tid 139879177004800] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/email/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jfAAAAUE"]
[Wed Jul 29 08:07:06.050434 2026] [:error] [pid 12728:tid 139879177004800] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /email/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/email/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jfAAAAUE"]
[Wed Jul 29 08:07:06.142364 2026] [:error] [pid 12728:tid 139879040124672] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jfQAAAUk"]
[Wed Jul 29 08:07:06.143064 2026] [:error] [pid 12728:tid 139879040124672] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jfQAAAUk"]
[Wed Jul 29 08:07:06.143474 2026] [:error] [pid 12728:tid 139879040124672] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jfQAAAUk"]
[Wed Jul 29 08:07:06.143658 2026] [:error] [pid 12728:tid 139879040124672] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /smtp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jfQAAAUk"]
[Wed Jul 29 08:07:06.250257 2026] [:error] [pid 12728:tid 139879065302784] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jfwAAAUY"]
[Wed Jul 29 08:07:06.251414 2026] [:error] [pid 12728:tid 139879065302784] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jfwAAAUY"]
[Wed Jul 29 08:07:06.252110 2026] [:error] [pid 12728:tid 139879065302784] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jfwAAAUY"]
[Wed Jul 29 08:07:06.252373 2026] [:error] [pid 12728:tid 139879065302784] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailing/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jfwAAAUY"]
[Wed Jul 29 08:07:06.358047 2026] [:error] [pid 12728:tid 139879090480896] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jgQAAAUM"]
[Wed Jul 29 08:07:06.359072 2026] [:error] [pid 12728:tid 139879090480896] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jgQAAAUM"]
[Wed Jul 29 08:07:06.359743 2026] [:error] [pid 12728:tid 139879090480896] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jgQAAAUM"]
[Wed Jul 29 08:07:06.359986 2026] [:error] [pid 12728:tid 139879090480896] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /notifications/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jgQAAAUM"]
[Wed Jul 29 08:07:06.450263 2026] [:error] [pid 12728:tid 139879031731968] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jggAAAUo"]
[Wed Jul 29 08:07:06.451155 2026] [:error] [pid 12728:tid 139879031731968] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jggAAAUo"]
[Wed Jul 29 08:07:06.451739 2026] [:error] [pid 12728:tid 139879031731968] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jggAAAUo"]
[Wed Jul 29 08:07:06.452005 2026] [:error] [pid 12728:tid 139879031731968] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /notify/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jggAAAUo"]
[Wed Jul 29 08:07:06.544798 2026] [:error] [pid 12728:tid 139878998161152] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jhAAAAU4"]
[Wed Jul 29 08:07:06.562569 2026] [:error] [pid 12728:tid 139878998161152] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jhAAAAU4"]
[Wed Jul 29 08:07:06.563100 2026] [:error] [pid 12728:tid 139878998161152] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jhAAAAU4"]
[Wed Jul 29 08:07:06.563264 2026] [:error] [pid 12728:tid 139878998161152] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sender/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jhAAAAU4"]
[Wed Jul 29 08:07:06.654032 2026] [:error] [pid 12728:tid 139878914234112] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jhgAAAVg"]
[Wed Jul 29 08:07:06.655040 2026] [:error] [pid 12728:tid 139878914234112] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jhgAAAVg"]
[Wed Jul 29 08:07:06.655640 2026] [:error] [pid 12728:tid 139878914234112] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jhgAAAVg"]
[Wed Jul 29 08:07:06.655903 2026] [:error] [pid 12728:tid 139878914234112] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /campaign/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jhgAAAVg"]
[Wed Jul 29 08:07:06.744584 2026] [:error] [pid 12728:tid 139878931019520] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jhwAAAVY"]
[Wed Jul 29 08:07:06.745304 2026] [:error] [pid 12728:tid 139878931019520] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jhwAAAVY"]
[Wed Jul 29 08:07:06.745759 2026] [:error] [pid 12728:tid 139878931019520] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jhwAAAVY"]
[Wed Jul 29 08:07:06.745955 2026] [:error] [pid 12728:tid 139878931019520] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /newsletter/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jhwAAAVY"]
[Wed Jul 29 08:07:06.844471 2026] [:error] [pid 12728:tid 139879082088192] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jiAAAAUQ"]
[Wed Jul 29 08:07:06.845122 2026] [:error] [pid 12728:tid 139879082088192] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jiAAAAUQ"]
[Wed Jul 29 08:07:06.845595 2026] [:error] [pid 12728:tid 139879082088192] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jiAAAAUQ"]
[Wed Jul 29 08:07:06.845827 2026] [:error] [pid 12728:tid 139879082088192] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /ses/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jiAAAAUQ"]
[Wed Jul 29 08:07:06.934724 2026] [:error] [pid 12728:tid 139879073695488] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jiQAAAUU"]
[Wed Jul 29 08:07:06.935477 2026] [:error] [pid 12728:tid 139879073695488] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jiQAAAUU"]
[Wed Jul 29 08:07:06.935963 2026] [:error] [pid 12728:tid 139879073695488] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jiQAAAUU"]
[Wed Jul 29 08:07:06.936156 2026] [:error] [pid 12728:tid 139879073695488] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sendgrid/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "ammYijqdFZ1TNKvQdY1jiQAAAUU"]
[Wed Jul 29 08:07:07.034389 2026] [:error] [pid 12728:tid 139878989768448] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jigAAAU8"]
[Wed Jul 29 08:07:07.035306 2026] [:error] [pid 12728:tid 139878989768448] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jigAAAU8"]
[Wed Jul 29 08:07:07.035861 2026] [:error] [pid 12728:tid 139878989768448] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jigAAAU8"]
[Wed Jul 29 08:07:07.036103 2026] [:error] [pid 12728:tid 139878989768448] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sparkpost/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jigAAAU8"]
[Wed Jul 29 08:07:07.097061 2026] [:error] [pid 12728:tid 139879006553856] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jiwAAAU0"]
[Wed Jul 29 08:07:07.097849 2026] [:error] [pid 12728:tid 139879006553856] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jiwAAAU0"]
[Wed Jul 29 08:07:07.098384 2026] [:error] [pid 12728:tid 139879006553856] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jiwAAAU0"]
[Wed Jul 29 08:07:07.098667 2026] [:error] [pid 12728:tid 139879006553856] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /postmark/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jiwAAAU0"]
[Wed Jul 29 08:07:07.163951 2026] [:error] [pid 12728:tid 139878922626816] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjAAAAVc"]
[Wed Jul 29 08:07:07.164568 2026] [:error] [pid 12728:tid 139878922626816] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjAAAAVc"]
[Wed Jul 29 08:07:07.164953 2026] [:error] [pid 12728:tid 139878922626816] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjAAAAVc"]
[Wed Jul 29 08:07:07.165102 2026] [:error] [pid 12728:tid 139878922626816] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailgun/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjAAAAVc"]
[Wed Jul 29 08:07:07.253429 2026] [:error] [pid 12728:tid 139879098873600] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjQAAAUI"]
[Wed Jul 29 08:07:07.254064 2026] [:error] [pid 12728:tid 139879098873600] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjQAAAUI"]
[Wed Jul 29 08:07:07.254463 2026] [:error] [pid 12728:tid 139879098873600] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjQAAAUI"]
[Wed Jul 29 08:07:07.254643 2026] [:error] [pid 12728:tid 139879098873600] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mandrill/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjQAAAUI"]
[Wed Jul 29 08:07:07.353629 2026] [:error] [pid 12728:tid 139878947804928] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjgAAAVQ"]
[Wed Jul 29 08:07:07.354499 2026] [:error] [pid 12728:tid 139878947804928] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjgAAAVQ"]
[Wed Jul 29 08:07:07.355117 2026] [:error] [pid 12728:tid 139878947804928] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjgAAAVQ"]
[Wed Jul 29 08:07:07.355371 2026] [:error] [pid 12728:tid 139878947804928] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailjet/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjgAAAVQ"]
[Wed Jul 29 08:07:07.449150 2026] [:error] [pid 12728:tid 139878981375744] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjwAAAVA"]
[Wed Jul 29 08:07:07.450000 2026] [:error] [pid 12728:tid 139878981375744] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjwAAAVA"]
[Wed Jul 29 08:07:07.450515 2026] [:error] [pid 12728:tid 139878981375744] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjwAAAVA"]
[Wed Jul 29 08:07:07.450783 2026] [:error] [pid 12728:tid 139878981375744] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /brevo/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jjwAAAVA"]
[Wed Jul 29 08:07:07.535519 2026] [:error] [pid 12728:tid 139878972983040] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jkAAAAVE"]
[Wed Jul 29 08:07:07.536373 2026] [:error] [pid 12728:tid 139878972983040] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jkAAAAVE"]
[Wed Jul 29 08:07:07.536975 2026] [:error] [pid 12728:tid 139878972983040] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jkAAAAVE"]
[Wed Jul 29 08:07:07.537203 2026] [:error] [pid 12728:tid 139878972983040] [client 162.158.49.88:10992] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /transactional/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "ammYizqdFZ1TNKvQdY1jkAAAAVE"]
[Wed Jul 29 08:07:07.696798 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "ammYi4puIafV02klyJL19QAAAEQ"]
[Wed Jul 29 08:07:07.738866 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "ammYi4puIafV02klyJL19QAAAEQ"]
[Wed Jul 29 08:07:07.739301 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "ammYi4puIafV02klyJL19QAAAEQ"]
[Wed Jul 29 08:07:07.739500 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /bulk/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "ammYi4puIafV02klyJL19QAAAEQ"]
[Wed Jul 29 08:07:07.834357 2026] [:error] [pid 29817:tid 139879014946560] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "ammYi4puIafV02klyJL19gAAAEw"]
[Wed Jul 29 08:07:07.835181 2026] [:error] [pid 29817:tid 139879014946560] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "ammYi4puIafV02klyJL19gAAAEw"]
[Wed Jul 29 08:07:07.835748 2026] [:error] [pid 29817:tid 139879014946560] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "ammYi4puIafV02klyJL19gAAAEw"]
[Wed Jul 29 08:07:07.835989 2026] [:error] [pid 29817:tid 139879014946560] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /aws/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "ammYi4puIafV02klyJL19gAAAEw"]
[Wed Jul 29 08:07:07.994090 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "ammYi4puIafV02klyJL1-AAAAFc"]
[Wed Jul 29 08:07:07.995147 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "ammYi4puIafV02klyJL1-AAAAFc"]
[Wed Jul 29 08:07:07.995762 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "ammYi4puIafV02klyJL1-AAAAFc"]
[Wed Jul 29 08:07:08.140594 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /azure/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "ammYi4puIafV02klyJL1-AAAAFc"]
[Wed Jul 29 08:07:08.192529 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "ammYjIpuIafV02klyJL1-gAAAFE"]
[Wed Jul 29 08:07:08.193673 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "ammYjIpuIafV02klyJL1-gAAAFE"]
[Wed Jul 29 08:07:08.194374 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "ammYjIpuIafV02klyJL1-gAAAFE"]
[Wed Jul 29 08:07:08.194670 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /gcp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "ammYjIpuIafV02klyJL1-gAAAFE"]
[Wed Jul 29 08:07:08.253916 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "ammYjIpuIafV02klyJL1-wAAAEc"]
[Wed Jul 29 08:07:08.254756 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "ammYjIpuIafV02klyJL1-wAAAEc"]
[Wed Jul 29 08:07:08.255381 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "ammYjIpuIafV02klyJL1-wAAAEc"]
[Wed Jul 29 08:07:08.255654 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cloud/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "ammYjIpuIafV02klyJL1-wAAAEc"]
[Wed Jul 29 08:07:08.342912 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "ammYjIpuIafV02klyJL1_AAAAEA"]
[Wed Jul 29 08:07:08.343848 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "ammYjIpuIafV02klyJL1_AAAAEA"]
[Wed Jul 29 08:07:08.344469 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "ammYjIpuIafV02klyJL1_AAAAEA"]
[Wed Jul 29 08:07:08.344744 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /infrastructure/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "ammYjIpuIafV02klyJL1_AAAAEA"]
[Wed Jul 29 08:07:08.394715 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "ammYjIpuIafV02klyJL1_gAAAE8"]
[Wed Jul 29 08:07:08.395414 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "ammYjIpuIafV02klyJL1_gAAAE8"]
[Wed Jul 29 08:07:08.395975 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "ammYjIpuIafV02klyJL1_gAAAE8"]
[Wed Jul 29 08:07:08.396155 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "ammYjIpuIafV02klyJL1_gAAAE8"]
[Wed Jul 29 08:07:08.543247 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "ammYjIpuIafV02klyJL1_wAAAEg"]
[Wed Jul 29 08:07:08.543998 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "ammYjIpuIafV02klyJL1_wAAAEg"]
[Wed Jul 29 08:07:08.544513 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "ammYjIpuIafV02klyJL1_wAAAEg"]
[Wed Jul 29 08:07:08.544709 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /k8s/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "ammYjIpuIafV02klyJL1_wAAAEg"]
[Wed Jul 29 08:07:08.642920 2026] [:error] [pid 29817:tid 139878947804928] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "ammYjIpuIafV02klyJL2AAAAAFQ"]
[Wed Jul 29 08:07:08.643990 2026] [:error] [pid 29817:tid 139878947804928] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "ammYjIpuIafV02klyJL2AAAAAFQ"]
[Wed Jul 29 08:07:08.644674 2026] [:error] [pid 29817:tid 139878947804928] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "ammYjIpuIafV02klyJL2AAAAAFQ"]
[Wed Jul 29 08:07:08.644957 2026] [:error] [pid 29817:tid 139878947804928] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kubernetes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "ammYjIpuIafV02klyJL2AAAAAFQ"]
[Wed Jul 29 08:07:08.734323 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "ammYjIpuIafV02klyJL2AQAAAE4"]
[Wed Jul 29 08:07:08.735178 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "ammYjIpuIafV02klyJL2AQAAAE4"]
[Wed Jul 29 08:07:08.735732 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "ammYjIpuIafV02klyJL2AQAAAE4"]
[Wed Jul 29 08:07:08.735976 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /terraform/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "ammYjIpuIafV02klyJL2AQAAAE4"]
[Wed Jul 29 08:07:08.788075 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "ammYjIpuIafV02klyJL2AgAAAFI"]
[Wed Jul 29 08:07:08.788660 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "ammYjIpuIafV02klyJL2AgAAAFI"]
[Wed Jul 29 08:07:08.789040 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "ammYjIpuIafV02klyJL2AgAAAFI"]
[Wed Jul 29 08:07:08.789206 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /ansible/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "ammYjIpuIafV02klyJL2AgAAAFI"]
[Wed Jul 29 08:07:08.854954 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "ammYjIpuIafV02klyJL2AwAAAEY"]
[Wed Jul 29 08:07:08.855726 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "ammYjIpuIafV02klyJL2AwAAAEY"]
[Wed Jul 29 08:07:08.856350 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "ammYjIpuIafV02klyJL2AwAAAEY"]
[Wed Jul 29 08:07:08.856629 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "ammYjIpuIafV02klyJL2AwAAAEY"]
[Wed Jul 29 08:07:08.935394 2026] [:error] [pid 29817:tid 139878914234112] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "ammYjIpuIafV02klyJL2BAAAAFg"]
[Wed Jul 29 08:07:08.935956 2026] [:error] [pid 29817:tid 139878914234112] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "ammYjIpuIafV02klyJL2BAAAAFg"]
[Wed Jul 29 08:07:08.936358 2026] [:error] [pid 29817:tid 139878914234112] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "ammYjIpuIafV02klyJL2BAAAAFg"]
[Wed Jul 29 08:07:08.936512 2026] [:error] [pid 29817:tid 139878914234112] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /ci/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "ammYjIpuIafV02klyJL2BAAAAFg"]
[Wed Jul 29 08:07:09.034677 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "ammYjYpuIafV02klyJL2BQAAAFA"]
[Wed Jul 29 08:07:09.035577 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "ammYjYpuIafV02klyJL2BQAAAFA"]
[Wed Jul 29 08:07:09.036168 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "ammYjYpuIafV02klyJL2BQAAAFA"]
[Wed Jul 29 08:07:09.036411 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cd/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "ammYjYpuIafV02klyJL2BQAAAFA"]
[Wed Jul 29 08:07:09.094730 2026] [:error] [pid 29817:tid 139878956197632] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "ammYjYpuIafV02klyJL2BgAAAFM"]
[Wed Jul 29 08:07:09.095602 2026] [:error] [pid 29817:tid 139878956197632] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "ammYjYpuIafV02klyJL2BgAAAFM"]
[Wed Jul 29 08:07:09.096121 2026] [:error] [pid 29817:tid 139878956197632] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "ammYjYpuIafV02klyJL2BgAAAFM"]
[Wed Jul 29 08:07:09.096389 2026] [:error] [pid 29817:tid 139878956197632] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /jenkins/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "ammYjYpuIafV02klyJL2BgAAAFM"]
[Wed Jul 29 08:07:09.234241 2026] [:error] [pid 29817:tid 139879031731968] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "ammYjYpuIafV02klyJL2CAAAAEo"]
[Wed Jul 29 08:07:09.235026 2026] [:error] [pid 29817:tid 139879031731968] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "ammYjYpuIafV02klyJL2CAAAAEo"]
[Wed Jul 29 08:07:09.235448 2026] [:error] [pid 29817:tid 139879031731968] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "ammYjYpuIafV02klyJL2CAAAAEo"]
[Wed Jul 29 08:07:09.235639 2026] [:error] [pid 29817:tid 139879031731968] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /gitlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "ammYjYpuIafV02klyJL2CAAAAEo"]
[Wed Jul 29 08:07:09.286029 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/github/.env"] [unique_id "ammYjYpuIafV02klyJL2CQAAAEQ"]
[Wed Jul 29 08:07:09.286723 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/github/.env"] [unique_id "ammYjYpuIafV02klyJL2CQAAAEQ"]
[Wed Jul 29 08:07:09.287282 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/github/.env"] [unique_id "ammYjYpuIafV02klyJL2CQAAAEQ"]
[Wed Jul 29 08:07:09.287529 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /github/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/github/.env"] [unique_id "ammYjYpuIafV02klyJL2CQAAAEQ"]
[Wed Jul 29 08:07:09.344733 2026] [:error] [pid 29817:tid 139878939412224] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "ammYjYpuIafV02klyJL2CgAAAFU"]
[Wed Jul 29 08:07:09.345471 2026] [:error] [pid 29817:tid 139878939412224] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "ammYjYpuIafV02klyJL2CgAAAFU"]
[Wed Jul 29 08:07:09.346117 2026] [:error] [pid 29817:tid 139878939412224] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "ammYjYpuIafV02klyJL2CgAAAFU"]
[Wed Jul 29 08:07:09.346339 2026] [:error] [pid 29817:tid 139878939412224] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /actions/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "ammYjYpuIafV02klyJL2CgAAAFU"]
[Wed Jul 29 08:07:09.434230 2026] [:error] [pid 29817:tid 139879014946560] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "ammYjYpuIafV02klyJL2CwAAAEw"]
[Wed Jul 29 08:07:09.435005 2026] [:error] [pid 29817:tid 139879014946560] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "ammYjYpuIafV02klyJL2CwAAAEw"]
[Wed Jul 29 08:07:09.435482 2026] [:error] [pid 29817:tid 139879014946560] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "ammYjYpuIafV02klyJL2CwAAAEw"]
[Wed Jul 29 08:07:09.435790 2026] [:error] [pid 29817:tid 139879014946560] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /circleci/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "ammYjYpuIafV02klyJL2CwAAAEw"]
[Wed Jul 29 08:07:09.492670 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "ammYjYpuIafV02klyJL2DAAAAFc"]
[Wed Jul 29 08:07:09.493474 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "ammYjYpuIafV02klyJL2DAAAAFc"]
[Wed Jul 29 08:07:09.494045 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "ammYjYpuIafV02klyJL2DAAAAFc"]
[Wed Jul 29 08:07:09.494289 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /travis/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "ammYjYpuIafV02klyJL2DAAAAFc"]
[Wed Jul 29 08:07:09.582071 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "ammYjYpuIafV02klyJL2DgAAAFE"]
[Wed Jul 29 08:07:09.583059 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "ammYjYpuIafV02klyJL2DgAAAFE"]
[Wed Jul 29 08:07:09.583659 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "ammYjYpuIafV02klyJL2DgAAAFE"]
[Wed Jul 29 08:07:09.583902 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /buildkite/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "ammYjYpuIafV02klyJL2DgAAAFE"]
[Wed Jul 29 08:07:09.644997 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "ammYjYpuIafV02klyJL2DwAAAEc"]
[Wed Jul 29 08:07:09.645931 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "ammYjYpuIafV02klyJL2DwAAAEc"]
[Wed Jul 29 08:07:09.646496 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "ammYjYpuIafV02klyJL2DwAAAEc"]
[Wed Jul 29 08:07:09.646781 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mysql/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "ammYjYpuIafV02klyJL2DwAAAEc"]
[Wed Jul 29 08:07:09.743876 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "ammYjYpuIafV02klyJL2EAAAAEA"]
[Wed Jul 29 08:07:09.744900 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "ammYjYpuIafV02klyJL2EAAAAEA"]
[Wed Jul 29 08:07:09.745544 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "ammYjYpuIafV02klyJL2EAAAAEA"]
[Wed Jul 29 08:07:09.745846 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /postgres/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "ammYjYpuIafV02klyJL2EAAAAEA"]
[Wed Jul 29 08:07:09.842916 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "ammYjYpuIafV02klyJL2EQAAAE8"]
[Wed Jul 29 08:07:09.843730 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "ammYjYpuIafV02klyJL2EQAAAE8"]
[Wed Jul 29 08:07:09.844187 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "ammYjYpuIafV02klyJL2EQAAAE8"]
[Wed Jul 29 08:07:09.844423 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mongodb/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "ammYjYpuIafV02klyJL2EQAAAE8"]
[Wed Jul 29 08:07:09.897628 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "ammYjYpuIafV02klyJL2EgAAAEg"]
[Wed Jul 29 08:07:09.955403 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "ammYjYpuIafV02klyJL2EgAAAEg"]
[Wed Jul 29 08:07:09.956027 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "ammYjYpuIafV02klyJL2EgAAAEg"]
[Wed Jul 29 08:07:09.966953 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /redis/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "ammYjYpuIafV02klyJL2EgAAAEg"]
[Wed Jul 29 08:07:10.042733 2026] [:error] [pid 29817:tid 139879006553856] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "ammYjopuIafV02klyJL2EwAAAE0"]
[Wed Jul 29 08:07:10.043656 2026] [:error] [pid 29817:tid 139879006553856] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "ammYjopuIafV02klyJL2EwAAAE0"]
[Wed Jul 29 08:07:10.044263 2026] [:error] [pid 29817:tid 139879006553856] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "ammYjopuIafV02klyJL2EwAAAE0"]
[Wed Jul 29 08:07:10.044509 2026] [:error] [pid 29817:tid 139879006553856] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /elasticsearch/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "ammYjopuIafV02klyJL2EwAAAE0"]
[Wed Jul 29 08:07:10.245982 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "ammYjopuIafV02klyJL2FQAAAE4"]
[Wed Jul 29 08:07:10.246917 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "ammYjopuIafV02klyJL2FQAAAE4"]
[Wed Jul 29 08:07:10.247539 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "ammYjopuIafV02klyJL2FQAAAE4"]
[Wed Jul 29 08:07:10.247758 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /rabbitmq/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "ammYjopuIafV02klyJL2FQAAAE4"]
[Wed Jul 29 08:07:10.381012 2026] [:error] [pid 29817:tid 139879023339264] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "ammYjopuIafV02klyJL2FwAAAEs"]
[Wed Jul 29 08:07:10.381997 2026] [:error] [pid 29817:tid 139879023339264] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "ammYjopuIafV02klyJL2FwAAAEs"]
[Wed Jul 29 08:07:10.382649 2026] [:error] [pid 29817:tid 139879023339264] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "ammYjopuIafV02klyJL2FwAAAEs"]
[Wed Jul 29 08:07:10.382927 2026] [:error] [pid 29817:tid 139879023339264] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kafka/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "ammYjopuIafV02klyJL2FwAAAEs"]
[Wed Jul 29 08:07:10.443349 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "ammYjopuIafV02klyJL2GAAAAFI"]
[Wed Jul 29 08:07:10.444171 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "ammYjopuIafV02klyJL2GAAAAFI"]
[Wed Jul 29 08:07:10.444702 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "ammYjopuIafV02klyJL2GAAAAFI"]
[Wed Jul 29 08:07:10.444937 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /queue/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "ammYjopuIafV02klyJL2GAAAAFI"]
[Wed Jul 29 08:07:10.534425 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "ammYjopuIafV02klyJL2GQAAAEY"]
[Wed Jul 29 08:07:10.535341 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "ammYjopuIafV02klyJL2GQAAAEY"]
[Wed Jul 29 08:07:10.535929 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "ammYjopuIafV02klyJL2GQAAAEY"]
[Wed Jul 29 08:07:10.536195 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /worker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "ammYjopuIafV02klyJL2GQAAAEY"]
[Wed Jul 29 08:07:10.591683 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/job/.env"] [unique_id "ammYjopuIafV02klyJL2GgAAAFA"]
[Wed Jul 29 08:07:10.592574 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/job/.env"] [unique_id "ammYjopuIafV02klyJL2GgAAAFA"]
[Wed Jul 29 08:07:10.593186 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/job/.env"] [unique_id "ammYjopuIafV02klyJL2GgAAAFA"]
[Wed Jul 29 08:07:10.593482 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /job/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/job/.env"] [unique_id "ammYjopuIafV02klyJL2GgAAAFA"]
[Wed Jul 29 08:07:10.655457 2026] [:error] [pid 29817:tid 139878956197632] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/test/.env"] [unique_id "ammYjopuIafV02klyJL2GwAAAFM"]
[Wed Jul 29 08:07:10.656115 2026] [:error] [pid 29817:tid 139878956197632] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/test/.env"] [unique_id "ammYjopuIafV02klyJL2GwAAAFM"]
[Wed Jul 29 08:07:10.656504 2026] [:error] [pid 29817:tid 139878956197632] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/test/.env"] [unique_id "ammYjopuIafV02klyJL2GwAAAFM"]
[Wed Jul 29 08:07:10.656717 2026] [:error] [pid 29817:tid 139878956197632] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /test/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/test/.env"] [unique_id "ammYjopuIafV02klyJL2GwAAAFM"]
[Wed Jul 29 08:07:10.744345 2026] [:error] [pid 29817:tid 139879073695488] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "ammYjopuIafV02klyJL2HAAAAEU"]
[Wed Jul 29 08:07:10.745060 2026] [:error] [pid 29817:tid 139879073695488] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "ammYjopuIafV02klyJL2HAAAAEU"]
[Wed Jul 29 08:07:10.745482 2026] [:error] [pid 29817:tid 139879073695488] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "ammYjopuIafV02klyJL2HAAAAEU"]
[Wed Jul 29 08:07:10.745670 2026] [:error] [pid 29817:tid 139879073695488] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /qa/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "ammYjopuIafV02klyJL2HAAAAEU"]
[Wed Jul 29 08:07:10.795296 2026] [:error] [pid 29817:tid 139879031731968] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "ammYjopuIafV02klyJL2HQAAAEo"]
[Wed Jul 29 08:07:10.795889 2026] [:error] [pid 29817:tid 139879031731968] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "ammYjopuIafV02klyJL2HQAAAEo"]
[Wed Jul 29 08:07:10.796346 2026] [:error] [pid 29817:tid 139879031731968] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "ammYjopuIafV02klyJL2HQAAAEo"]
[Wed Jul 29 08:07:10.796528 2026] [:error] [pid 29817:tid 139879031731968] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /preview/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "ammYjopuIafV02klyJL2HQAAAEo"]
[Wed Jul 29 08:07:10.869495 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "ammYjopuIafV02klyJL2HgAAAEQ"]
[Wed Jul 29 08:07:10.870150 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "ammYjopuIafV02klyJL2HgAAAEQ"]
[Wed Jul 29 08:07:10.870533 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "ammYjopuIafV02klyJL2HgAAAEQ"]
[Wed Jul 29 08:07:10.870712 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /beta/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "ammYjopuIafV02klyJL2HgAAAEQ"]
[Wed Jul 29 08:07:10.945478 2026] [:error] [pid 29817:tid 139879098873600] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "ammYjopuIafV02klyJL2IQAAAEI"]
[Wed Jul 29 08:07:10.946369 2026] [:error] [pid 29817:tid 139879098873600] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "ammYjopuIafV02klyJL2IQAAAEI"]
[Wed Jul 29 08:07:10.946956 2026] [:error] [pid 29817:tid 139879098873600] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "ammYjopuIafV02klyJL2IQAAAEI"]
[Wed Jul 29 08:07:10.947194 2026] [:error] [pid 29817:tid 139879098873600] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uat/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "ammYjopuIafV02klyJL2IQAAAEI"]
[Wed Jul 29 08:07:11.042930 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "ammYj4puIafV02klyJL2IgAAAFc"]
[Wed Jul 29 08:07:11.043971 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "ammYj4puIafV02klyJL2IgAAAFc"]
[Wed Jul 29 08:07:11.044615 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "ammYj4puIafV02klyJL2IgAAAFc"]
[Wed Jul 29 08:07:11.044890 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /stage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "ammYj4puIafV02klyJL2IgAAAFc"]
[Wed Jul 29 08:07:11.135284 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/development/.env"] [unique_id "ammYj4puIafV02klyJL2IwAAAFE"]
[Wed Jul 29 08:07:11.136108 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/development/.env"] [unique_id "ammYj4puIafV02klyJL2IwAAAFE"]
[Wed Jul 29 08:07:11.136561 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/development/.env"] [unique_id "ammYj4puIafV02klyJL2IwAAAFE"]
[Wed Jul 29 08:07:11.136754 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /development/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/development/.env"] [unique_id "ammYj4puIafV02klyJL2IwAAAFE"]
[Wed Jul 29 08:07:11.195471 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/production/.env"] [unique_id "ammYj4puIafV02klyJL2JAAAAEc"]
[Wed Jul 29 08:07:11.196274 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/production/.env"] [unique_id "ammYj4puIafV02klyJL2JAAAAEc"]
[Wed Jul 29 08:07:11.196738 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/production/.env"] [unique_id "ammYj4puIafV02klyJL2JAAAAEc"]
[Wed Jul 29 08:07:11.196944 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /production/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/production/.env"] [unique_id "ammYj4puIafV02klyJL2JAAAAEc"]
[Wed Jul 29 08:07:11.264902 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "ammYj4puIafV02klyJL2JQAAAEA"]
[Wed Jul 29 08:07:11.265913 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "ammYj4puIafV02klyJL2JQAAAEA"]
[Wed Jul 29 08:07:11.266596 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "ammYj4puIafV02klyJL2JQAAAEA"]
[Wed Jul 29 08:07:11.266872 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "ammYj4puIafV02klyJL2JQAAAEA"]
[Wed Jul 29 08:07:11.334649 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "ammYj4puIafV02klyJL2JgAAAE8"]
[Wed Jul 29 08:07:11.335673 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "ammYj4puIafV02klyJL2JgAAAE8"]
[Wed Jul 29 08:07:11.336323 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "ammYj4puIafV02klyJL2JgAAAE8"]
[Wed Jul 29 08:07:11.488368 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "ammYj4puIafV02klyJL2JwAAAEg"]
[Wed Jul 29 08:07:11.489289 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "ammYj4puIafV02klyJL2JwAAAEg"]
[Wed Jul 29 08:07:11.489883 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "ammYj4puIafV02klyJL2JwAAAEg"]
[Wed Jul 29 08:07:11.546347 2026] [:error] [pid 29817:tid 139879090480896] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/php.php"] [unique_id "ammYj4puIafV02klyJL2KAAAAEM"]
[Wed Jul 29 08:07:11.546964 2026] [:error] [pid 29817:tid 139879090480896] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/php.php"] [unique_id "ammYj4puIafV02klyJL2KAAAAEM"]
[Wed Jul 29 08:07:11.547338 2026] [:error] [pid 29817:tid 139879090480896] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/php.php"] [unique_id "ammYj4puIafV02klyJL2KAAAAEM"]
[Wed Jul 29 08:07:11.638990 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/i.php"] [unique_id "ammYj4puIafV02klyJL2KQAAAE4"]
[Wed Jul 29 08:07:11.639797 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/i.php"] [unique_id "ammYj4puIafV02klyJL2KQAAAE4"]
[Wed Jul 29 08:07:11.640404 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/i.php"] [unique_id "ammYj4puIafV02klyJL2KQAAAE4"]
[Wed Jul 29 08:07:11.691334 2026] [:error] [pid 29817:tid 139879023339264] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/pi.php"] [unique_id "ammYj4puIafV02klyJL2KgAAAEs"]
[Wed Jul 29 08:07:11.691963 2026] [:error] [pid 29817:tid 139879023339264] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/pi.php"] [unique_id "ammYj4puIafV02klyJL2KgAAAEs"]
[Wed Jul 29 08:07:11.692354 2026] [:error] [pid 29817:tid 139879023339264] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/pi.php"] [unique_id "ammYj4puIafV02klyJL2KgAAAEs"]
[Wed Jul 29 08:07:11.760169 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/pinfo.php"] [unique_id "ammYj4puIafV02klyJL2KwAAAFI"]
[Wed Jul 29 08:07:11.760993 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/pinfo.php"] [unique_id "ammYj4puIafV02klyJL2KwAAAFI"]
[Wed Jul 29 08:07:11.761379 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/pinfo.php"] [unique_id "ammYj4puIafV02klyJL2KwAAAFI"]
[Wed Jul 29 08:07:11.844225 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/test.php"] [unique_id "ammYj4puIafV02klyJL2LAAAAEY"]
[Wed Jul 29 08:07:11.844730 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/test.php"] [unique_id "ammYj4puIafV02klyJL2LAAAAEY"]
[Wed Jul 29 08:07:11.845145 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/test.php"] [unique_id "ammYj4puIafV02klyJL2LAAAAEY"]
[Wed Jul 29 08:07:11.942411 2026] [:error] [pid 29817:tid 139878914234112] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo"] [unique_id "ammYj4puIafV02klyJL2LQAAAFg"]
[Wed Jul 29 08:07:11.943152 2026] [:error] [pid 29817:tid 139878914234112] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo"] [unique_id "ammYj4puIafV02klyJL2LQAAAFg"]
[Wed Jul 29 08:07:11.943639 2026] [:error] [pid 29817:tid 139878914234112] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo"] [unique_id "ammYj4puIafV02klyJL2LQAAAFg"]
[Wed Jul 29 08:07:12.039019 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/p.php"] [unique_id "ammYkIpuIafV02klyJL2LgAAAFA"]
[Wed Jul 29 08:07:12.039872 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/p.php"] [unique_id "ammYkIpuIafV02klyJL2LgAAAFA"]
[Wed Jul 29 08:07:12.040391 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/p.php"] [unique_id "ammYkIpuIafV02klyJL2LgAAAFA"]
[Wed Jul 29 08:07:12.176077 2026] [:error] [pid 29817:tid 139879073695488] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/debug.php"] [unique_id "ammYkIpuIafV02klyJL2MAAAAEU"]
[Wed Jul 29 08:07:12.177181 2026] [:error] [pid 29817:tid 139879073695488] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/debug.php"] [unique_id "ammYkIpuIafV02klyJL2MAAAAEU"]
[Wed Jul 29 08:07:12.177805 2026] [:error] [pid 29817:tid 139879073695488] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/debug.php"] [unique_id "ammYkIpuIafV02klyJL2MAAAAEU"]
[Wed Jul 29 08:07:12.237372 2026] [:error] [pid 29817:tid 139879177004800] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2MQAAAEE"]
[Wed Jul 29 08:07:12.238063 2026] [:error] [pid 29817:tid 139879177004800] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2MQAAAEE"]
[Wed Jul 29 08:07:12.238489 2026] [:error] [pid 29817:tid 139879177004800] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2MQAAAEE"]
[Wed Jul 29 08:07:12.294155 2026] [:error] [pid 29817:tid 139878931019520] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/test/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2MgAAAFY"]
[Wed Jul 29 08:07:12.294873 2026] [:error] [pid 29817:tid 139878931019520] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/test/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2MgAAAFY"]
[Wed Jul 29 08:07:12.295305 2026] [:error] [pid 29817:tid 139878931019520] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/test/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2MgAAAFY"]
[Wed Jul 29 08:07:12.345950 2026] [:error] [pid 29817:tid 139879031731968] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dev/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2MwAAAEo"]
[Wed Jul 29 08:07:12.346892 2026] [:error] [pid 29817:tid 139879031731968] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dev/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2MwAAAEo"]
[Wed Jul 29 08:07:12.347348 2026] [:error] [pid 29817:tid 139879031731968] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dev/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2MwAAAEo"]
[Wed Jul 29 08:07:12.442667 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/old/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2NAAAAEQ"]
[Wed Jul 29 08:07:12.443526 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/old/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2NAAAAEQ"]
[Wed Jul 29 08:07:12.444105 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/old/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2NAAAAEQ"]
[Wed Jul 29 08:07:12.575386 2026] [:error] [pid 29817:tid 139879098873600] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/tmp/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2NQAAAEI"]
[Wed Jul 29 08:07:12.576271 2026] [:error] [pid 29817:tid 139879098873600] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/tmp/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2NQAAAEI"]
[Wed Jul 29 08:07:12.576866 2026] [:error] [pid 29817:tid 139879098873600] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/tmp/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2NQAAAEI"]
[Wed Jul 29 08:07:12.634243 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/public/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2NgAAAFc"]
[Wed Jul 29 08:07:12.634904 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/public/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2NgAAAFc"]
[Wed Jul 29 08:07:12.635329 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/public/phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2NgAAAFc"]
[Wed Jul 29 08:07:12.689631 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/info"] [unique_id "ammYkIpuIafV02klyJL2NwAAAFE"]
[Wed Jul 29 08:07:12.690467 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/info"] [unique_id "ammYkIpuIafV02klyJL2NwAAAFE"]
[Wed Jul 29 08:07:12.691002 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/info"] [unique_id "ammYkIpuIafV02klyJL2NwAAAFE"]
[Wed Jul 29 08:07:12.753522 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "ammYkIpuIafV02klyJL2OAAAAEc"]
[Wed Jul 29 08:07:12.754349 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "ammYkIpuIafV02klyJL2OAAAAEc"]
[Wed Jul 29 08:07:12.754865 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "ammYkIpuIafV02klyJL2OAAAAEc"]
[Wed Jul 29 08:07:12.836678 2026] [:error] [pid 29817:tid 139878947804928] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpversion.php"] [unique_id "ammYkIpuIafV02klyJL2OQAAAFQ"]
[Wed Jul 29 08:07:12.837388 2026] [:error] [pid 29817:tid 139878947804928] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpversion.php"] [unique_id "ammYkIpuIafV02klyJL2OQAAAFQ"]
[Wed Jul 29 08:07:12.837827 2026] [:error] [pid 29817:tid 139878947804928] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpversion.php"] [unique_id "ammYkIpuIafV02klyJL2OQAAAFQ"]
[Wed Jul 29 08:07:12.893270 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2OgAAAEA"]
[Wed Jul 29 08:07:12.893866 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2OgAAAEA"]
[Wed Jul 29 08:07:12.894238 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2OgAAAEA"]
[Wed Jul 29 08:07:12.953335 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/old_phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2OwAAAE8"]
[Wed Jul 29 08:07:12.954035 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/old_phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2OwAAAE8"]
[Wed Jul 29 08:07:12.954432 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/old_phpinfo.php"] [unique_id "ammYkIpuIafV02klyJL2OwAAAE8"]
[Wed Jul 29 08:07:13.042683 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server-info.php"] [unique_id "ammYkYpuIafV02klyJL2PAAAAEg"]
[Wed Jul 29 08:07:13.043536 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/server-info.php"] [unique_id "ammYkYpuIafV02klyJL2PAAAAEg"]
[Wed Jul 29 08:07:13.044195 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/server-info.php"] [unique_id "ammYkYpuIafV02klyJL2PAAAAEg"]
[Wed Jul 29 08:07:13.140758 2026] [:error] [pid 29817:tid 139879090480896] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server-status.php"] [unique_id "ammYkYpuIafV02klyJL2PQAAAEM"]
[Wed Jul 29 08:07:13.141592 2026] [:error] [pid 29817:tid 139879090480896] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/server-status.php"] [unique_id "ammYkYpuIafV02klyJL2PQAAAEM"]
[Wed Jul 29 08:07:13.142119 2026] [:error] [pid 29817:tid 139879090480896] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/server-status.php"] [unique_id "ammYkYpuIafV02klyJL2PQAAAEM"]
[Wed Jul 29 08:07:13.239407 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_profiler/phpinfo"] [unique_id "ammYkYpuIafV02klyJL2QAAAAFI"]
[Wed Jul 29 08:07:13.240430 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_profiler/phpinfo"] [unique_id "ammYkYpuIafV02klyJL2QAAAAFI"]
[Wed Jul 29 08:07:13.240976 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_profiler/phpinfo"] [unique_id "ammYkYpuIafV02klyJL2QAAAAFI"]
[Wed Jul 29 08:07:13.292836 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/_environment"] [unique_id "ammYkYpuIafV02klyJL2QQAAAEY"]
[Wed Jul 29 08:07:13.293832 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/_environment"] [unique_id "ammYkYpuIafV02klyJL2QQAAAEY"]
[Wed Jul 29 08:07:13.294426 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/_environment"] [unique_id "ammYkYpuIafV02klyJL2QQAAAEY"]
[Wed Jul 29 08:07:13.346739 2026] [:error] [pid 29817:tid 139878914234112] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/webroot/index.php/_environment"] [unique_id "ammYkYpuIafV02klyJL2QgAAAFg"]
[Wed Jul 29 08:07:13.347489 2026] [:error] [pid 29817:tid 139878914234112] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/webroot/index.php/_environment"] [unique_id "ammYkYpuIafV02klyJL2QgAAAFg"]
[Wed Jul 29 08:07:13.348062 2026] [:error] [pid 29817:tid 139878914234112] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/webroot/index.php/_environment"] [unique_id "ammYkYpuIafV02klyJL2QgAAAFg"]
[Wed Jul 29 08:07:13.443941 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mail/phpinfo.php"] [unique_id "ammYkYpuIafV02klyJL2QwAAAFA"]
[Wed Jul 29 08:07:13.444574 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mail/phpinfo.php"] [unique_id "ammYkYpuIafV02klyJL2QwAAAFA"]
[Wed Jul 29 08:07:13.445072 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mail/phpinfo.php"] [unique_id "ammYkYpuIafV02klyJL2QwAAAFA"]
[Wed Jul 29 08:07:13.534013 2026] [:error] [pid 29817:tid 139879073695488] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cpanel/phpinfo.php"] [unique_id "ammYkYpuIafV02klyJL2RAAAAEU"]
[Wed Jul 29 08:07:13.860837 2026] [:error] [pid 29817:tid 139878931019520] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/hosting/phpinfo.php"] [unique_id "ammYkYpuIafV02klyJL2RwAAAFY"]
[Wed Jul 29 08:07:13.861875 2026] [:error] [pid 29817:tid 139878931019520] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/hosting/phpinfo.php"] [unique_id "ammYkYpuIafV02klyJL2RwAAAFY"]
[Wed Jul 29 08:07:13.862485 2026] [:error] [pid 29817:tid 139878931019520] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/hosting/phpinfo.php"] [unique_id "ammYkYpuIafV02klyJL2RwAAAFY"]
[Wed Jul 29 08:07:13.934764 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/webmail/phpinfo.php"] [unique_id "ammYkYpuIafV02klyJL2SAAAAEQ"]
[Wed Jul 29 08:07:13.935367 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/webmail/phpinfo.php"] [unique_id "ammYkYpuIafV02klyJL2SAAAAEQ"]
[Wed Jul 29 08:07:13.935845 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/webmail/phpinfo.php"] [unique_id "ammYkYpuIafV02klyJL2SAAAAEQ"]
[Wed Jul 29 08:07:13.978574 2026] [:error] [pid 29817:tid 139879098873600] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/smtp/phpinfo.php"] [unique_id "ammYkYpuIafV02klyJL2SQAAAEI"]
[Wed Jul 29 08:07:13.979277 2026] [:error] [pid 29817:tid 139879098873600] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/smtp/phpinfo.php"] [unique_id "ammYkYpuIafV02klyJL2SQAAAEI"]
[Wed Jul 29 08:07:13.979744 2026] [:error] [pid 29817:tid 139879098873600] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/smtp/phpinfo.php"] [unique_id "ammYkYpuIafV02klyJL2SQAAAEI"]
[Wed Jul 29 08:07:14.035602 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "ammYkopuIafV02klyJL2SgAAAFc"]
[Wed Jul 29 08:07:14.036317 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "ammYkopuIafV02klyJL2SgAAAFc"]
[Wed Jul 29 08:07:14.036793 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "ammYkopuIafV02klyJL2SgAAAFc"]
[Wed Jul 29 08:07:14.142852 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.old"] [unique_id "ammYkopuIafV02klyJL2SwAAAFE"]
[Wed Jul 29 08:07:14.143902 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.old"] [unique_id "ammYkopuIafV02klyJL2SwAAAFE"]
[Wed Jul 29 08:07:14.144515 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.old"] [unique_id "ammYkopuIafV02klyJL2SwAAAFE"]
[Wed Jul 29 08:07:14.244468 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "ammYkopuIafV02klyJL2TAAAAEc"]
[Wed Jul 29 08:07:14.245195 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "ammYkopuIafV02klyJL2TAAAAEc"]
[Wed Jul 29 08:07:14.245440 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Pattern match "\\\\.[^.~]+~(?:/.*|)$" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1060"] [id "920500"] [msg "Attempt to access a backup or working file"] [data ".php~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "ammYkopuIafV02klyJL2TAAAAEc"]
[Wed Jul 29 08:07:14.245671 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "ammYkopuIafV02klyJL2TAAAAEc"]
[Wed Jul 29 08:07:14.334695 2026] [:error] [pid 29817:tid 139878939412224] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "ammYkopuIafV02klyJL2TQAAAFU"]
[Wed Jul 29 08:07:14.335701 2026] [:error] [pid 29817:tid 139878939412224] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "ammYkopuIafV02klyJL2TQAAAFU"]
[Wed Jul 29 08:07:14.336282 2026] [:error] [pid 29817:tid 139878939412224] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "ammYkopuIafV02klyJL2TQAAAFU"]
[Wed Jul 29 08:07:14.388413 2026] [:error] [pid 29817:tid 139878947804928] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.save"] [unique_id "ammYkopuIafV02klyJL2TgAAAFQ"]
[Wed Jul 29 08:07:14.389064 2026] [:error] [pid 29817:tid 139878947804928] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.save"] [unique_id "ammYkopuIafV02klyJL2TgAAAFQ"]
[Wed Jul 29 08:07:14.389500 2026] [:error] [pid 29817:tid 139878947804928] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/phpinfo.php.save"] [unique_id "ammYkopuIafV02klyJL2TgAAAFQ"]
[Wed Jul 29 08:07:14.452634 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/staging/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2TwAAAEA"]
[Wed Jul 29 08:07:14.453487 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/staging/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2TwAAAEA"]
[Wed Jul 29 08:07:14.453981 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/staging/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2TwAAAEA"]
[Wed Jul 29 08:07:14.541957 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/beta/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2UAAAAE8"]
[Wed Jul 29 08:07:14.542588 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/beta/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2UAAAAE8"]
[Wed Jul 29 08:07:14.542970 2026] [:error] [pid 29817:tid 139878989768448] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/beta/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2UAAAAE8"]
[Wed Jul 29 08:07:14.593138 2026] [:error] [pid 29817:tid 139878956197632] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/uat/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2UQAAAFM"]
[Wed Jul 29 08:07:14.593739 2026] [:error] [pid 29817:tid 139878956197632] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/uat/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2UQAAAFM"]
[Wed Jul 29 08:07:14.594120 2026] [:error] [pid 29817:tid 139878956197632] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/uat/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2UQAAAFM"]
[Wed Jul 29 08:07:14.653357 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/qa/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2UgAAAEg"]
[Wed Jul 29 08:07:14.653987 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/qa/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2UgAAAEg"]
[Wed Jul 29 08:07:14.654375 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/qa/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2UgAAAEg"]
[Wed Jul 29 08:07:14.798141 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/preview/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2VAAAAE4"]
[Wed Jul 29 08:07:14.798861 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/preview/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2VAAAAE4"]
[Wed Jul 29 08:07:14.799248 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/preview/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2VAAAAE4"]
[Wed Jul 29 08:07:14.939453 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/www/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2VQAAAEY"]
[Wed Jul 29 08:07:14.940161 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/www/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2VQAAAEY"]
[Wed Jul 29 08:07:14.940597 2026] [:error] [pid 29817:tid 139879065302784] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/www/phpinfo.php"] [unique_id "ammYkopuIafV02klyJL2VQAAAEY"]
[Wed Jul 29 08:07:15.034471 2026] [:error] [pid 29817:tid 139879014946560] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2VgAAAEw"]
[Wed Jul 29 08:07:15.035496 2026] [:error] [pid 29817:tid 139879014946560] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2VgAAAEw"]
[Wed Jul 29 08:07:15.036170 2026] [:error] [pid 29817:tid 139879014946560] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2VgAAAEw"]
[Wed Jul 29 08:07:15.134341 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/public_html/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2VwAAAFA"]
[Wed Jul 29 08:07:15.135281 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/public_html/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2VwAAAFA"]
[Wed Jul 29 08:07:15.135875 2026] [:error] [pid 29817:tid 139878981375744] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/public_html/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2VwAAAFA"]
[Wed Jul 29 08:07:15.187502 2026] [:error] [pid 29817:tid 139879073695488] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/site/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2WAAAAEU"]
[Wed Jul 29 08:07:15.188124 2026] [:error] [pid 29817:tid 139879073695488] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/site/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2WAAAAEU"]
[Wed Jul 29 08:07:15.188529 2026] [:error] [pid 29817:tid 139879073695488] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/site/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2WAAAAEU"]
[Wed Jul 29 08:07:15.253842 2026] [:error] [pid 29817:tid 139879040124672] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/docs/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2WQAAAEk"]
[Wed Jul 29 08:07:15.254763 2026] [:error] [pid 29817:tid 139879040124672] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/docs/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2WQAAAEk"]
[Wed Jul 29 08:07:15.255183 2026] [:error] [pid 29817:tid 139879040124672] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/docs/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2WQAAAEk"]
[Wed Jul 29 08:07:15.344537 2026] [:error] [pid 29817:tid 139878931019520] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2WgAAAFY"]
[Wed Jul 29 08:07:15.345222 2026] [:error] [pid 29817:tid 139878931019520] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2WgAAAFY"]
[Wed Jul 29 08:07:15.345623 2026] [:error] [pid 29817:tid 139878931019520] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2WgAAAFY"]
[Wed Jul 29 08:07:15.434216 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/administrator/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2WwAAAEQ"]
[Wed Jul 29 08:07:15.435092 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/administrator/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2WwAAAEQ"]
[Wed Jul 29 08:07:15.435615 2026] [:error] [pid 29817:tid 139879082088192] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/administrator/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2WwAAAEQ"]
[Wed Jul 29 08:07:15.493764 2026] [:error] [pid 29817:tid 139879098873600] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/core/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2XQAAAEI"]
[Wed Jul 29 08:07:15.494467 2026] [:error] [pid 29817:tid 139879098873600] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/core/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2XQAAAEI"]
[Wed Jul 29 08:07:15.494965 2026] [:error] [pid 29817:tid 139879098873600] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/core/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2XQAAAEI"]
[Wed Jul 29 08:07:15.571457 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/includes/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2XgAAAFc"]
[Wed Jul 29 08:07:15.572146 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/includes/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2XgAAAFc"]
[Wed Jul 29 08:07:15.572602 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/includes/phpinfo.php"] [unique_id "ammYk4puIafV02klyJL2XgAAAFc"]
[Wed Jul 29 08:07:15.653703 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/service-account.json"] [unique_id "ammYk4puIafV02klyJL2XwAAAFE"]
[Wed Jul 29 08:07:15.654634 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/service-account.json"] [unique_id "ammYk4puIafV02klyJL2XwAAAFE"]
[Wed Jul 29 08:07:15.655191 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/service-account.json"] [unique_id "ammYk4puIafV02klyJL2XwAAAFE"]
[Wed Jul 29 08:07:15.744567 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sa.json"] [unique_id "ammYk4puIafV02klyJL2YAAAAEc"]
[Wed Jul 29 08:07:15.745303 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sa.json"] [unique_id "ammYk4puIafV02klyJL2YAAAAEc"]
[Wed Jul 29 08:07:15.745771 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sa.json"] [unique_id "ammYk4puIafV02klyJL2YAAAAEc"]
[Wed Jul 29 08:07:15.844474 2026] [:error] [pid 29817:tid 139878939412224] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gcp-key.json"] [unique_id "ammYk4puIafV02klyJL2YQAAAFU"]
[Wed Jul 29 08:07:15.845060 2026] [:error] [pid 29817:tid 139878939412224] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gcp-key.json"] [unique_id "ammYk4puIafV02klyJL2YQAAAFU"]
[Wed Jul 29 08:07:15.845532 2026] [:error] [pid 29817:tid 139878939412224] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gcp-key.json"] [unique_id "ammYk4puIafV02klyJL2YQAAAFU"]
[Wed Jul 29 08:07:15.895669 2026] [:error] [pid 29817:tid 139878947804928] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gcp-credentials.json"] [unique_id "ammYk4puIafV02klyJL2YgAAAFQ"]
[Wed Jul 29 08:07:15.978410 2026] [:error] [pid 29817:tid 139878947804928] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gcp-credentials.json"] [unique_id "ammYk4puIafV02klyJL2YgAAAFQ"]
[Wed Jul 29 08:07:15.979007 2026] [:error] [pid 29817:tid 139878947804928] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gcp-credentials.json"] [unique_id "ammYk4puIafV02klyJL2YgAAAFQ"]
[Wed Jul 29 08:07:16.034829 2026] [:error] [pid 29817:tid 139879177004800] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gcp-sa.json"] [unique_id "ammYlIpuIafV02klyJL2YwAAAEE"]
[Wed Jul 29 08:07:16.035747 2026] [:error] [pid 29817:tid 139879177004800] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gcp-sa.json"] [unique_id "ammYlIpuIafV02klyJL2YwAAAEE"]
[Wed Jul 29 08:07:16.036329 2026] [:error] [pid 29817:tid 139879177004800] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gcp-sa.json"] [unique_id "ammYlIpuIafV02klyJL2YwAAAEE"]
[Wed Jul 29 08:07:16.089286 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/credentials.json"] [unique_id "ammYlIpuIafV02klyJL2ZAAAAEA"]
[Wed Jul 29 08:07:16.089951 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/credentials.json"] [unique_id "ammYlIpuIafV02klyJL2ZAAAAEA"]
[Wed Jul 29 08:07:16.090345 2026] [:error] [pid 29817:tid 139879185397504] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/credentials.json"] [unique_id "ammYlIpuIafV02klyJL2ZAAAAEA"]
[Wed Jul 29 08:07:16.145148 2026] [:error] [pid 29817:tid 139879023339264] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/google-credentials.json"] [unique_id "ammYlIpuIafV02klyJL2ZgAAAEs"]
[Wed Jul 29 08:07:16.166916 2026] [:error] [pid 29817:tid 139879023339264] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/google-credentials.json"] [unique_id "ammYlIpuIafV02klyJL2ZgAAAEs"]
[Wed Jul 29 08:07:16.167619 2026] [:error] [pid 29817:tid 139879023339264] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/google-credentials.json"] [unique_id "ammYlIpuIafV02klyJL2ZgAAAEs"]
[Wed Jul 29 08:07:16.244883 2026] [:error] [pid 29817:tid 139878956197632] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/google-key.json"] [unique_id "ammYlIpuIafV02klyJL2ZwAAAFM"]
[Wed Jul 29 08:07:16.245854 2026] [:error] [pid 29817:tid 139878956197632] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/google-key.json"] [unique_id "ammYlIpuIafV02klyJL2ZwAAAFM"]
[Wed Jul 29 08:07:16.246418 2026] [:error] [pid 29817:tid 139878956197632] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/google-key.json"] [unique_id "ammYlIpuIafV02klyJL2ZwAAAFM"]
[Wed Jul 29 08:07:16.434053 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.config/gcloud/application_default_credentials.json"] [unique_id "ammYlIpuIafV02klyJL2aAAAAEg"]
[Wed Jul 29 08:07:16.434853 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.config/gcloud/application_default_credentials.json"] [unique_id "ammYlIpuIafV02klyJL2aAAAAEg"]
[Wed Jul 29 08:07:16.435341 2026] [:error] [pid 29817:tid 139879048517376] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.config/gcloud/application_default_credentials.json"] [unique_id "ammYlIpuIafV02klyJL2aAAAAEg"]
[Wed Jul 29 08:07:16.492325 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application_default_credentials.json"] [unique_id "ammYlIpuIafV02klyJL2aQAAAFI"]
[Wed Jul 29 08:07:16.492912 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application_default_credentials.json"] [unique_id "ammYlIpuIafV02klyJL2aQAAAFI"]
[Wed Jul 29 08:07:16.493276 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application_default_credentials.json"] [unique_id "ammYlIpuIafV02klyJL2aQAAAFI"]
[Wed Jul 29 08:07:16.553688 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/key.json"] [unique_id "ammYlIpuIafV02klyJL2agAAAE4"]
[Wed Jul 29 08:07:16.554517 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/key.json"] [unique_id "ammYlIpuIafV02klyJL2agAAAE4"]
[Wed Jul 29 08:07:16.555132 2026] [:error] [pid 29817:tid 139878998161152] [client 162.158.49.88:9462] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/key.json"] [unique_id "ammYlIpuIafV02klyJL2agAAAE4"]
[Wed Jul 29 08:07:16.734414 2026] [:error] [pid 12728:tid 139878956197632] [client 162.158.49.88:9469] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/keyfile.json"] [unique_id "ammYlDqdFZ1TNKvQdY1jpgAAAVM"]
[Wed Jul 29 08:07:16.735207 2026] [:error] [pid 12728:tid 139878956197632] [client 162.158.49.88:9469] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/keyfile.json"] [unique_id "ammYlDqdFZ1TNKvQdY1jpgAAAVM"]
[Wed Jul 29 08:07:16.735857 2026] [:error] [pid 12728:tid 139878956197632] [client 162.158.49.88:9469] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/keyfile.json"] [unique_id "ammYlDqdFZ1TNKvQdY1jpgAAAVM"]
[Wed Jul 29 08:07:16.792719 2026] [:error] [pid 12728:tid 139879040124672] [client 162.158.49.88:9469] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/firebase-adminsdk.json"] [unique_id "ammYlDqdFZ1TNKvQdY1jqAAAAUk"]
[Wed Jul 29 08:07:16.793461 2026] [:error] [pid 12728:tid 139879040124672] [client 162.158.49.88:9469] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/firebase-adminsdk.json"] [unique_id "ammYlDqdFZ1TNKvQdY1jqAAAAUk"]
[Wed Jul 29 08:07:16.793914 2026] [:error] [pid 12728:tid 139879040124672] [client 162.158.49.88:9469] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/firebase-adminsdk.json"] [unique_id "ammYlDqdFZ1TNKvQdY1jqAAAAUk"]
[Wed Jul 29 08:07:16.857600 2026] [:error] [pid 12728:tid 139879065302784] [client 162.158.49.88:9469] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/firebase-key.json"] [unique_id "ammYlDqdFZ1TNKvQdY1jqQAAAUY"]
[Wed Jul 29 08:07:16.858450 2026] [:error] [pid 12728:tid 139879065302784] [client 162.158.49.88:9469] [client 162.158.49.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/firebase-key.json"] [unique_id "ammYlDqdFZ1TNKvQdY1jqQAAAUY"]
[Wed Jul 29 08:07:16.858985 2026] [:error] [pid 12728:tid 139879065302784] [client 162.158.49.88:9469] [client 162.158.49.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/firebase-key.json"] [unique_id "ammYlDqdFZ1TNKvQdY1jqQAAAUY"]
[Wed Jul 29 08:10:10.138066 2026] [:error] [pid 32190:tid 139878964590336] [client 172.71.154.26:11704] [client 172.71.154.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZQqGf2ExAGdIXvjNbGAAAARI"]
[Wed Jul 29 08:10:10.138792 2026] [:error] [pid 32190:tid 139878964590336] [client 172.71.154.26:11704] [client 172.71.154.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZQqGf2ExAGdIXvjNbGAAAARI"]
[Wed Jul 29 08:10:10.139207 2026] [:error] [pid 32190:tid 139878964590336] [client 172.71.154.26:11704] [client 172.71.154.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZQqGf2ExAGdIXvjNbGAAAARI"]
[Wed Jul 29 08:10:10.148937 2026] [:error] [pid 12781:tid 139878989768448] [client 162.158.163.204:9731] [client 162.158.163.204] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/license.txt"] [unique_id "ammZQmwejwALtycjqdrMaAAAAY8"]
[Wed Jul 29 08:10:10.149915 2026] [:error] [pid 12781:tid 139878989768448] [client 162.158.163.204:9731] [client 162.158.163.204] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/license.txt"] [unique_id "ammZQmwejwALtycjqdrMaAAAAY8"]
[Wed Jul 29 08:10:10.150048 2026] [:error] [pid 12781:tid 139878989768448] [client 162.158.163.204:9731] [client 162.158.163.204] ModSecurity: Warning. Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "142"] [id "913101"] [msg "Found User-Agent associated with scripting/generic HTTP client"] [data "Matched Data: python-requests found within REQUEST_HEADERS:User-Agent: python-requests/2.27.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scripting"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/license.txt"] [unique_id "ammZQmwejwALtycjqdrMaAAAAY8"]
[Wed Jul 29 08:10:10.150383 2026] [:error] [pid 12781:tid 139878989768448] [client 162.158.163.204:9731] [client 162.158.163.204] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/license.txt"] [unique_id "ammZQmwejwALtycjqdrMaAAAAY8"]
[Wed Jul 29 08:10:10.155711 2026] [:error] [pid 29817:tid 139878972983040] [client 172.69.134.202:12896] [client 172.69.134.202] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZQopuIafV02klyJL3bQAAAFE"]
[Wed Jul 29 08:10:10.156273 2026] [:error] [pid 29817:tid 139878972983040] [client 172.69.134.202:12896] [client 172.69.134.202] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZQopuIafV02klyJL3bQAAAFE"]
[Wed Jul 29 08:10:10.156609 2026] [:error] [pid 29817:tid 139878972983040] [client 172.69.134.202:12896] [client 172.69.134.202] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZQopuIafV02klyJL3bQAAAFE"]
[Wed Jul 29 08:10:10.344435 2026] [:error] [pid 12781:tid 139878998161152] [client 172.71.155.154:12169] [client 172.71.155.154] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZQmwejwALtycjqdrMaQAAAY4"]
[Wed Jul 29 08:10:10.345520 2026] [:error] [pid 12781:tid 139878998161152] [client 172.71.155.154:12169] [client 172.71.155.154] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZQmwejwALtycjqdrMaQAAAY4"]
[Wed Jul 29 08:10:10.346022 2026] [:error] [pid 12781:tid 139878998161152] [client 172.71.155.154:12169] [client 172.71.155.154] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZQmwejwALtycjqdrMaQAAAY4"]
[Wed Jul 29 08:10:10.365311 2026] [:error] [pid 29818:tid 139879073695488] [client 172.69.23.92:13983] [client 172.69.23.92] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZQsNm_eEjUiZv2_itXwAAAIU"]
[Wed Jul 29 08:10:10.366272 2026] [:error] [pid 29818:tid 139879073695488] [client 172.69.23.92:13983] [client 172.69.23.92] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZQsNm_eEjUiZv2_itXwAAAIU"]
[Wed Jul 29 08:10:10.366818 2026] [:error] [pid 29818:tid 139879073695488] [client 172.69.23.92:13983] [client 172.69.23.92] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZQsNm_eEjUiZv2_itXwAAAIU"]
[Wed Jul 29 08:10:41.387158 2026] [:error] [pid 12728:tid 139879048517376] [client 172.71.154.27:13573] [client 172.71.154.27] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZYTqdFZ1TNKvQdY1lJwAAAUg"]
[Wed Jul 29 08:10:41.388140 2026] [:error] [pid 12728:tid 139879048517376] [client 172.71.154.27:13573] [client 172.71.154.27] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZYTqdFZ1TNKvQdY1lJwAAAUg"]
[Wed Jul 29 08:10:41.388671 2026] [:error] [pid 12728:tid 139879048517376] [client 172.71.154.27:13573] [client 172.71.154.27] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZYTqdFZ1TNKvQdY1lJwAAAUg"]
[Wed Jul 29 08:10:41.391317 2026] [:error] [pid 12728:tid 139879048517376] [client 162.158.167.48:9594] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZYTqdFZ1TNKvQdY1lKAAAAUg"]
[Wed Jul 29 08:10:41.392033 2026] [:error] [pid 12728:tid 139879048517376] [client 162.158.167.48:9594] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZYTqdFZ1TNKvQdY1lKAAAAUg"]
[Wed Jul 29 08:10:41.392510 2026] [:error] [pid 12728:tid 139879048517376] [client 162.158.167.48:9594] [client 162.158.167.48] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZYTqdFZ1TNKvQdY1lKAAAAUg"]
[Wed Jul 29 08:10:41.789267 2026] [:error] [pid 29913:tid 139879098873600] [client 172.69.135.36:11143] [client 172.69.135.36] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZYQVDiGi-ktKYT-KoHwAAAMI"]
[Wed Jul 29 08:10:41.789267 2026] [:error] [pid 29913:tid 139878981375744] [client 172.71.158.125:14132] [client 172.71.158.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZYQVDiGi-ktKYT-KoIAAAANA"]
[Wed Jul 29 08:10:41.789813 2026] [:error] [pid 29913:tid 139878981375744] [client 172.71.158.125:14132] [client 172.71.158.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZYQVDiGi-ktKYT-KoIAAAANA"]
[Wed Jul 29 08:10:41.789815 2026] [:error] [pid 29913:tid 139879098873600] [client 172.69.135.36:11143] [client 172.69.135.36] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZYQVDiGi-ktKYT-KoHwAAAMI"]
[Wed Jul 29 08:10:41.790129 2026] [:error] [pid 29913:tid 139878981375744] [client 172.71.158.125:14132] [client 172.71.158.125] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZYQVDiGi-ktKYT-KoIAAAANA"]
[Wed Jul 29 08:10:41.790157 2026] [:error] [pid 29913:tid 139879098873600] [client 172.69.135.36:11143] [client 172.69.135.36] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZYQVDiGi-ktKYT-KoHwAAAMI"]
[Wed Jul 29 08:11:42.644746 2026] [:error] [pid 32190:tid 139879082088192] [client 162.158.167.48:12449] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZnqGf2ExAGdIXvjNdngAAAQQ"]
[Wed Jul 29 08:11:42.645349 2026] [:error] [pid 32190:tid 139879082088192] [client 162.158.167.48:12449] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZnqGf2ExAGdIXvjNdngAAAQQ"]
[Wed Jul 29 08:11:42.645810 2026] [:error] [pid 32190:tid 139879082088192] [client 162.158.167.48:12449] [client 162.158.167.48] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZnqGf2ExAGdIXvjNdngAAAQQ"]
[Wed Jul 29 08:11:42.647748 2026] [:error] [pid 32190:tid 139879082088192] [client 172.71.154.26:11879] [client 172.71.154.26] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZnqGf2ExAGdIXvjNdnwAAAQQ"]
[Wed Jul 29 08:11:42.648190 2026] [:error] [pid 32190:tid 139879082088192] [client 172.71.154.26:11879] [client 172.71.154.26] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZnqGf2ExAGdIXvjNdnwAAAQQ"]
[Wed Jul 29 08:11:42.648543 2026] [:error] [pid 32190:tid 139879082088192] [client 172.71.154.26:11879] [client 172.71.154.26] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZnqGf2ExAGdIXvjNdnwAAAQQ"]
[Wed Jul 29 08:11:43.133867 2026] [:error] [pid 29913:tid 139878964590336] [client 172.69.135.35:9260] [client 172.69.135.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZnwVDiGi-ktKYT-KolwAAANI"]
[Wed Jul 29 08:11:43.134431 2026] [:error] [pid 29913:tid 139878964590336] [client 172.69.135.35:9260] [client 172.69.135.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZnwVDiGi-ktKYT-KolwAAANI"]
[Wed Jul 29 08:11:43.134857 2026] [:error] [pid 29913:tid 139878964590336] [client 172.69.135.35:9260] [client 172.69.135.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZnwVDiGi-ktKYT-KolwAAANI"]
[Wed Jul 29 08:11:43.234880 2026] [:error] [pid 29913:tid 139879073695488] [client 104.22.20.117:13735] [client 104.22.20.117] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZnwVDiGi-ktKYT-KomQAAAMU"]
[Wed Jul 29 08:11:43.235874 2026] [:error] [pid 29913:tid 139879073695488] [client 104.22.20.117:13735] [client 104.22.20.117] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZnwVDiGi-ktKYT-KomQAAAMU"]
[Wed Jul 29 08:11:43.236368 2026] [:error] [pid 29913:tid 139879073695488] [client 104.22.20.117:13735] [client 104.22.20.117] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammZnwVDiGi-ktKYT-KomQAAAMU"]
[Wed Jul 29 08:13:44.284395 2026] [:error] [pid 29913:tid 139879014946560] [client 162.158.167.47:14131] [client 162.158.167.47] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammaGAVDiGi-ktKYT-KpeAAAAMw"]
[Wed Jul 29 08:13:44.285052 2026] [:error] [pid 29913:tid 139879014946560] [client 162.158.167.47:14131] [client 162.158.167.47] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammaGAVDiGi-ktKYT-KpeAAAAMw"]
[Wed Jul 29 08:13:44.285404 2026] [:error] [pid 29913:tid 139879014946560] [client 162.158.167.47:14131] [client 162.158.167.47] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammaGAVDiGi-ktKYT-KpeAAAAMw"]
[Wed Jul 29 08:13:44.290305 2026] [:error] [pid 12782:tid 139878956197632] [client 172.69.134.202:13674] [client 172.69.134.202] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammaGEFdlBZRl6Abom2FuAAAAdM"]
[Wed Jul 29 08:13:44.290890 2026] [:error] [pid 12782:tid 139878956197632] [client 172.69.134.202:13674] [client 172.69.134.202] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammaGEFdlBZRl6Abom2FuAAAAdM"]
[Wed Jul 29 08:13:44.291207 2026] [:error] [pid 12782:tid 139878956197632] [client 172.69.134.202:13674] [client 172.69.134.202] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammaGEFdlBZRl6Abom2FuAAAAdM"]
[Wed Jul 29 08:13:44.849846 2026] [:error] [pid 29913:tid 139878964590336] [client 104.22.17.16:9924] [client 104.22.17.16] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammaGAVDiGi-ktKYT-KpeQAAANI"]
[Wed Jul 29 08:13:44.850778 2026] [:error] [pid 29913:tid 139878964590336] [client 104.22.17.16:9924] [client 104.22.17.16] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammaGAVDiGi-ktKYT-KpeQAAANI"]
[Wed Jul 29 08:13:44.851284 2026] [:error] [pid 29913:tid 139878964590336] [client 104.22.17.16:9924] [client 104.22.17.16] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammaGAVDiGi-ktKYT-KpeQAAANI"]
[Wed Jul 29 08:13:45.043856 2026] [:error] [pid 29913:tid 139879073695488] [client 172.71.155.154:12725] [client 172.71.155.154] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammaGAVDiGi-ktKYT-KpegAAAMU"]
[Wed Jul 29 08:13:45.044505 2026] [:error] [pid 29913:tid 139879073695488] [client 172.71.155.154:12725] [client 172.71.155.154] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammaGAVDiGi-ktKYT-KpegAAAMU"]
[Wed Jul 29 08:13:45.044872 2026] [:error] [pid 29913:tid 139879073695488] [client 172.71.155.154:12725] [client 172.71.155.154] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammaGAVDiGi-ktKYT-KpegAAAMU"]
[Wed Jul 29 08:15:24.739498 2026] [:error] [pid 29818:tid 139879006553856] [client 172.70.208.166:12690] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ammafMNm_eEjUiZv2_ivDQAAAI0"]
[Wed Jul 29 08:15:24.740442 2026] [:error] [pid 29818:tid 139879006553856] [client 172.70.208.166:12690] [client 172.70.208.166] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ammafMNm_eEjUiZv2_ivDQAAAI0"]
[Wed Jul 29 08:15:24.741022 2026] [:error] [pid 29818:tid 139879006553856] [client 172.70.208.166:12690] [client 172.70.208.166] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ammafMNm_eEjUiZv2_ivDQAAAI0"]
[Wed Jul 29 08:18:45.442210 2026] [:error] [pid 29816:tid 139879073695488] [client 162.158.167.47:11144] [client 162.158.167.47] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammbRbiIh7LJBqOi9DxvmQAAAAU"]
[Wed Jul 29 08:18:45.442215 2026] [:error] [pid 29816:tid 139879082088192] [client 162.158.167.47:11138] [client 162.158.167.47] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammbRbiIh7LJBqOi9DxvmAAAAAQ"]
[Wed Jul 29 08:18:45.443152 2026] [:error] [pid 29816:tid 139879082088192] [client 162.158.167.47:11138] [client 162.158.167.47] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammbRbiIh7LJBqOi9DxvmAAAAAQ"]
[Wed Jul 29 08:18:45.443170 2026] [:error] [pid 29816:tid 139879073695488] [client 162.158.167.47:11144] [client 162.158.167.47] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammbRbiIh7LJBqOi9DxvmQAAAAU"]
[Wed Jul 29 08:18:45.443774 2026] [:error] [pid 29816:tid 139879082088192] [client 162.158.167.47:11138] [client 162.158.167.47] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammbRbiIh7LJBqOi9DxvmAAAAAQ"]
[Wed Jul 29 08:18:45.443796 2026] [:error] [pid 29816:tid 139879073695488] [client 162.158.167.47:11144] [client 162.158.167.47] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammbRbiIh7LJBqOi9DxvmQAAAAU"]
[Wed Jul 29 08:18:46.845765 2026] [:error] [pid 29913:tid 139878947804928] [client 162.158.167.19:10803] [client 162.158.167.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammbRgVDiGi-ktKYT-KswwAAANQ"]
[Wed Jul 29 08:18:46.846691 2026] [:error] [pid 29913:tid 139878947804928] [client 162.158.167.19:10803] [client 162.158.167.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammbRgVDiGi-ktKYT-KswwAAANQ"]
[Wed Jul 29 08:18:46.847290 2026] [:error] [pid 29913:tid 139878947804928] [client 162.158.167.19:10803] [client 162.158.167.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammbRgVDiGi-ktKYT-KswwAAANQ"]
[Wed Jul 29 08:18:46.854951 2026] [:error] [pid 29816:tid 139879098873600] [client 172.69.23.91:9338] [client 172.69.23.91] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammbRriIh7LJBqOi9DxvowAAAAI"]
[Wed Jul 29 08:18:46.855725 2026] [:error] [pid 29816:tid 139879098873600] [client 172.69.23.91:9338] [client 172.69.23.91] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammbRriIh7LJBqOi9DxvowAAAAI"]
[Wed Jul 29 08:18:46.856221 2026] [:error] [pid 29816:tid 139879098873600] [client 172.69.23.91:9338] [client 172.69.23.91] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammbRriIh7LJBqOi9DxvowAAAAI"]
[Wed Jul 29 08:23:34.676917 2026] [:error] [pid 29818:tid 139879023339264] [client 104.23.197.76:12755] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ammcZsNm_eEjUiZv2_ixRQAAAIs"]
[Wed Jul 29 08:23:34.678165 2026] [:error] [pid 29818:tid 139879023339264] [client 104.23.197.76:12755] [client 104.23.197.76] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ammcZsNm_eEjUiZv2_ixRQAAAIs"]
[Wed Jul 29 08:23:34.678778 2026] [:error] [pid 29818:tid 139879023339264] [client 104.23.197.76:12755] [client 104.23.197.76] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ammcZsNm_eEjUiZv2_ixRQAAAIs"]
[Wed Jul 29 08:28:46.835747 2026] [:error] [pid 29913:tid 139878998161152] [client 104.22.17.232:9697] [client 104.22.17.232] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammdngVDiGi-ktKYT-KzkAAAAM4"]
[Wed Jul 29 08:28:46.836600 2026] [:error] [pid 29913:tid 139878998161152] [client 104.22.17.232:9697] [client 104.22.17.232] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammdngVDiGi-ktKYT-KzkAAAAM4"]
[Wed Jul 29 08:28:46.837194 2026] [:error] [pid 29913:tid 139878998161152] [client 104.22.17.232:9697] [client 104.22.17.232] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammdngVDiGi-ktKYT-KzkAAAAM4"]
[Wed Jul 29 08:28:46.837734 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.167.48:10042] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammdnopuIafV02klyJL_xQAAAFI"]
[Wed Jul 29 08:28:46.838272 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.167.48:10042] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammdnopuIafV02klyJL_xQAAAFI"]
[Wed Jul 29 08:28:46.838689 2026] [:error] [pid 29817:tid 139878964590336] [client 162.158.167.48:10042] [client 162.158.167.48] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammdnopuIafV02klyJL_xQAAAFI"]
[Wed Jul 29 08:28:48.183381 2026] [:error] [pid 12782:tid 139879082088192] [client 172.71.155.153:11252] [client 172.71.155.153] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammdoEFdlBZRl6Abom2OBwAAAcQ"]
[Wed Jul 29 08:28:48.184190 2026] [:error] [pid 12782:tid 139879082088192] [client 172.71.155.153:11252] [client 172.71.155.153] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammdoEFdlBZRl6Abom2OBwAAAcQ"]
[Wed Jul 29 08:28:48.184697 2026] [:error] [pid 12782:tid 139879082088192] [client 172.71.155.153:11252] [client 172.71.155.153] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammdoEFdlBZRl6Abom2OBwAAAcQ"]
[Wed Jul 29 08:28:48.234078 2026] [:error] [pid 29913:tid 139879090480896] [client 162.158.167.19:13404] [client 162.158.167.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammdoAVDiGi-ktKYT-KzlAAAAMM"]
[Wed Jul 29 08:28:48.234955 2026] [:error] [pid 29913:tid 139879090480896] [client 162.158.167.19:13404] [client 162.158.167.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammdoAVDiGi-ktKYT-KzlAAAAMM"]
[Wed Jul 29 08:28:48.235400 2026] [:error] [pid 29913:tid 139879090480896] [client 162.158.167.19:13404] [client 162.158.167.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammdoAVDiGi-ktKYT-KzlAAAAMM"]
[Wed Jul 29 08:32:45.122166 2026] [:error] [pid 12782:tid 139878914234112] [client 172.71.158.54:11555] [client 172.71.158.54] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammejUFdlBZRl6Abom2P-gAAAdg"]
[Wed Jul 29 08:32:45.123163 2026] [:error] [pid 12782:tid 139878914234112] [client 172.71.158.54:11555] [client 172.71.158.54] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammejUFdlBZRl6Abom2P-gAAAdg"]
[Wed Jul 29 08:32:45.123647 2026] [:error] [pid 12782:tid 139878914234112] [client 172.71.158.54:11555] [client 172.71.158.54] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammejUFdlBZRl6Abom2P-gAAAdg"]
[Wed Jul 29 08:32:45.125426 2026] [:error] [pid 12782:tid 139878914234112] [client 172.69.134.203:13280] [client 172.69.134.203] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammejUFdlBZRl6Abom2P-wAAAdg"]
[Wed Jul 29 08:32:45.125991 2026] [:error] [pid 12782:tid 139878914234112] [client 172.69.134.203:13280] [client 172.69.134.203] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammejUFdlBZRl6Abom2P-wAAAdg"]
[Wed Jul 29 08:32:45.126253 2026] [:error] [pid 12782:tid 139878914234112] [client 172.69.134.203:13280] [client 172.69.134.203] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/__resolve-check"] [unique_id "ammejUFdlBZRl6Abom2P-wAAAdg"]
[Wed Jul 29 08:42:31.049583 2026] [:error] [pid 29816:tid 139879048517376] [client 104.22.100.89:9960] [client 104.22.100.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammg17iIh7LJBqOi9Dx-fgAAAAg"]
[Wed Jul 29 08:42:31.078813 2026] [:error] [pid 29816:tid 139879048517376] [client 104.22.100.89:9960] [client 104.22.100.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammg17iIh7LJBqOi9Dx-fgAAAAg"]
[Wed Jul 29 08:42:31.079157 2026] [:error] [pid 29816:tid 139879048517376] [client 104.22.100.89:9960] [client 104.22.100.89] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammg17iIh7LJBqOi9Dx-fgAAAAg"]
[Wed Jul 29 08:42:31.079234 2026] [:error] [pid 29816:tid 139879048517376] [client 104.22.100.89:9960] [client 104.22.100.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammg17iIh7LJBqOi9Dx-fgAAAAg"]
[Wed Jul 29 08:42:31.244031 2026] [:error] [pid 12728:tid 139879056910080] [client 172.71.223.107:10091] [client 172.71.223.107] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammg1zqdFZ1TNKvQdY1zrAAAAUc"]
[Wed Jul 29 08:42:31.244710 2026] [:error] [pid 12728:tid 139879056910080] [client 172.71.223.107:10091] [client 172.71.223.107] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammg1zqdFZ1TNKvQdY1zrAAAAUc"]
[Wed Jul 29 08:42:31.245091 2026] [:error] [pid 12728:tid 139879056910080] [client 172.71.223.107:10091] [client 172.71.223.107] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammg1zqdFZ1TNKvQdY1zrAAAAUc"]
[Wed Jul 29 09:17:36.942350 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.206.129:11959] [client 172.70.206.129] ModSecurity: Warning. Match of "rx ^%{tx.allowed_request_content_type_charset}$" against "TX:1" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "983"] [id "920480"] [msg "Request content type charset is not allowed by policy"] [data "utf-8"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammpEKGf2ExAGdIXvjOYYwAAARQ"]
[Wed Jul 29 09:17:36.942608 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.206.129:11959] [client 172.70.206.129] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammpEKGf2ExAGdIXvjOYYwAAARQ"]
[Wed Jul 29 09:17:36.943534 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.206.129:11959] [client 172.70.206.129] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammpEKGf2ExAGdIXvjOYYwAAARQ"]
[Wed Jul 29 09:17:36.943890 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.206.129:11959] [client 172.70.206.129] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|text/html|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammpEKGf2ExAGdIXvjOYYwAAARQ"]
[Wed Jul 29 09:17:36.944221 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.206.129:11959] [client 172.70.206.129] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammpEKGf2ExAGdIXvjOYYwAAARQ"]
[Wed Jul 29 09:19:56.689961 2026] [:error] [pid 29816:tid 139878981375744] [client 104.23.217.116:12000] [client 104.23.217.116] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ammpnLiIh7LJBqOi9DynLgAAABA"]
[Wed Jul 29 09:19:56.691117 2026] [:error] [pid 29816:tid 139878981375744] [client 104.23.217.116:12000] [client 104.23.217.116] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ammpnLiIh7LJBqOi9DynLgAAABA"]
[Wed Jul 29 09:19:56.691809 2026] [:error] [pid 29816:tid 139878981375744] [client 104.23.217.116:12000] [client 104.23.217.116] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "ammpnLiIh7LJBqOi9DynLgAAABA"]
[Wed Jul 29 09:35:47.185207 2026] [:error] [pid 12728:tid 139879098873600] [client 162.158.167.48:14306] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammtUzqdFZ1TNKvQdY2HmAAAAUI"]
[Wed Jul 29 09:35:47.252648 2026] [:error] [pid 12728:tid 139879098873600] [client 162.158.167.48:14306] [client 162.158.167.48] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammtUzqdFZ1TNKvQdY2HmAAAAUI"]
[Wed Jul 29 09:35:47.253087 2026] [:error] [pid 12728:tid 139879098873600] [client 162.158.167.48:14306] [client 162.158.167.48] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammtUzqdFZ1TNKvQdY2HmAAAAUI"]
[Wed Jul 29 09:37:38.388432 2026] [:error] [pid 29913:tid 139879098873600] [client 172.68.130.154:13723] [client 172.68.130.154] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammtwgVDiGi-ktKYT-LmVQAAAMI"]
[Wed Jul 29 09:37:38.389234 2026] [:error] [pid 29913:tid 139879098873600] [client 172.68.130.154:13723] [client 172.68.130.154] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammtwgVDiGi-ktKYT-LmVQAAAMI"]
[Wed Jul 29 09:37:38.389713 2026] [:error] [pid 29913:tid 139879098873600] [client 172.68.130.154:13723] [client 172.68.130.154] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammtwgVDiGi-ktKYT-LmVQAAAMI"]
[Wed Jul 29 09:40:23.071112 2026] [:error] [pid 29913:tid 139879031731968] [client 104.23.243.19:9618] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ammuZwVDiGi-ktKYT-LobQAAAMo"]
[Wed Jul 29 09:40:23.072072 2026] [:error] [pid 29913:tid 139879031731968] [client 104.23.243.19:9618] [client 104.23.243.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ammuZwVDiGi-ktKYT-LobQAAAMo"]
[Wed Jul 29 09:40:23.072569 2026] [:error] [pid 29913:tid 139879031731968] [client 104.23.243.19:9618] [client 104.23.243.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ammuZwVDiGi-ktKYT-LobQAAAMo"]
[Wed Jul 29 09:40:29.635672 2026] [:error] [pid 12781:tid 139878956197632] [client 205.210.31.44:65222] [client 205.210.31.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammubWwejwALtycjqdrz7gAAAZM"]
[Wed Jul 29 09:40:29.636621 2026] [:error] [pid 12781:tid 139878956197632] [client 205.210.31.44:65222] [client 205.210.31.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammubWwejwALtycjqdrz7gAAAZM"]
[Wed Jul 29 09:40:29.636926 2026] [:error] [pid 12781:tid 139878956197632] [client 205.210.31.44:65222] [client 205.210.31.44] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammubWwejwALtycjqdrz7gAAAZM"]
[Wed Jul 29 10:00:07.447921 2026] [:error] [pid 12728:tid 139879073695488] [client 104.23.172.124:13349] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammzBzqdFZ1TNKvQdY2ZWwAAAUU"]
[Wed Jul 29 10:00:07.448972 2026] [:error] [pid 12728:tid 139879073695488] [client 104.23.172.124:13349] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammzBzqdFZ1TNKvQdY2ZWwAAAUU"]
[Wed Jul 29 10:00:07.449487 2026] [:error] [pid 12728:tid 139879073695488] [client 104.23.172.124:13349] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "ammzBzqdFZ1TNKvQdY2ZWwAAAUU"]
[Wed Jul 29 10:00:14.593567 2026] [:error] [pid 29816:tid 139878947804928] [client 172.71.183.39:12476] [client 172.71.183.39] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ammzDriIh7LJBqOi9Dy5GwAAABQ"]
[Wed Jul 29 10:00:14.594189 2026] [:error] [pid 29816:tid 139878947804928] [client 172.71.183.39:12476] [client 172.71.183.39] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ammzDriIh7LJBqOi9Dy5GwAAABQ"]
[Wed Jul 29 10:00:14.594701 2026] [:error] [pid 29816:tid 139878947804928] [client 172.71.183.39:12476] [client 172.71.183.39] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "ammzDriIh7LJBqOi9Dy5GwAAABQ"]
[Wed Jul 29 10:00:16.763106 2026] [:error] [pid 12782:tid 139878998161152] [client 162.159.113.45:14237] [client 162.159.113.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/application_default_credentials.json"] [unique_id "ammzEEFdlBZRl6Abom265gAAAc4"]
[Wed Jul 29 10:00:16.764019 2026] [:error] [pid 12782:tid 139878998161152] [client 162.159.113.45:14237] [client 162.159.113.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/application_default_credentials.json"] [unique_id "ammzEEFdlBZRl6Abom265gAAAc4"]
[Wed Jul 29 10:00:16.764340 2026] [:error] [pid 12782:tid 139878998161152] [client 162.159.113.45:14237] [client 162.159.113.45] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/application_default_credentials.json"] [unique_id "ammzEEFdlBZRl6Abom265gAAAc4"]
[Wed Jul 29 10:00:16.764419 2026] [:error] [pid 12782:tid 139878998161152] [client 162.159.113.45:14237] [client 162.159.113.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/application_default_credentials.json"] [unique_id "ammzEEFdlBZRl6Abom265gAAAc4"]
[Wed Jul 29 10:00:18.674826 2026] [:error] [pid 32190:tid 139878998161152] [client 104.23.172.125:10682] [client 104.23.172.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/account.json"] [unique_id "ammzEqGf2ExAGdIXvjOztQAAAQ4"]
[Wed Jul 29 10:00:18.675743 2026] [:error] [pid 32190:tid 139878998161152] [client 104.23.172.125:10682] [client 104.23.172.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/account.json"] [unique_id "ammzEqGf2ExAGdIXvjOztQAAAQ4"]
[Wed Jul 29 10:00:18.676205 2026] [:error] [pid 32190:tid 139878998161152] [client 104.23.172.125:10682] [client 104.23.172.125] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/account.json"] [unique_id "ammzEqGf2ExAGdIXvjOztQAAAQ4"]
[Wed Jul 29 10:00:18.676312 2026] [:error] [pid 32190:tid 139878998161152] [client 104.23.172.125:10682] [client 104.23.172.125] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/account.json"] [unique_id "ammzEqGf2ExAGdIXvjOztQAAAQ4"]
[Wed Jul 29 10:00:18.867213 2026] [:error] [pid 29913:tid 139878947804928] [client 104.23.168.5:12511] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.config/gcloud/application_default_credentials.json"] [unique_id "ammzEgVDiGi-ktKYT-L68QAAANQ"]
[Wed Jul 29 10:00:18.867283 2026] [:error] [pid 29913:tid 139879031731968] [client 104.23.166.83:9615] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/google.json"] [unique_id "ammzEgVDiGi-ktKYT-L68gAAAMo"]
[Wed Jul 29 10:00:18.867602 2026] [:error] [pid 29913:tid 139878947804928] [client 104.23.168.5:12511] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.config/gcloud/application_default_credentials.json"] [unique_id "ammzEgVDiGi-ktKYT-L68QAAANQ"]
[Wed Jul 29 10:00:18.867854 2026] [:error] [pid 29913:tid 139878947804928] [client 104.23.168.5:12511] [client 104.23.168.5] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.config/gcloud/application_default_credentials.json"] [unique_id "ammzEgVDiGi-ktKYT-L68QAAANQ"]
[Wed Jul 29 10:00:18.867870 2026] [:error] [pid 29913:tid 139879031731968] [client 104.23.166.83:9615] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/google.json"] [unique_id "ammzEgVDiGi-ktKYT-L68gAAAMo"]
[Wed Jul 29 10:00:18.867915 2026] [:error] [pid 29913:tid 139878947804928] [client 104.23.168.5:12511] [client 104.23.168.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.config/gcloud/application_default_credentials.json"] [unique_id "ammzEgVDiGi-ktKYT-L68QAAANQ"]
[Wed Jul 29 10:00:18.868268 2026] [:error] [pid 29913:tid 139879031731968] [client 104.23.166.83:9615] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/google.json"] [unique_id "ammzEgVDiGi-ktKYT-L68gAAAMo"]
[Wed Jul 29 10:00:19.135051 2026] [:error] [pid 29913:tid 139879023339264] [client 162.159.113.90:11444] [client 162.159.113.90] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gcloud.json"] [unique_id "ammzEwVDiGi-ktKYT-L69AAAAMs"]
[Wed Jul 29 10:00:19.136284 2026] [:error] [pid 29913:tid 139879023339264] [client 162.159.113.90:11444] [client 162.159.113.90] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gcloud.json"] [unique_id "ammzEwVDiGi-ktKYT-L69AAAAMs"]
[Wed Jul 29 10:00:19.136921 2026] [:error] [pid 29913:tid 139879023339264] [client 162.159.113.90:11444] [client 162.159.113.90] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gcloud.json"] [unique_id "ammzEwVDiGi-ktKYT-L69AAAAMs"]
[Wed Jul 29 10:00:21.336602 2026] [:error] [pid 29913:tid 139879185397504] [client 104.23.166.130:10167] [client 104.23.166.130] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ammzFQVDiGi-ktKYT-L6_gAAAMA"]
[Wed Jul 29 10:00:21.337737 2026] [:error] [pid 29913:tid 139879185397504] [client 104.23.166.130:10167] [client 104.23.166.130] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ammzFQVDiGi-ktKYT-L6_gAAAMA"]
[Wed Jul 29 10:00:21.338514 2026] [:error] [pid 29913:tid 139879185397504] [client 104.23.166.130:10167] [client 104.23.166.130] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "ammzFQVDiGi-ktKYT-L6_gAAAMA"]
[Wed Jul 29 10:00:21.344461 2026] [:error] [pid 12782:tid 139878989768448] [client 104.23.168.14:9462] [client 104.23.168.14] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bigquery-credentials.json"] [unique_id "ammzFUFdlBZRl6Abom266wAAAc8"]
[Wed Jul 29 10:00:21.345152 2026] [:error] [pid 12782:tid 139878989768448] [client 104.23.168.14:9462] [client 104.23.168.14] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bigquery-credentials.json"] [unique_id "ammzFUFdlBZRl6Abom266wAAAc8"]
[Wed Jul 29 10:00:21.345535 2026] [:error] [pid 12782:tid 139878989768448] [client 104.23.168.14:9462] [client 104.23.168.14] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bigquery-credentials.json"] [unique_id "ammzFUFdlBZRl6Abom266wAAAc8"]
[Wed Jul 29 10:00:23.890864 2026] [:error] [pid 29913:tid 139878922626816] [client 104.23.172.124:12184] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/debug/pprof/cmdline"] [unique_id "ammzFwVDiGi-ktKYT-L7CAAAANc"]
[Wed Jul 29 10:00:23.891881 2026] [:error] [pid 29913:tid 139878922626816] [client 104.23.172.124:12184] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/debug/pprof/cmdline"] [unique_id "ammzFwVDiGi-ktKYT-L7CAAAANc"]
[Wed Jul 29 10:00:23.892426 2026] [:error] [pid 29913:tid 139878922626816] [client 104.23.172.124:12184] [client 104.23.172.124] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/debug/pprof/cmdline"] [unique_id "ammzFwVDiGi-ktKYT-L7CAAAANc"]
[Wed Jul 29 10:00:23.892581 2026] [:error] [pid 29913:tid 139878922626816] [client 104.23.172.124:12184] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/debug/pprof/cmdline"] [unique_id "ammzFwVDiGi-ktKYT-L7CAAAANc"]
[Wed Jul 29 10:00:27.234733 2026] [:error] [pid 12781:tid 139878998161152] [client 162.159.113.44:13970] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/secrets/gcp-sa.json"] [unique_id "ammzG2wejwALtycjqdr7xAAAAY4"]
[Wed Jul 29 10:00:27.235835 2026] [:error] [pid 12781:tid 139878998161152] [client 162.159.113.44:13970] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/secrets/gcp-sa.json"] [unique_id "ammzG2wejwALtycjqdr7xAAAAY4"]
[Wed Jul 29 10:00:27.236518 2026] [:error] [pid 12781:tid 139878998161152] [client 162.159.113.44:13970] [client 162.159.113.44] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/secrets/gcp-sa.json"] [unique_id "ammzG2wejwALtycjqdr7xAAAAY4"]
[Wed Jul 29 10:00:27.236704 2026] [:error] [pid 12781:tid 139878998161152] [client 162.159.113.44:13970] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets/gcp-sa.json"] [unique_id "ammzG2wejwALtycjqdr7xAAAAY4"]
[Wed Jul 29 10:00:27.754770 2026] [:error] [pid 29913:tid 139879098873600] [client 104.23.172.124:12184] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/var/secrets/google/key.json"] [unique_id "ammzGwVDiGi-ktKYT-L7GAAAAMI"]
[Wed Jul 29 10:00:27.755627 2026] [:error] [pid 29913:tid 139879098873600] [client 104.23.172.124:12184] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/var/secrets/google/key.json"] [unique_id "ammzGwVDiGi-ktKYT-L7GAAAAMI"]
[Wed Jul 29 10:00:27.756037 2026] [:error] [pid 29913:tid 139879098873600] [client 104.23.172.124:12184] [client 104.23.172.124] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/var/secrets/google/key.json"] [unique_id "ammzGwVDiGi-ktKYT-L7GAAAAMI"]
[Wed Jul 29 10:00:27.756144 2026] [:error] [pid 29913:tid 139879098873600] [client 104.23.172.124:12184] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/var/secrets/google/key.json"] [unique_id "ammzGwVDiGi-ktKYT-L7GAAAAMI"]
[Wed Jul 29 10:00:27.759040 2026] [:error] [pid 12781:tid 139879177004800] [client 104.23.168.5:14083] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/etc/secrets/gcp-key.json"] [unique_id "ammzG2wejwALtycjqdr7xQAAAYE"]
[Wed Jul 29 10:00:27.759879 2026] [:error] [pid 12781:tid 139879177004800] [client 104.23.168.5:14083] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/etc/secrets/gcp-key.json"] [unique_id "ammzG2wejwALtycjqdr7xQAAAYE"]
[Wed Jul 29 10:00:27.760337 2026] [:error] [pid 12781:tid 139879177004800] [client 104.23.168.5:14083] [client 104.23.168.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/etc/secrets/gcp-key.json"] [unique_id "ammzG2wejwALtycjqdr7xQAAAYE"]
[Wed Jul 29 10:00:27.766040 2026] [:error] [pid 12781:tid 139879031731968] [client 104.23.166.131:11159] [client 104.23.166.131] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/secrets/firebase-adminsdk.json"] [unique_id "ammzG2wejwALtycjqdr7xgAAAYo"]
[Wed Jul 29 10:00:27.766820 2026] [:error] [pid 12781:tid 139879031731968] [client 104.23.166.131:11159] [client 104.23.166.131] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/secrets/firebase-adminsdk.json"] [unique_id "ammzG2wejwALtycjqdr7xgAAAYo"]
[Wed Jul 29 10:00:27.767296 2026] [:error] [pid 12781:tid 139879031731968] [client 104.23.166.131:11159] [client 104.23.166.131] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets/firebase-adminsdk.json"] [unique_id "ammzG2wejwALtycjqdr7xgAAAYo"]
[Wed Jul 29 10:00:27.845729 2026] [:error] [pid 12781:tid 139878914234112] [client 172.71.103.42:11344] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/server/credentials.json"] [unique_id "ammzG2wejwALtycjqdr7xwAAAZg"]
[Wed Jul 29 10:00:27.846529 2026] [:error] [pid 12781:tid 139878914234112] [client 172.71.103.42:11344] [client 172.71.103.42] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/server/credentials.json"] [unique_id "ammzG2wejwALtycjqdr7xwAAAZg"]
[Wed Jul 29 10:00:27.847051 2026] [:error] [pid 12781:tid 139878914234112] [client 172.71.103.42:11344] [client 172.71.103.42] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/server/credentials.json"] [unique_id "ammzG2wejwALtycjqdr7xwAAAZg"]
[Wed Jul 29 10:00:27.847162 2026] [:error] [pid 12781:tid 139878914234112] [client 172.71.103.42:11344] [client 172.71.103.42] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/server/credentials.json"] [unique_id "ammzG2wejwALtycjqdr7xwAAAZg"]
[Wed Jul 29 10:00:27.954427 2026] [:error] [pid 12728:tid 139878914234112] [client 104.23.170.162:10073] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gcs-credentials.json"] [unique_id "ammzGzqdFZ1TNKvQdY2ZeAAAAVg"]
[Wed Jul 29 10:00:27.955328 2026] [:error] [pid 12728:tid 139878914234112] [client 104.23.170.162:10073] [client 104.23.170.162] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gcs-credentials.json"] [unique_id "ammzGzqdFZ1TNKvQdY2ZeAAAAVg"]
[Wed Jul 29 10:00:27.955783 2026] [:error] [pid 12728:tid 139878914234112] [client 104.23.170.162:10073] [client 104.23.170.162] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/gcs-credentials.json"] [unique_id "ammzGzqdFZ1TNKvQdY2ZeAAAAVg"]
[Wed Jul 29 10:00:27.955967 2026] [:error] [pid 12728:tid 139878914234112] [client 104.23.170.162:10073] [client 104.23.170.162] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gcs-credentials.json"] [unique_id "ammzGzqdFZ1TNKvQdY2ZeAAAAVg"]
[Wed Jul 29 10:00:29.539819 2026] [:error] [pid 12781:tid 139879023339264] [client 162.159.113.44:13970] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/backend/credentials.json"] [unique_id "ammzHWwejwALtycjqdr7zgAAAYs"]
[Wed Jul 29 10:00:29.540763 2026] [:error] [pid 12781:tid 139879023339264] [client 162.159.113.44:13970] [client 162.159.113.44] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/backend/credentials.json"] [unique_id "ammzHWwejwALtycjqdr7zgAAAYs"]
[Wed Jul 29 10:00:29.541316 2026] [:error] [pid 12781:tid 139879023339264] [client 162.159.113.44:13970] [client 162.159.113.44] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/backend/credentials.json"] [unique_id "ammzHWwejwALtycjqdr7zgAAAYs"]
[Wed Jul 29 10:00:29.541591 2026] [:error] [pid 12781:tid 139879023339264] [client 162.159.113.44:13970] [client 162.159.113.44] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/backend/credentials.json"] [unique_id "ammzHWwejwALtycjqdr7zgAAAYs"]
[Wed Jul 29 10:00:32.055916 2026] [:error] [pid 29818:tid 139878914234112] [client 162.159.113.90:12588] [client 162.159.113.90] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sa-key.json"] [unique_id "ammzIMNm_eEjUiZv2_jVLAAAAJg"]
[Wed Jul 29 10:00:32.154570 2026] [:error] [pid 29818:tid 139878914234112] [client 162.159.113.90:12588] [client 162.159.113.90] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sa-key.json"] [unique_id "ammzIMNm_eEjUiZv2_jVLAAAAJg"]
[Wed Jul 29 10:00:32.155043 2026] [:error] [pid 29818:tid 139878914234112] [client 162.159.113.90:12588] [client 162.159.113.90] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sa-key.json"] [unique_id "ammzIMNm_eEjUiZv2_jVLAAAAJg"]
[Wed Jul 29 10:00:32.155156 2026] [:error] [pid 29818:tid 139878914234112] [client 162.159.113.90:12588] [client 162.159.113.90] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sa-key.json"] [unique_id "ammzIMNm_eEjUiZv2_jVLAAAAJg"]
[Wed Jul 29 10:00:32.467968 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.170.125:10806] [client 104.23.170.125] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.gcp/credentials.json"] [unique_id "ammzIKGf2ExAGdIXvjO0KAAAAQ8"]
[Wed Jul 29 10:00:32.469136 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.170.125:10806] [client 104.23.170.125] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.gcp/credentials.json"] [unique_id "ammzIKGf2ExAGdIXvjO0KAAAAQ8"]
[Wed Jul 29 10:00:32.469750 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.170.125:10806] [client 104.23.170.125] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.gcp/credentials.json"] [unique_id "ammzIKGf2ExAGdIXvjO0KAAAAQ8"]
[Wed Jul 29 10:00:32.478820 2026] [:error] [pid 12781:tid 139878922626816] [client 104.23.168.5:14083] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/google-sa.json"] [unique_id "ammzIGwejwALtycjqdr71AAAAZc"]
[Wed Jul 29 10:00:32.479498 2026] [:error] [pid 12781:tid 139878922626816] [client 104.23.168.5:14083] [client 104.23.168.5] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/google-sa.json"] [unique_id "ammzIGwejwALtycjqdr71AAAAZc"]
[Wed Jul 29 10:00:32.479914 2026] [:error] [pid 12781:tid 139878922626816] [client 104.23.168.5:14083] [client 104.23.168.5] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/google-sa.json"] [unique_id "ammzIGwejwALtycjqdr71AAAAZc"]
[Wed Jul 29 10:00:32.480015 2026] [:error] [pid 12781:tid 139878922626816] [client 104.23.168.5:14083] [client 104.23.168.5] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/google-sa.json"] [unique_id "ammzIGwejwALtycjqdr71AAAAZc"]
[Wed Jul 29 10:00:32.487658 2026] [:error] [pid 29816:tid 139879090480896] [client 172.71.102.115:13184] [client 172.71.102.115] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gcp/key.json"] [unique_id "ammzILiIh7LJBqOi9Dy5LgAAAAM"]
[Wed Jul 29 10:00:32.488321 2026] [:error] [pid 29816:tid 139879090480896] [client 172.71.102.115:13184] [client 172.71.102.115] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gcp/key.json"] [unique_id "ammzILiIh7LJBqOi9Dy5LgAAAAM"]
[Wed Jul 29 10:00:32.488795 2026] [:error] [pid 29816:tid 139879090480896] [client 172.71.102.115:13184] [client 172.71.102.115] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gcp/key.json"] [unique_id "ammzILiIh7LJBqOi9Dy5LgAAAAM"]
[Wed Jul 29 10:00:34.748266 2026] [:error] [pid 32190:tid 139879090480896] [client 104.23.166.83:10741] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "ammzIqGf2ExAGdIXvjO0LQAAAQM"]
[Wed Jul 29 10:00:34.749277 2026] [:error] [pid 32190:tid 139879090480896] [client 104.23.166.83:10741] [client 104.23.166.83] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "ammzIqGf2ExAGdIXvjO0LQAAAQM"]
[Wed Jul 29 10:00:34.749841 2026] [:error] [pid 32190:tid 139879090480896] [client 104.23.166.83:10741] [client 104.23.166.83] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/secrets.json"] [unique_id "ammzIqGf2ExAGdIXvjO0LQAAAQM"]
[Wed Jul 29 10:00:34.782512 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.172.124:12098] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "ammzIqGf2ExAGdIXvjO0LgAAAQ0"]
[Wed Jul 29 10:00:34.783419 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.172.124:12098] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "ammzIqGf2ExAGdIXvjO0LgAAAQ0"]
[Wed Jul 29 10:00:34.783803 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.172.124:12098] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "ammzIqGf2ExAGdIXvjO0LgAAAQ0"]
[Wed Jul 29 10:00:34.783966 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.172.124:12098] [client 104.23.172.124] ModSecurity: Warning. Matched phrase ".aws/credentials" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/credentials found within REQUEST_FILENAME: /.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.aws/credentials"] [unique_id "ammzIqGf2ExAGdIXvjO0LgAAAQ0"]
[Wed Jul 29 10:00:34.871731 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.172.124:12098] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "ammzIqGf2ExAGdIXvjO0LwAAAQU"]
[Wed Jul 29 10:00:34.872643 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.172.124:12098] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "ammzIqGf2ExAGdIXvjO0LwAAAQU"]
[Wed Jul 29 10:00:34.873081 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.172.124:12098] [client 104.23.172.124] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "ammzIqGf2ExAGdIXvjO0LwAAAQU"]
[Wed Jul 29 10:00:34.873189 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.172.124:12098] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "ammzIqGf2ExAGdIXvjO0LwAAAQU"]
[Wed Jul 29 10:00:34.873453 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.172.124:12098] [client 104.23.172.124] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "sbf-consultancy.com"] [uri "/.git/config"] [unique_id "ammzIqGf2ExAGdIXvjO0LwAAAQU"]
[Wed Jul 29 10:00:37.557629 2026] [:error] [pid 29913:tid 139878956197632] [client 172.71.183.35:13715] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/loadable-stats.json"] [unique_id "ammzJQVDiGi-ktKYT-L7RgAAANM"]
[Wed Jul 29 10:00:37.558632 2026] [:error] [pid 29913:tid 139878956197632] [client 172.71.183.35:13715] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/loadable-stats.json"] [unique_id "ammzJQVDiGi-ktKYT-L7RgAAANM"]
[Wed Jul 29 10:00:37.559215 2026] [:error] [pid 29913:tid 139878956197632] [client 172.71.183.35:13715] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/loadable-stats.json"] [unique_id "ammzJQVDiGi-ktKYT-L7RgAAANM"]
[Wed Jul 29 10:00:38.546629 2026] [:error] [pid 29913:tid 139879177004800] [client 172.71.98.106:10366] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/asset-manifest.json"] [unique_id "ammzJgVDiGi-ktKYT-L7SwAAAME"]
[Wed Jul 29 10:00:38.745067 2026] [:error] [pid 29913:tid 139879177004800] [client 172.71.98.106:10366] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/asset-manifest.json"] [unique_id "ammzJgVDiGi-ktKYT-L7SwAAAME"]
[Wed Jul 29 10:00:38.746086 2026] [:error] [pid 29913:tid 139879177004800] [client 172.71.98.106:10366] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/asset-manifest.json"] [unique_id "ammzJgVDiGi-ktKYT-L7SwAAAME"]
[Wed Jul 29 10:00:40.234528 2026] [:error] [pid 12728:tid 139879082088192] [client 172.71.182.51:11968] [client 172.71.182.51] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/manifest.json"] [unique_id "ammzKDqdFZ1TNKvQdY2ZjAAAAUQ"]
[Wed Jul 29 10:00:40.235504 2026] [:error] [pid 12728:tid 139879082088192] [client 172.71.182.51:11968] [client 172.71.182.51] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/manifest.json"] [unique_id "ammzKDqdFZ1TNKvQdY2ZjAAAAUQ"]
[Wed Jul 29 10:00:40.236149 2026] [:error] [pid 12728:tid 139879082088192] [client 172.71.182.51:11968] [client 172.71.182.51] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/manifest.json"] [unique_id "ammzKDqdFZ1TNKvQdY2ZjAAAAUQ"]
[Wed Jul 29 10:00:41.144686 2026] [:error] [pid 12728:tid 139879098873600] [client 104.23.172.124:12853] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "ammzKTqdFZ1TNKvQdY2ZjQAAAUI"]
[Wed Jul 29 10:00:41.145490 2026] [:error] [pid 12728:tid 139879098873600] [client 104.23.172.124:12853] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "ammzKTqdFZ1TNKvQdY2ZjQAAAUI"]
[Wed Jul 29 10:00:41.145882 2026] [:error] [pid 12728:tid 139879098873600] [client 104.23.172.124:12853] [client 104.23.172.124] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "ammzKTqdFZ1TNKvQdY2ZjQAAAUI"]
[Wed Jul 29 10:00:41.145977 2026] [:error] [pid 12728:tid 139879098873600] [client 104.23.172.124:12853] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.json"] [unique_id "ammzKTqdFZ1TNKvQdY2ZjQAAAUI"]
[Wed Jul 29 10:00:41.165502 2026] [:error] [pid 29818:tid 139878972983040] [client 172.71.99.206:9570] [client 172.71.99.206] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/v1/graphql"] [unique_id "ammzKcNm_eEjUiZv2_jVNAAAAJE"]
[Wed Jul 29 10:00:41.166445 2026] [:error] [pid 29818:tid 139878972983040] [client 172.71.99.206:9570] [client 172.71.99.206] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/v1/graphql"] [unique_id "ammzKcNm_eEjUiZv2_jVNAAAAJE"]
[Wed Jul 29 10:00:41.167044 2026] [:error] [pid 29818:tid 139878972983040] [client 172.71.99.206:9570] [client 172.71.99.206] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/v1/graphql"] [unique_id "ammzKcNm_eEjUiZv2_jVNAAAAJE"]
[Wed Jul 29 10:00:42.582512 2026] [:error] [pid 12782:tid 139879048517376] [client 172.71.99.40:12530] [client 172.71.99.40] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "ammzKkFdlBZRl6Abom27AQAAAcg"]
[Wed Jul 29 10:00:42.583197 2026] [:error] [pid 12782:tid 139879048517376] [client 172.71.99.40:12530] [client 172.71.99.40] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "ammzKkFdlBZRl6Abom27AQAAAcg"]
[Wed Jul 29 10:00:42.583488 2026] [:error] [pid 12782:tid 139879048517376] [client 172.71.99.40:12530] [client 172.71.99.40] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "ammzKkFdlBZRl6Abom27AQAAAcg"]
[Wed Jul 29 10:00:42.583561 2026] [:error] [pid 12782:tid 139879048517376] [client 172.71.99.40:12530] [client 172.71.99.40] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/config.js"] [unique_id "ammzKkFdlBZRl6Abom27AQAAAcg"]
[Wed Jul 29 10:00:44.190780 2026] [:error] [pid 29913:tid 139879185397504] [client 172.71.95.21:9650] [client 172.71.95.21] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/__/firebase/init.json"] [unique_id "ammzLAVDiGi-ktKYT-L7YQAAAMA"]
[Wed Jul 29 10:00:44.191646 2026] [:error] [pid 29913:tid 139879185397504] [client 172.71.95.21:9650] [client 172.71.95.21] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/__/firebase/init.json"] [unique_id "ammzLAVDiGi-ktKYT-L7YQAAAMA"]
[Wed Jul 29 10:00:44.192086 2026] [:error] [pid 29913:tid 139879185397504] [client 172.71.95.21:9650] [client 172.71.95.21] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/__/firebase/init.json"] [unique_id "ammzLAVDiGi-ktKYT-L7YQAAAMA"]
[Wed Jul 29 10:00:44.192195 2026] [:error] [pid 29913:tid 139879185397504] [client 172.71.95.21:9650] [client 172.71.95.21] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/__/firebase/init.json"] [unique_id "ammzLAVDiGi-ktKYT-L7YQAAAMA"]
[Wed Jul 29 10:00:46.089446 2026] [:error] [pid 29818:tid 139879098873600] [client 172.71.98.107:9401] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v1/settings"] [unique_id "ammzLsNm_eEjUiZv2_jVPwAAAII"]
[Wed Jul 29 10:00:46.090141 2026] [:error] [pid 29818:tid 139879098873600] [client 172.71.98.107:9401] [client 172.71.98.107] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v1/settings"] [unique_id "ammzLsNm_eEjUiZv2_jVPwAAAII"]
[Wed Jul 29 10:00:46.090544 2026] [:error] [pid 29818:tid 139879098873600] [client 172.71.98.107:9401] [client 172.71.98.107] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v1/settings"] [unique_id "ammzLsNm_eEjUiZv2_jVPwAAAII"]
[Wed Jul 29 10:00:46.553773 2026] [:error] [pid 29913:tid 139878947804928] [client 172.71.182.50:12955] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "ammzLgVDiGi-ktKYT-L7bwAAANQ"]
[Wed Jul 29 10:00:46.554828 2026] [:error] [pid 29913:tid 139878947804928] [client 172.71.182.50:12955] [client 172.71.182.50] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "ammzLgVDiGi-ktKYT-L7bwAAANQ"]
[Wed Jul 29 10:00:46.555267 2026] [:error] [pid 29913:tid 139878947804928] [client 172.71.182.50:12955] [client 172.71.182.50] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "ammzLgVDiGi-ktKYT-L7bwAAANQ"]
[Wed Jul 29 10:00:46.555386 2026] [:error] [pid 29913:tid 139878947804928] [client 172.71.182.50:12955] [client 172.71.182.50] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/settings.json"] [unique_id "ammzLgVDiGi-ktKYT-L7bwAAANQ"]
[Wed Jul 29 10:00:46.645761 2026] [:error] [pid 29913:tid 139878981375744] [client 172.71.95.21:9650] [client 172.71.95.21] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/settings"] [unique_id "ammzLgVDiGi-ktKYT-L7cAAAANA"]
[Wed Jul 29 10:00:46.648170 2026] [:error] [pid 29913:tid 139878981375744] [client 172.71.95.21:9650] [client 172.71.95.21] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/settings"] [unique_id "ammzLgVDiGi-ktKYT-L7cAAAANA"]
[Wed Jul 29 10:00:46.648772 2026] [:error] [pid 29913:tid 139878981375744] [client 172.71.95.21:9650] [client 172.71.95.21] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/settings"] [unique_id "ammzLgVDiGi-ktKYT-L7cAAAANA"]
[Wed Jul 29 10:00:46.659168 2026] [:error] [pid 29818:tid 139879185397504] [client 104.23.172.124:12854] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "ammzLsNm_eEjUiZv2_jVQgAAAIA"]
[Wed Jul 29 10:00:46.660199 2026] [:error] [pid 29818:tid 139879185397504] [client 104.23.172.124:12854] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "ammzLsNm_eEjUiZv2_jVQgAAAIA"]
[Wed Jul 29 10:00:46.660753 2026] [:error] [pid 29818:tid 139879185397504] [client 104.23.172.124:12854] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/config"] [unique_id "ammzLsNm_eEjUiZv2_jVQgAAAIA"]
[Wed Jul 29 10:00:49.686540 2026] [:error] [pid 12782:tid 139878998161152] [client 172.71.95.147:9425] [client 172.71.95.147] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env.js"] [unique_id "ammzMUFdlBZRl6Abom27FQAAAc4"]
[Wed Jul 29 10:00:49.687436 2026] [:error] [pid 12782:tid 139878998161152] [client 172.71.95.147:9425] [client 172.71.95.147] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env.js"] [unique_id "ammzMUFdlBZRl6Abom27FQAAAc4"]
[Wed Jul 29 10:00:49.687961 2026] [:error] [pid 12782:tid 139878998161152] [client 172.71.95.147:9425] [client 172.71.95.147] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/env.js"] [unique_id "ammzMUFdlBZRl6Abom27FQAAAc4"]
[Wed Jul 29 10:00:49.834102 2026] [:error] [pid 29818:tid 139878981375744] [client 104.23.172.124:12854] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/jwks.json"] [unique_id "ammzMcNm_eEjUiZv2_jVRwAAAJA"]
[Wed Jul 29 10:00:49.835007 2026] [:error] [pid 29818:tid 139878981375744] [client 104.23.172.124:12854] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/jwks.json"] [unique_id "ammzMcNm_eEjUiZv2_jVRwAAAJA"]
[Wed Jul 29 10:00:49.835510 2026] [:error] [pid 29818:tid 139878981375744] [client 104.23.172.124:12854] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/jwks.json"] [unique_id "ammzMcNm_eEjUiZv2_jVRwAAAJA"]
[Wed Jul 29 10:00:50.555394 2026] [:error] [pid 29816:tid 139878972983040] [client 172.71.183.35:12751] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/firebase-config.json"] [unique_id "ammzMriIh7LJBqOi9Dy5PAAAABE"]
[Wed Jul 29 10:00:50.556036 2026] [:error] [pid 29816:tid 139878972983040] [client 172.71.183.35:12751] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/firebase-config.json"] [unique_id "ammzMriIh7LJBqOi9Dy5PAAAABE"]
[Wed Jul 29 10:00:50.556377 2026] [:error] [pid 29816:tid 139878972983040] [client 172.71.183.35:12751] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/firebase-config.json"] [unique_id "ammzMriIh7LJBqOi9Dy5PAAAABE"]
[Wed Jul 29 10:00:50.955795 2026] [:error] [pid 12781:tid 139879185397504] [client 172.70.46.164:10632] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v2/config"] [unique_id "ammzMmwejwALtycjqdr76gAAAYA"]
[Wed Jul 29 10:00:50.956781 2026] [:error] [pid 12781:tid 139879185397504] [client 172.70.46.164:10632] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v2/config"] [unique_id "ammzMmwejwALtycjqdr76gAAAYA"]
[Wed Jul 29 10:00:50.957229 2026] [:error] [pid 12781:tid 139879185397504] [client 172.70.46.164:10632] [client 172.70.46.164] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/api/v2/config"] [unique_id "ammzMmwejwALtycjqdr76gAAAYA"]
[Wed Jul 29 10:00:50.957390 2026] [:error] [pid 12781:tid 139879185397504] [client 172.70.46.164:10632] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v2/config"] [unique_id "ammzMmwejwALtycjqdr76gAAAYA"]
[Wed Jul 29 10:00:51.194799 2026] [:error] [pid 12781:tid 139879098873600] [client 172.70.46.164:10632] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/env.json"] [unique_id "ammzM2wejwALtycjqdr76wAAAYI"]
[Wed Jul 29 10:00:51.195677 2026] [:error] [pid 12781:tid 139879098873600] [client 172.70.46.164:10632] [client 172.70.46.164] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/env.json"] [unique_id "ammzM2wejwALtycjqdr76wAAAYI"]
[Wed Jul 29 10:00:51.196028 2026] [:error] [pid 12781:tid 139879098873600] [client 172.70.46.164:10632] [client 172.70.46.164] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/env.json"] [unique_id "ammzM2wejwALtycjqdr76wAAAYI"]
[Wed Jul 29 10:00:51.196098 2026] [:error] [pid 12781:tid 139879098873600] [client 172.70.46.164:10632] [client 172.70.46.164] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/env.json"] [unique_id "ammzM2wejwALtycjqdr76wAAAYI"]
[Wed Jul 29 10:00:53.376323 2026] [:error] [pid 29816:tid 139879065302784] [client 172.71.183.35:12751] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/env"] [unique_id "ammzNbiIh7LJBqOi9Dy5PwAAAAY"]
[Wed Jul 29 10:00:53.376996 2026] [:error] [pid 29816:tid 139879065302784] [client 172.71.183.35:12751] [client 172.71.183.35] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/env"] [unique_id "ammzNbiIh7LJBqOi9Dy5PwAAAAY"]
[Wed Jul 29 10:00:53.377307 2026] [:error] [pid 29816:tid 139879065302784] [client 172.71.183.35:12751] [client 172.71.183.35] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/api/env"] [unique_id "ammzNbiIh7LJBqOi9Dy5PwAAAAY"]
[Wed Jul 29 10:00:53.377378 2026] [:error] [pid 29816:tid 139879065302784] [client 172.71.183.35:12751] [client 172.71.183.35] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/env"] [unique_id "ammzNbiIh7LJBqOi9Dy5PwAAAAY"]
[Wed Jul 29 10:00:53.664257 2026] [:error] [pid 29913:tid 139879006553856] [client 172.71.98.106:9502] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v1/config"] [unique_id "ammzNQVDiGi-ktKYT-L7hQAAAM0"]
[Wed Jul 29 10:00:53.665109 2026] [:error] [pid 29913:tid 139879006553856] [client 172.71.98.106:9502] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v1/config"] [unique_id "ammzNQVDiGi-ktKYT-L7hQAAAM0"]
[Wed Jul 29 10:00:53.665731 2026] [:error] [pid 29913:tid 139879006553856] [client 172.71.98.106:9502] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v1/config"] [unique_id "ammzNQVDiGi-ktKYT-L7hQAAAM0"]
[Wed Jul 29 10:00:54.268853 2026] [:error] [pid 29818:tid 139878964590336] [client 104.23.172.124:12854] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/api/v2/settings"] [unique_id "ammzNsNm_eEjUiZv2_jVTgAAAJI"]
[Wed Jul 29 10:00:54.269889 2026] [:error] [pid 29818:tid 139878964590336] [client 104.23.172.124:12854] [client 104.23.172.124] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/api/v2/settings"] [unique_id "ammzNsNm_eEjUiZv2_jVTgAAAJI"]
[Wed Jul 29 10:00:54.270431 2026] [:error] [pid 29818:tid 139878964590336] [client 104.23.172.124:12854] [client 104.23.172.124] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/api/v2/settings"] [unique_id "ammzNsNm_eEjUiZv2_jVTgAAAJI"]
[Wed Jul 29 10:00:57.956199 2026] [:error] [pid 29818:tid 139879006553856] [client 104.23.168.16:11511] [client 104.23.168.16] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/runtime-config.js"] [unique_id "ammzOcNm_eEjUiZv2_jVVgAAAI0"]
[Wed Jul 29 10:00:57.957181 2026] [:error] [pid 29818:tid 139879006553856] [client 104.23.168.16:11511] [client 104.23.168.16] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/runtime-config.js"] [unique_id "ammzOcNm_eEjUiZv2_jVVgAAAI0"]
[Wed Jul 29 10:00:57.957686 2026] [:error] [pid 29818:tid 139879006553856] [client 104.23.168.16:11511] [client 104.23.168.16] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920300"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/runtime-config.js"] [unique_id "ammzOcNm_eEjUiZv2_jVVgAAAI0"]
[Wed Jul 29 10:00:57.957815 2026] [:error] [pid 29818:tid 139879006553856] [client 104.23.168.16:11511] [client 104.23.168.16] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/runtime-config.js"] [unique_id "ammzOcNm_eEjUiZv2_jVVgAAAI0"]
[Wed Jul 29 10:32:20.953747 2026] [:error] [pid 32190:tid 139878931019520] [client 104.23.197.193:11868] [client 104.23.197.193] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amm6lKGf2ExAGdIXvjPBygAAARY"]
[Wed Jul 29 10:32:20.954911 2026] [:error] [pid 32190:tid 139878931019520] [client 104.23.197.193:11868] [client 104.23.197.193] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amm6lKGf2ExAGdIXvjPBygAAARY"]
[Wed Jul 29 10:32:20.955474 2026] [:error] [pid 32190:tid 139878931019520] [client 104.23.197.193:11868] [client 104.23.197.193] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amm6lKGf2ExAGdIXvjPBygAAARY"]
[Wed Jul 29 10:36:14.044634 2026] [:error] [pid 12728:tid 139879056910080] [client 172.68.189.187:13942] [client 172.68.189.187] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amm7fjqdFZ1TNKvQdY2uhgAAAUc"]
[Wed Jul 29 10:36:14.075871 2026] [:error] [pid 12728:tid 139879056910080] [client 172.68.189.187:13942] [client 172.68.189.187] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amm7fjqdFZ1TNKvQdY2uhgAAAUc"]
[Wed Jul 29 10:36:14.076651 2026] [:error] [pid 12728:tid 139879056910080] [client 172.68.189.187:13942] [client 172.68.189.187] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amm7fjqdFZ1TNKvQdY2uhgAAAUc"]
[Wed Jul 29 10:40:36.358893 2026] [:error] [pid 29816:tid 139878972983040] [client 104.22.93.88:13085] [client 104.22.93.88] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amm8hLiIh7LJBqOi9DzK3QAAABE"]
[Wed Jul 29 10:40:36.360032 2026] [:error] [pid 29816:tid 139878972983040] [client 104.22.93.88:13085] [client 104.22.93.88] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amm8hLiIh7LJBqOi9DzK3QAAABE"]
[Wed Jul 29 10:40:36.360688 2026] [:error] [pid 29816:tid 139878972983040] [client 104.22.93.88:13085] [client 104.22.93.88] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amm8hLiIh7LJBqOi9DzK3QAAABE"]
[Wed Jul 29 10:41:35.546820 2026] [:error] [pid 29913:tid 139879048517376] [client 104.22.100.89:13558] [client 104.22.100.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amm8vwVDiGi-ktKYT-IpawAAAMg"]
[Wed Jul 29 10:41:35.547847 2026] [:error] [pid 29913:tid 139879048517376] [client 104.22.100.89:13558] [client 104.22.100.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amm8vwVDiGi-ktKYT-IpawAAAMg"]
[Wed Jul 29 10:41:35.548450 2026] [:error] [pid 29913:tid 139879048517376] [client 104.22.100.89:13558] [client 104.22.100.89] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua=\\x22Not)A;Brand\\x22;v=\\x228\\x22, \\x22Chromium\\x22;v=\\x22138\\x22, \\x22HeadlessChrome\\x22;v=\\x22138\\x22"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amm8vwVDiGi-ktKYT-IpawAAAMg"]
[Wed Jul 29 10:41:35.548511 2026] [:error] [pid 29913:tid 139879048517376] [client 104.22.100.89:13558] [client 104.22.100.89] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:sec-ch-ua-mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:sec-ch-ua-mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amm8vwVDiGi-ktKYT-IpawAAAMg"]
[Wed Jul 29 10:41:35.548567 2026] [:error] [pid 29913:tid 139879048517376] [client 104.22.100.89:13558] [client 104.22.100.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amm8vwVDiGi-ktKYT-IpawAAAMg"]
[Wed Jul 29 10:42:29.789426 2026] [:error] [pid 29816:tid 139879031731968] [client 172.68.15.205:13463] [client 172.68.15.205] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amm89biIh7LJBqOi9DzLeQAAAAo"]
[Wed Jul 29 10:42:29.790386 2026] [:error] [pid 29816:tid 139879031731968] [client 172.68.15.205:13463] [client 172.68.15.205] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amm89biIh7LJBqOi9DzLeQAAAAo"]
[Wed Jul 29 10:42:29.790634 2026] [:error] [pid 29816:tid 139879031731968] [client 172.68.15.205:13463] [client 172.68.15.205] ModSecurity: Warning. Matched phrase "SemrushBot" at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "176"] [id "913102"] [msg "Found User-Agent associated with web crawler/bot"] [data "Matched Data: SemrushBot found within REQUEST_HEADERS:User-Agent: mozilla/5.0 (compatible; semrushbot/7~bl; +http://www.semrush.com/bot.html)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-crawler"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amm89biIh7LJBqOi9DzLeQAAAAo"]
[Wed Jul 29 10:42:29.791015 2026] [:error] [pid 29816:tid 139879031731968] [client 172.68.15.205:13463] [client 172.68.15.205] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amm89biIh7LJBqOi9DzLeQAAAAo"]
[Wed Jul 29 10:42:30.949334 2026] [:error] [pid 32190:tid 139878964590336] [client 104.22.100.89:13329] [client 104.22.100.89] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amm89qGf2ExAGdIXvjPIaQAAARI"]
[Wed Jul 29 10:42:30.950383 2026] [:error] [pid 32190:tid 139878964590336] [client 104.22.100.89:13329] [client 104.22.100.89] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amm89qGf2ExAGdIXvjPIaQAAARI"]
[Wed Jul 29 10:42:30.950606 2026] [:error] [pid 32190:tid 139878964590336] [client 104.22.100.89:13329] [client 104.22.100.89] ModSecurity: Warning. Matched phrase "SemrushBot" at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "176"] [id "913102"] [msg "Found User-Agent associated with web crawler/bot"] [data "Matched Data: SemrushBot found within REQUEST_HEADERS:User-Agent: mozilla/5.0 (compatible; semrushbot/7~bl; +http://www.semrush.com/bot.html)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-crawler"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amm89qGf2ExAGdIXvjPIaQAAARI"]
[Wed Jul 29 10:42:30.951053 2026] [:error] [pid 32190:tid 139878964590336] [client 104.22.100.89:13329] [client 104.22.100.89] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amm89qGf2ExAGdIXvjPIaQAAARI"]
[Wed Jul 29 10:42:37.284281 2026] [:error] [pid 12781:tid 139879056910080] [client 172.70.38.128:12400] [client 172.70.38.128] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amm8_WwejwALtycjqdoJ7wAAAYc"]
[Wed Jul 29 10:42:37.284964 2026] [:error] [pid 12781:tid 139879056910080] [client 172.70.38.128:12400] [client 172.70.38.128] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amm8_WwejwALtycjqdoJ7wAAAYc"]
[Wed Jul 29 10:42:37.285102 2026] [:error] [pid 12781:tid 139879056910080] [client 172.70.38.128:12400] [client 172.70.38.128] ModSecurity: Warning. Matched phrase "SemrushBot" at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "176"] [id "913102"] [msg "Found User-Agent associated with web crawler/bot"] [data "Matched Data: SemrushBot found within REQUEST_HEADERS:User-Agent: mozilla/5.0 (compatible; semrushbot/7~bl; +http://www.semrush.com/bot.html)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-crawler"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amm8_WwejwALtycjqdoJ7wAAAYc"]
[Wed Jul 29 10:42:37.285382 2026] [:error] [pid 12781:tid 139879056910080] [client 172.70.38.128:12400] [client 172.70.38.128] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amm8_WwejwALtycjqdoJ7wAAAYc"]
[Wed Jul 29 10:50:58.696230 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amm-8gVDiGi-ktKYT-I0HAAAANY"]
[Wed Jul 29 10:50:58.861331 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amm-8gVDiGi-ktKYT-I0HAAAANY"]
[Wed Jul 29 10:50:58.861698 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amm-8gVDiGi-ktKYT-I0HAAAANY"]
[Wed Jul 29 10:50:58.861760 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amm-8gVDiGi-ktKYT-I0HAAAANY"]
[Wed Jul 29 10:51:00.161998 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amm-9AVDiGi-ktKYT-I0KgAAAMw"]
[Wed Jul 29 10:51:00.163114 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amm-9AVDiGi-ktKYT-I0KgAAAMw"]
[Wed Jul 29 10:51:00.163588 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amm-9AVDiGi-ktKYT-I0KgAAAMw"]
[Wed Jul 29 10:51:00.163692 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amm-9AVDiGi-ktKYT-I0KgAAAMw"]
[Wed Jul 29 10:51:01.261814 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/nothing2.php"] [unique_id "amm-9YpuIafV02klyJIyqAAAAFE"]
[Wed Jul 29 10:51:01.262396 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/nothing2.php"] [unique_id "amm-9YpuIafV02klyJIyqAAAAFE"]
[Wed Jul 29 10:51:01.262728 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/nothing2.php"] [unique_id "amm-9YpuIafV02klyJIyqAAAAFE"]
[Wed Jul 29 10:51:01.262797 2026] [:error] [pid 29817:tid 139878972983040] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/nothing2.php"] [unique_id "amm-9YpuIafV02klyJIyqAAAAFE"]
[Wed Jul 29 10:51:01.569416 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wkl.php"] [unique_id "amm-9QVDiGi-ktKYT-I0NwAAAME"]
[Wed Jul 29 10:51:01.570435 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wkl.php"] [unique_id "amm-9QVDiGi-ktKYT-I0NwAAAME"]
[Wed Jul 29 10:51:01.570853 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wkl.php"] [unique_id "amm-9QVDiGi-ktKYT-I0NwAAAME"]
[Wed Jul 29 10:51:01.570935 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wkl.php"] [unique_id "amm-9QVDiGi-ktKYT-I0NwAAAME"]
[Wed Jul 29 10:51:02.035518 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ls.php"] [unique_id "amm-9gVDiGi-ktKYT-I0OwAAANc"]
[Wed Jul 29 10:51:02.036297 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ls.php"] [unique_id "amm-9gVDiGi-ktKYT-I0OwAAANc"]
[Wed Jul 29 10:51:02.036645 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ls.php"] [unique_id "amm-9gVDiGi-ktKYT-I0OwAAANc"]
[Wed Jul 29 10:51:02.036706 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ls.php"] [unique_id "amm-9gVDiGi-ktKYT-I0OwAAANc"]
[Wed Jul 29 10:51:02.144771 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/error.php"] [unique_id "amm-9opuIafV02klyJIyqgAAAFc"]
[Wed Jul 29 10:51:02.145740 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/error.php"] [unique_id "amm-9opuIafV02klyJIyqgAAAFc"]
[Wed Jul 29 10:51:02.146172 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/error.php"] [unique_id "amm-9opuIafV02klyJIyqgAAAFc"]
[Wed Jul 29 10:51:02.146280 2026] [:error] [pid 29817:tid 139878922626816] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/error.php"] [unique_id "amm-9opuIafV02klyJIyqgAAAFc"]
[Wed Jul 29 10:51:02.287961 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wpo.php"] [unique_id "amm-9gVDiGi-ktKYT-I0PQAAAM0"]
[Wed Jul 29 10:51:02.288845 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wpo.php"] [unique_id "amm-9gVDiGi-ktKYT-I0PQAAAM0"]
[Wed Jul 29 10:51:02.289231 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wpo.php"] [unique_id "amm-9gVDiGi-ktKYT-I0PQAAAM0"]
[Wed Jul 29 10:51:02.289343 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wpo.php"] [unique_id "amm-9gVDiGi-ktKYT-I0PQAAAM0"]
[Wed Jul 29 10:51:02.367032 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/shellalfa.php"] [unique_id "amm-9gVDiGi-ktKYT-I0PgAAANY"]
[Wed Jul 29 10:51:02.367651 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/shellalfa.php"] [unique_id "amm-9gVDiGi-ktKYT-I0PgAAANY"]
[Wed Jul 29 10:51:02.367933 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/shellalfa.php"] [unique_id "amm-9gVDiGi-ktKYT-I0PgAAANY"]
[Wed Jul 29 10:51:02.367988 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/shellalfa.php"] [unique_id "amm-9gVDiGi-ktKYT-I0PgAAANY"]
[Wed Jul 29 10:51:02.453250 2026] [:error] [pid 29913:tid 139878981375744] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/simple.php"] [unique_id "amm-9gVDiGi-ktKYT-I0QAAAANA"]
[Wed Jul 29 10:51:02.454147 2026] [:error] [pid 29913:tid 139878981375744] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/simple.php"] [unique_id "amm-9gVDiGi-ktKYT-I0QAAAANA"]
[Wed Jul 29 10:51:02.454610 2026] [:error] [pid 29913:tid 139878981375744] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/simple.php"] [unique_id "amm-9gVDiGi-ktKYT-I0QAAAANA"]
[Wed Jul 29 10:51:02.454703 2026] [:error] [pid 29913:tid 139878981375744] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/simple.php"] [unique_id "amm-9gVDiGi-ktKYT-I0QAAAANA"]
[Wed Jul 29 10:51:02.785625 2026] [:error] [pid 29817:tid 139878931019520] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/8.php"] [unique_id "amm-9opuIafV02klyJIyrQAAAFY"]
[Wed Jul 29 10:51:02.786605 2026] [:error] [pid 29817:tid 139878931019520] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/8.php"] [unique_id "amm-9opuIafV02klyJIyrQAAAFY"]
[Wed Jul 29 10:51:02.787046 2026] [:error] [pid 29817:tid 139878931019520] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/8.php"] [unique_id "amm-9opuIafV02klyJIyrQAAAFY"]
[Wed Jul 29 10:51:02.787155 2026] [:error] [pid 29817:tid 139878931019520] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/8.php"] [unique_id "amm-9opuIafV02klyJIyrQAAAFY"]
[Wed Jul 29 10:51:02.849035 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amm-9gVDiGi-ktKYT-I0RQAAAME"]
[Wed Jul 29 10:51:02.850007 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amm-9gVDiGi-ktKYT-I0RQAAAME"]
[Wed Jul 29 10:51:02.850392 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amm-9gVDiGi-ktKYT-I0RQAAAME"]
[Wed Jul 29 10:51:02.850460 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amm-9gVDiGi-ktKYT-I0RQAAAME"]
[Wed Jul 29 10:51:02.964217 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/n.php"] [unique_id "amm-9gVDiGi-ktKYT-I0RwAAANU"]
[Wed Jul 29 10:51:02.965377 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/n.php"] [unique_id "amm-9gVDiGi-ktKYT-I0RwAAANU"]
[Wed Jul 29 10:51:02.965849 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/n.php"] [unique_id "amm-9gVDiGi-ktKYT-I0RwAAANU"]
[Wed Jul 29 10:51:02.965947 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/n.php"] [unique_id "amm-9gVDiGi-ktKYT-I0RwAAANU"]
[Wed Jul 29 10:51:03.043507 2026] [:error] [pid 29817:tid 139878914234112] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/s.php"] [unique_id "amm-94puIafV02klyJIyrgAAAFg"]
[Wed Jul 29 10:51:03.044313 2026] [:error] [pid 29817:tid 139878914234112] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/s.php"] [unique_id "amm-94puIafV02klyJIyrgAAAFg"]
[Wed Jul 29 10:51:03.044709 2026] [:error] [pid 29817:tid 139878914234112] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/s.php"] [unique_id "amm-94puIafV02klyJIyrgAAAFg"]
[Wed Jul 29 10:51:03.044789 2026] [:error] [pid 29817:tid 139878914234112] [client 162.158.123.38:13106] [client 162.158.123.38] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/s.php"] [unique_id "amm-94puIafV02klyJIyrgAAAFg"]
[Wed Jul 29 10:51:03.187544 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cong.php"] [unique_id "amm-9wVDiGi-ktKYT-I0SQAAAM4"]
[Wed Jul 29 10:51:03.188177 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cong.php"] [unique_id "amm-9wVDiGi-ktKYT-I0SQAAAM4"]
[Wed Jul 29 10:51:03.188458 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/cong.php"] [unique_id "amm-9wVDiGi-ktKYT-I0SQAAAM4"]
[Wed Jul 29 10:51:03.188599 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cong.php"] [unique_id "amm-9wVDiGi-ktKYT-I0SQAAAM4"]
[Wed Jul 29 10:51:03.344644 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "amm-9wVDiGi-ktKYT-I0SwAAAMI"]
[Wed Jul 29 10:51:03.345517 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "amm-9wVDiGi-ktKYT-I0SwAAAMI"]
[Wed Jul 29 10:51:03.345982 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "amm-9wVDiGi-ktKYT-I0SwAAAMI"]
[Wed Jul 29 10:51:03.346078 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "amm-9wVDiGi-ktKYT-I0SwAAAMI"]
[Wed Jul 29 10:51:03.579736 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/css.php"] [unique_id "amm-9wVDiGi-ktKYT-I0TgAAAM0"]
[Wed Jul 29 10:51:03.580899 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/css.php"] [unique_id "amm-9wVDiGi-ktKYT-I0TgAAAM0"]
[Wed Jul 29 10:51:03.581247 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/css.php"] [unique_id "amm-9wVDiGi-ktKYT-I0TgAAAM0"]
[Wed Jul 29 10:51:03.581343 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/css.php"] [unique_id "amm-9wVDiGi-ktKYT-I0TgAAAM0"]
[Wed Jul 29 10:51:03.953953 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/lv.php"] [unique_id "amm-9wVDiGi-ktKYT-I0UwAAAME"]
[Wed Jul 29 10:51:03.955027 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/lv.php"] [unique_id "amm-9wVDiGi-ktKYT-I0UwAAAME"]
[Wed Jul 29 10:51:03.955532 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/lv.php"] [unique_id "amm-9wVDiGi-ktKYT-I0UwAAAME"]
[Wed Jul 29 10:51:03.955644 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/lv.php"] [unique_id "amm-9wVDiGi-ktKYT-I0UwAAAME"]
[Wed Jul 29 10:51:04.243830 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ee.php"] [unique_id "amm--AVDiGi-ktKYT-I0VwAAAMI"]
[Wed Jul 29 10:51:04.244660 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ee.php"] [unique_id "amm--AVDiGi-ktKYT-I0VwAAAMI"]
[Wed Jul 29 10:51:04.245043 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ee.php"] [unique_id "amm--AVDiGi-ktKYT-I0VwAAAMI"]
[Wed Jul 29 10:51:04.245102 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ee.php"] [unique_id "amm--AVDiGi-ktKYT-I0VwAAAMI"]
[Wed Jul 29 10:51:04.344104 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/6.php"] [unique_id "amm--AVDiGi-ktKYT-I0WQAAAM0"]
[Wed Jul 29 10:51:04.344957 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/6.php"] [unique_id "amm--AVDiGi-ktKYT-I0WQAAAM0"]
[Wed Jul 29 10:51:04.345323 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/6.php"] [unique_id "amm--AVDiGi-ktKYT-I0WQAAAM0"]
[Wed Jul 29 10:51:04.345403 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/6.php"] [unique_id "amm--AVDiGi-ktKYT-I0WQAAAM0"]
[Wed Jul 29 10:51:04.446963 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/system_log.php"] [unique_id "amm--AVDiGi-ktKYT-I0WwAAAMg"]
[Wed Jul 29 10:51:04.447752 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/system_log.php"] [unique_id "amm--AVDiGi-ktKYT-I0WwAAAMg"]
[Wed Jul 29 10:51:04.448108 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/system_log.php"] [unique_id "amm--AVDiGi-ktKYT-I0WwAAAMg"]
[Wed Jul 29 10:51:04.448186 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/system_log.php"] [unique_id "amm--AVDiGi-ktKYT-I0WwAAAMg"]
[Wed Jul 29 10:51:04.544549 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ab.php"] [unique_id "amm--AVDiGi-ktKYT-I0XAAAAMM"]
[Wed Jul 29 10:51:04.545371 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ab.php"] [unique_id "amm--AVDiGi-ktKYT-I0XAAAAMM"]
[Wed Jul 29 10:51:04.545813 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ab.php"] [unique_id "amm--AVDiGi-ktKYT-I0XAAAAMM"]
[Wed Jul 29 10:51:04.545902 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ab.php"] [unique_id "amm--AVDiGi-ktKYT-I0XAAAAMM"]
[Wed Jul 29 10:51:04.634100 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/lock360.php"] [unique_id "amm--AVDiGi-ktKYT-I0XQAAAME"]
[Wed Jul 29 10:51:04.634617 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/lock360.php"] [unique_id "amm--AVDiGi-ktKYT-I0XQAAAME"]
[Wed Jul 29 10:51:04.634890 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/lock360.php"] [unique_id "amm--AVDiGi-ktKYT-I0XQAAAME"]
[Wed Jul 29 10:51:04.634960 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/lock360.php"] [unique_id "amm--AVDiGi-ktKYT-I0XQAAAME"]
[Wed Jul 29 10:51:05.555705 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/about.php"] [unique_id "amm--QVDiGi-ktKYT-I0ZwAAAMA"]
[Wed Jul 29 10:51:05.556229 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/about.php"] [unique_id "amm--QVDiGi-ktKYT-I0ZwAAAMA"]
[Wed Jul 29 10:51:05.556590 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/about.php"] [unique_id "amm--QVDiGi-ktKYT-I0ZwAAAMA"]
[Wed Jul 29 10:51:05.556666 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/about.php"] [unique_id "amm--QVDiGi-ktKYT-I0ZwAAAMA"]
[Wed Jul 29 10:51:05.643044 2026] [:error] [pid 29913:tid 139878914234112] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/222.php"] [unique_id "amm--QVDiGi-ktKYT-I0aQAAANg"]
[Wed Jul 29 10:51:05.643973 2026] [:error] [pid 29913:tid 139878914234112] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/222.php"] [unique_id "amm--QVDiGi-ktKYT-I0aQAAANg"]
[Wed Jul 29 10:51:05.644384 2026] [:error] [pid 29913:tid 139878914234112] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/222.php"] [unique_id "amm--QVDiGi-ktKYT-I0aQAAANg"]
[Wed Jul 29 10:51:05.644484 2026] [:error] [pid 29913:tid 139878914234112] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/222.php"] [unique_id "amm--QVDiGi-ktKYT-I0aQAAANg"]
[Wed Jul 29 10:51:05.868911 2026] [:error] [pid 29913:tid 139878947804928] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/abcd.php"] [unique_id "amm--QVDiGi-ktKYT-I0bAAAANQ"]
[Wed Jul 29 10:51:05.870182 2026] [:error] [pid 29913:tid 139878947804928] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/abcd.php"] [unique_id "amm--QVDiGi-ktKYT-I0bAAAANQ"]
[Wed Jul 29 10:51:05.870636 2026] [:error] [pid 29913:tid 139878947804928] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/abcd.php"] [unique_id "amm--QVDiGi-ktKYT-I0bAAAANQ"]
[Wed Jul 29 10:51:05.870749 2026] [:error] [pid 29913:tid 139878947804928] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/abcd.php"] [unique_id "amm--QVDiGi-ktKYT-I0bAAAANQ"]
[Wed Jul 29 10:51:06.341712 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gifclass.php"] [unique_id "amm--gVDiGi-ktKYT-I0cgAAANc"]
[Wed Jul 29 10:51:06.342785 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gifclass.php"] [unique_id "amm--gVDiGi-ktKYT-I0cgAAANc"]
[Wed Jul 29 10:51:06.343156 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/gifclass.php"] [unique_id "amm--gVDiGi-ktKYT-I0cgAAANc"]
[Wed Jul 29 10:51:06.343222 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gifclass.php"] [unique_id "amm--gVDiGi-ktKYT-I0cgAAANc"]
[Wed Jul 29 10:51:06.654446 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/enclas.php"] [unique_id "amm--gVDiGi-ktKYT-I0dQAAAMA"]
[Wed Jul 29 10:51:06.655758 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/enclas.php"] [unique_id "amm--gVDiGi-ktKYT-I0dQAAAMA"]
[Wed Jul 29 10:51:06.659387 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/enclas.php"] [unique_id "amm--gVDiGi-ktKYT-I0dQAAAMA"]
[Wed Jul 29 10:51:06.659541 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/enclas.php"] [unique_id "amm--gVDiGi-ktKYT-I0dQAAAMA"]
[Wed Jul 29 10:51:06.745404 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/alfa.php"] [unique_id "amm--gVDiGi-ktKYT-I0dwAAANM"]
[Wed Jul 29 10:51:06.746305 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/alfa.php"] [unique_id "amm--gVDiGi-ktKYT-I0dwAAANM"]
[Wed Jul 29 10:51:06.746783 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/alfa.php"] [unique_id "amm--gVDiGi-ktKYT-I0dwAAANM"]
[Wed Jul 29 10:51:06.746874 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/alfa.php"] [unique_id "amm--gVDiGi-ktKYT-I0dwAAANM"]
[Wed Jul 29 10:51:06.849084 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/we.php"] [unique_id "amm--gVDiGi-ktKYT-I0eAAAAMg"]
[Wed Jul 29 10:51:06.889109 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/we.php"] [unique_id "amm--gVDiGi-ktKYT-I0eAAAAMg"]
[Wed Jul 29 10:51:06.889546 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/we.php"] [unique_id "amm--gVDiGi-ktKYT-I0eAAAAMg"]
[Wed Jul 29 10:51:06.889665 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/we.php"] [unique_id "amm--gVDiGi-ktKYT-I0eAAAAMg"]
[Wed Jul 29 10:51:07.572417 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fe5.php"] [unique_id "amm--wVDiGi-ktKYT-I0fgAAAM8"]
[Wed Jul 29 10:51:07.572991 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fe5.php"] [unique_id "amm--wVDiGi-ktKYT-I0fgAAAM8"]
[Wed Jul 29 10:51:07.573242 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fe5.php"] [unique_id "amm--wVDiGi-ktKYT-I0fgAAAM8"]
[Wed Jul 29 10:51:07.573291 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/fe5.php"] [unique_id "amm--wVDiGi-ktKYT-I0fgAAAM8"]
[Wed Jul 29 10:51:07.650480 2026] [:error] [pid 29913:tid 139879073695488] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/tgrs.php"] [unique_id "amm--wVDiGi-ktKYT-I0gQAAAMU"]
[Wed Jul 29 10:51:07.651644 2026] [:error] [pid 29913:tid 139879073695488] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/tgrs.php"] [unique_id "amm--wVDiGi-ktKYT-I0gQAAAMU"]
[Wed Jul 29 10:51:07.652042 2026] [:error] [pid 29913:tid 139879073695488] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/tgrs.php"] [unique_id "amm--wVDiGi-ktKYT-I0gQAAAMU"]
[Wed Jul 29 10:51:07.652138 2026] [:error] [pid 29913:tid 139879073695488] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/tgrs.php"] [unique_id "amm--wVDiGi-ktKYT-I0gQAAAMU"]
[Wed Jul 29 10:51:07.743270 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ut.php"] [unique_id "amm--wVDiGi-ktKYT-I0gwAAANM"]
[Wed Jul 29 10:51:07.744365 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ut.php"] [unique_id "amm--wVDiGi-ktKYT-I0gwAAANM"]
[Wed Jul 29 10:51:07.744771 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ut.php"] [unique_id "amm--wVDiGi-ktKYT-I0gwAAANM"]
[Wed Jul 29 10:51:07.744838 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ut.php"] [unique_id "amm--wVDiGi-ktKYT-I0gwAAANM"]
[Wed Jul 29 10:51:07.834969 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/a3.php"] [unique_id "amm--wVDiGi-ktKYT-I0hAAAAMg"]
[Wed Jul 29 10:51:07.835838 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/a3.php"] [unique_id "amm--wVDiGi-ktKYT-I0hAAAAMg"]
[Wed Jul 29 10:51:07.836236 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/a3.php"] [unique_id "amm--wVDiGi-ktKYT-I0hAAAAMg"]
[Wed Jul 29 10:51:07.836315 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/a3.php"] [unique_id "amm--wVDiGi-ktKYT-I0hAAAAMg"]
[Wed Jul 29 10:51:08.035099 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aa.php"] [unique_id "amm-_AVDiGi-ktKYT-I0hQAAANc"]
[Wed Jul 29 10:51:08.035656 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aa.php"] [unique_id "amm-_AVDiGi-ktKYT-I0hQAAANc"]
[Wed Jul 29 10:51:08.035920 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/aa.php"] [unique_id "amm-_AVDiGi-ktKYT-I0hQAAANc"]
[Wed Jul 29 10:51:08.035968 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/aa.php"] [unique_id "amm-_AVDiGi-ktKYT-I0hQAAANc"]
[Wed Jul 29 10:51:08.195401 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amm-_AVDiGi-ktKYT-I0hwAAANE"]
[Wed Jul 29 10:51:08.196293 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amm-_AVDiGi-ktKYT-I0hwAAANE"]
[Wed Jul 29 10:51:08.196697 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amm-_AVDiGi-ktKYT-I0hwAAANE"]
[Wed Jul 29 10:51:08.196771 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amm-_AVDiGi-ktKYT-I0hwAAANE"]
[Wed Jul 29 10:51:08.197431 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] File does not exist: /usr/local/apache/autossl_tmp/.well-known/acme-challenge/about.php
[Wed Jul 29 10:51:08.244308 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/3.php"] [unique_id "amm-_AVDiGi-ktKYT-I0iAAAAMw"]
[Wed Jul 29 10:51:08.245123 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/3.php"] [unique_id "amm-_AVDiGi-ktKYT-I0iAAAAMw"]
[Wed Jul 29 10:51:08.245567 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/3.php"] [unique_id "amm-_AVDiGi-ktKYT-I0iAAAAMw"]
[Wed Jul 29 10:51:08.245651 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/3.php"] [unique_id "amm-_AVDiGi-ktKYT-I0iAAAAMw"]
[Wed Jul 29 10:51:08.344521 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/f6.php"] [unique_id "amm-_AVDiGi-ktKYT-I0igAAAME"]
[Wed Jul 29 10:51:08.362416 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/f6.php"] [unique_id "amm-_AVDiGi-ktKYT-I0igAAAME"]
[Wed Jul 29 10:51:08.362826 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/f6.php"] [unique_id "amm-_AVDiGi-ktKYT-I0igAAAME"]
[Wed Jul 29 10:51:08.362887 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/f6.php"] [unique_id "amm-_AVDiGi-ktKYT-I0igAAAME"]
[Wed Jul 29 10:51:08.534029 2026] [:error] [pid 29913:tid 139879065302784] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fm.php"] [unique_id "amm-_AVDiGi-ktKYT-I0jAAAAMY"]
[Wed Jul 29 10:51:08.534974 2026] [:error] [pid 29913:tid 139879065302784] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fm.php"] [unique_id "amm-_AVDiGi-ktKYT-I0jAAAAMY"]
[Wed Jul 29 10:51:08.535330 2026] [:error] [pid 29913:tid 139879065302784] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fm.php"] [unique_id "amm-_AVDiGi-ktKYT-I0jAAAAMY"]
[Wed Jul 29 10:51:08.535396 2026] [:error] [pid 29913:tid 139879065302784] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/fm.php"] [unique_id "amm-_AVDiGi-ktKYT-I0jAAAAMY"]
[Wed Jul 29 10:51:08.648505 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/rrr.php"] [unique_id "amm-_AVDiGi-ktKYT-I0jgAAAM8"]
[Wed Jul 29 10:51:08.649345 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/rrr.php"] [unique_id "amm-_AVDiGi-ktKYT-I0jgAAAM8"]
[Wed Jul 29 10:51:08.649689 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/rrr.php"] [unique_id "amm-_AVDiGi-ktKYT-I0jgAAAM8"]
[Wed Jul 29 10:51:08.649801 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/rrr.php"] [unique_id "amm-_AVDiGi-ktKYT-I0jgAAAM8"]
[Wed Jul 29 10:51:08.752565 2026] [:error] [pid 29913:tid 139879073695488] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/usep.php"] [unique_id "amm-_AVDiGi-ktKYT-I0kAAAAMU"]
[Wed Jul 29 10:51:08.753242 2026] [:error] [pid 29913:tid 139879073695488] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/usep.php"] [unique_id "amm-_AVDiGi-ktKYT-I0kAAAAMU"]
[Wed Jul 29 10:51:08.753539 2026] [:error] [pid 29913:tid 139879073695488] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/usep.php"] [unique_id "amm-_AVDiGi-ktKYT-I0kAAAAMU"]
[Wed Jul 29 10:51:08.753630 2026] [:error] [pid 29913:tid 139879073695488] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/usep.php"] [unique_id "amm-_AVDiGi-ktKYT-I0kAAAAMU"]
[Wed Jul 29 10:51:09.034487 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fm.php"] [unique_id "amm-_QVDiGi-ktKYT-I0kgAAANE"]
[Wed Jul 29 10:51:09.035486 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fm.php"] [unique_id "amm-_QVDiGi-ktKYT-I0kgAAANE"]
[Wed Jul 29 10:51:09.035999 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fm.php"] [unique_id "amm-_QVDiGi-ktKYT-I0kgAAANE"]
[Wed Jul 29 10:51:09.036101 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/fm.php"] [unique_id "amm-_QVDiGi-ktKYT-I0kgAAANE"]
[Wed Jul 29 10:51:09.236203 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/0x.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lAAAAME"]
[Wed Jul 29 10:51:09.237311 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/0x.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lAAAAME"]
[Wed Jul 29 10:51:09.237835 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/0x.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lAAAAME"]
[Wed Jul 29 10:51:09.237927 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/0x.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lAAAAME"]
[Wed Jul 29 10:51:09.344774 2026] [:error] [pid 29913:tid 139879065302784] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/goat.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lQAAAMY"]
[Wed Jul 29 10:51:09.345716 2026] [:error] [pid 29913:tid 139879065302784] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/goat.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lQAAAMY"]
[Wed Jul 29 10:51:09.346159 2026] [:error] [pid 29913:tid 139879065302784] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/goat.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lQAAAMY"]
[Wed Jul 29 10:51:09.346252 2026] [:error] [pid 29913:tid 139879065302784] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/goat.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lQAAAMY"]
[Wed Jul 29 10:51:09.435629 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/123.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lgAAAM8"]
[Wed Jul 29 10:51:09.436526 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/123.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lgAAAM8"]
[Wed Jul 29 10:51:09.436919 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/123.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lgAAAM8"]
[Wed Jul 29 10:51:09.437009 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/123.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lgAAAM8"]
[Wed Jul 29 10:51:09.542727 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ioxi-o.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lwAAANY"]
[Wed Jul 29 10:51:09.543545 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ioxi-o.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lwAAANY"]
[Wed Jul 29 10:51:09.543933 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ioxi-o.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lwAAANY"]
[Wed Jul 29 10:51:09.544022 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ioxi-o.php"] [unique_id "amm-_QVDiGi-ktKYT-I0lwAAANY"]
[Wed Jul 29 10:51:09.673725 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/taktak.php"] [unique_id "amm-_QVDiGi-ktKYT-I0mAAAANM"]
[Wed Jul 29 10:51:09.674631 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/taktak.php"] [unique_id "amm-_QVDiGi-ktKYT-I0mAAAANM"]
[Wed Jul 29 10:51:09.674995 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/taktak.php"] [unique_id "amm-_QVDiGi-ktKYT-I0mAAAANM"]
[Wed Jul 29 10:51:09.675069 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/taktak.php"] [unique_id "amm-_QVDiGi-ktKYT-I0mAAAANM"]
[Wed Jul 29 10:51:09.846248 2026] [:error] [pid 29913:tid 139879073695488] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/tgrs.php"] [unique_id "amm-_QVDiGi-ktKYT-I0mgAAAMU"]
[Wed Jul 29 10:51:09.847135 2026] [:error] [pid 29913:tid 139879073695488] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/tgrs.php"] [unique_id "amm-_QVDiGi-ktKYT-I0mgAAAMU"]
[Wed Jul 29 10:51:09.847618 2026] [:error] [pid 29913:tid 139879073695488] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/tgrs.php"] [unique_id "amm-_QVDiGi-ktKYT-I0mgAAAMU"]
[Wed Jul 29 10:51:09.847708 2026] [:error] [pid 29913:tid 139879073695488] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/tgrs.php"] [unique_id "amm-_QVDiGi-ktKYT-I0mgAAAMU"]
[Wed Jul 29 10:51:10.044891 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gt.php"] [unique_id "amm-_gVDiGi-ktKYT-I0nQAAANc"]
[Wed Jul 29 10:51:10.045957 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gt.php"] [unique_id "amm-_gVDiGi-ktKYT-I0nQAAANc"]
[Wed Jul 29 10:51:10.046371 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/gt.php"] [unique_id "amm-_gVDiGi-ktKYT-I0nQAAANc"]
[Wed Jul 29 10:51:10.046453 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gt.php"] [unique_id "amm-_gVDiGi-ktKYT-I0nQAAANc"]
[Wed Jul 29 10:51:10.136750 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aghbvr.php"] [unique_id "amm-_gVDiGi-ktKYT-I0nwAAAMw"]
[Wed Jul 29 10:51:10.137854 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aghbvr.php"] [unique_id "amm-_gVDiGi-ktKYT-I0nwAAAMw"]
[Wed Jul 29 10:51:10.138276 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/aghbvr.php"] [unique_id "amm-_gVDiGi-ktKYT-I0nwAAAMw"]
[Wed Jul 29 10:51:10.138358 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/aghbvr.php"] [unique_id "amm-_gVDiGi-ktKYT-I0nwAAAMw"]
[Wed Jul 29 10:51:10.198255 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/miso.php"] [unique_id "amm-_gVDiGi-ktKYT-I0oAAAAMM"]
[Wed Jul 29 10:51:10.198941 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/miso.php"] [unique_id "amm-_gVDiGi-ktKYT-I0oAAAAMM"]
[Wed Jul 29 10:51:10.199233 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/miso.php"] [unique_id "amm-_gVDiGi-ktKYT-I0oAAAAMM"]
[Wed Jul 29 10:51:10.199291 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/miso.php"] [unique_id "amm-_gVDiGi-ktKYT-I0oAAAAMM"]
[Wed Jul 29 10:51:10.581292 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/naxc.php"] [unique_id "amm-_gVDiGi-ktKYT-I0owAAANU"]
[Wed Jul 29 10:51:10.582389 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/naxc.php"] [unique_id "amm-_gVDiGi-ktKYT-I0owAAANU"]
[Wed Jul 29 10:51:10.582858 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/naxc.php"] [unique_id "amm-_gVDiGi-ktKYT-I0owAAANU"]
[Wed Jul 29 10:51:10.582977 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/naxc.php"] [unique_id "amm-_gVDiGi-ktKYT-I0owAAANU"]
[Wed Jul 29 10:51:10.751869 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fex.php"] [unique_id "amm-_gVDiGi-ktKYT-I0pAAAAM8"]
[Wed Jul 29 10:51:10.752863 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fex.php"] [unique_id "amm-_gVDiGi-ktKYT-I0pAAAAM8"]
[Wed Jul 29 10:51:10.753269 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fex.php"] [unique_id "amm-_gVDiGi-ktKYT-I0pAAAAM8"]
[Wed Jul 29 10:51:10.753360 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/fex.php"] [unique_id "amm-_gVDiGi-ktKYT-I0pAAAAM8"]
[Wed Jul 29 10:51:10.844643 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/taff.php"] [unique_id "amm-_gVDiGi-ktKYT-I0pQAAANI"]
[Wed Jul 29 10:51:10.845499 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/taff.php"] [unique_id "amm-_gVDiGi-ktKYT-I0pQAAANI"]
[Wed Jul 29 10:51:10.845835 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/taff.php"] [unique_id "amm-_gVDiGi-ktKYT-I0pQAAANI"]
[Wed Jul 29 10:51:10.845897 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/taff.php"] [unique_id "amm-_gVDiGi-ktKYT-I0pQAAANI"]
[Wed Jul 29 10:51:11.043405 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bless11.php"] [unique_id "amm-_wVDiGi-ktKYT-I0pwAAANE"]
[Wed Jul 29 10:51:11.044278 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bless11.php"] [unique_id "amm-_wVDiGi-ktKYT-I0pwAAANE"]
[Wed Jul 29 10:51:11.053096 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bless11.php"] [unique_id "amm-_wVDiGi-ktKYT-I0pwAAANE"]
[Wed Jul 29 10:51:11.053196 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bless11.php"] [unique_id "amm-_wVDiGi-ktKYT-I0pwAAANE"]
[Wed Jul 29 10:51:11.164739 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aj.php"] [unique_id "amm-_wVDiGi-ktKYT-I0qgAAAMI"]
[Wed Jul 29 10:51:11.165647 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aj.php"] [unique_id "amm-_wVDiGi-ktKYT-I0qgAAAMI"]
[Wed Jul 29 10:51:11.165979 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/aj.php"] [unique_id "amm-_wVDiGi-ktKYT-I0qgAAAMI"]
[Wed Jul 29 10:51:11.166087 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/aj.php"] [unique_id "amm-_wVDiGi-ktKYT-I0qgAAAMI"]
[Wed Jul 29 10:51:11.334563 2026] [:error] [pid 29913:tid 139879023339264] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/opts.php"] [unique_id "amm-_wVDiGi-ktKYT-I0qwAAAMs"]
[Wed Jul 29 10:51:11.335669 2026] [:error] [pid 29913:tid 139879023339264] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/opts.php"] [unique_id "amm-_wVDiGi-ktKYT-I0qwAAAMs"]
[Wed Jul 29 10:51:11.336094 2026] [:error] [pid 29913:tid 139879023339264] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/opts.php"] [unique_id "amm-_wVDiGi-ktKYT-I0qwAAAMs"]
[Wed Jul 29 10:51:11.336210 2026] [:error] [pid 29913:tid 139879023339264] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/opts.php"] [unique_id "amm-_wVDiGi-ktKYT-I0qwAAAMs"]
[Wed Jul 29 10:51:11.453695 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wpo.php"] [unique_id "amm-_wVDiGi-ktKYT-I0rAAAANc"]
[Wed Jul 29 10:51:11.454621 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wpo.php"] [unique_id "amm-_wVDiGi-ktKYT-I0rAAAANc"]
[Wed Jul 29 10:51:11.455095 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wpo.php"] [unique_id "amm-_wVDiGi-ktKYT-I0rAAAANc"]
[Wed Jul 29 10:51:11.455170 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wpo.php"] [unique_id "amm-_wVDiGi-ktKYT-I0rAAAANc"]
[Wed Jul 29 10:51:11.741716 2026] [:error] [pid 29913:tid 139879082088192] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/filer.php"] [unique_id "amm-_wVDiGi-ktKYT-I0rgAAAMQ"]
[Wed Jul 29 10:51:11.742199 2026] [:error] [pid 29913:tid 139879082088192] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/filer.php"] [unique_id "amm-_wVDiGi-ktKYT-I0rgAAAMQ"]
[Wed Jul 29 10:51:11.742470 2026] [:error] [pid 29913:tid 139879082088192] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/filer.php"] [unique_id "amm-_wVDiGi-ktKYT-I0rgAAAMQ"]
[Wed Jul 29 10:51:11.742595 2026] [:error] [pid 29913:tid 139879082088192] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/filer.php"] [unique_id "amm-_wVDiGi-ktKYT-I0rgAAAMQ"]
[Wed Jul 29 10:51:12.062692 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/enclas.php"] [unique_id "amm_AAVDiGi-ktKYT-I0sAAAAMM"]
[Wed Jul 29 10:51:12.063582 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/enclas.php"] [unique_id "amm_AAVDiGi-ktKYT-I0sAAAAMM"]
[Wed Jul 29 10:51:12.063962 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/enclas.php"] [unique_id "amm_AAVDiGi-ktKYT-I0sAAAAMM"]
[Wed Jul 29 10:51:12.064046 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/enclas.php"] [unique_id "amm_AAVDiGi-ktKYT-I0sAAAAMM"]
[Wed Jul 29 10:51:12.343426 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/en0.php"] [unique_id "amm_AAVDiGi-ktKYT-I0sQAAANU"]
[Wed Jul 29 10:51:12.344310 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/en0.php"] [unique_id "amm_AAVDiGi-ktKYT-I0sQAAANU"]
[Wed Jul 29 10:51:12.344747 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/en0.php"] [unique_id "amm_AAVDiGi-ktKYT-I0sQAAANU"]
[Wed Jul 29 10:51:12.344830 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/en0.php"] [unique_id "amm_AAVDiGi-ktKYT-I0sQAAANU"]
[Wed Jul 29 10:51:12.637343 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/kaza.php"] [unique_id "amm_AAVDiGi-ktKYT-I0sgAAAMo"]
[Wed Jul 29 10:51:12.638310 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/kaza.php"] [unique_id "amm_AAVDiGi-ktKYT-I0sgAAAMo"]
[Wed Jul 29 10:51:12.638966 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/kaza.php"] [unique_id "amm_AAVDiGi-ktKYT-I0sgAAAMo"]
[Wed Jul 29 10:51:12.639076 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/kaza.php"] [unique_id "amm_AAVDiGi-ktKYT-I0sgAAAMo"]
[Wed Jul 29 10:51:12.865456 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wsd.php"] [unique_id "amm_AAVDiGi-ktKYT-I0tAAAANI"]
[Wed Jul 29 10:51:12.866100 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wsd.php"] [unique_id "amm_AAVDiGi-ktKYT-I0tAAAANI"]
[Wed Jul 29 10:51:12.866513 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wsd.php"] [unique_id "amm_AAVDiGi-ktKYT-I0tAAAANI"]
[Wed Jul 29 10:51:12.866648 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wsd.php"] [unique_id "amm_AAVDiGi-ktKYT-I0tAAAANI"]
[Wed Jul 29 10:51:12.934437 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gifclass4.php"] [unique_id "amm_AAVDiGi-ktKYT-I0tQAAAMA"]
[Wed Jul 29 10:51:12.935276 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gifclass4.php"] [unique_id "amm_AAVDiGi-ktKYT-I0tQAAAMA"]
[Wed Jul 29 10:51:12.935679 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/gifclass4.php"] [unique_id "amm_AAVDiGi-ktKYT-I0tQAAAMA"]
[Wed Jul 29 10:51:12.935764 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gifclass4.php"] [unique_id "amm_AAVDiGi-ktKYT-I0tQAAAMA"]
[Wed Jul 29 10:51:13.035721 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amm_AQVDiGi-ktKYT-I0tgAAANE"]
[Wed Jul 29 10:51:13.036510 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amm_AQVDiGi-ktKYT-I0tgAAANE"]
[Wed Jul 29 10:51:13.036903 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amm_AQVDiGi-ktKYT-I0tgAAANE"]
[Wed Jul 29 10:51:13.037003 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/info.php"] [unique_id "amm_AQVDiGi-ktKYT-I0tgAAANE"]
[Wed Jul 29 10:51:13.134286 2026] [:error] [pid 29913:tid 139879056910080] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/333.php"] [unique_id "amm_AQVDiGi-ktKYT-I0twAAAMc"]
[Wed Jul 29 10:51:13.135265 2026] [:error] [pid 29913:tid 139879056910080] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/333.php"] [unique_id "amm_AQVDiGi-ktKYT-I0twAAAMc"]
[Wed Jul 29 10:51:13.135751 2026] [:error] [pid 29913:tid 139879056910080] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/333.php"] [unique_id "amm_AQVDiGi-ktKYT-I0twAAAMc"]
[Wed Jul 29 10:51:13.135843 2026] [:error] [pid 29913:tid 139879056910080] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/333.php"] [unique_id "amm_AQVDiGi-ktKYT-I0twAAAMc"]
[Wed Jul 29 10:51:13.334281 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cfile.php"] [unique_id "amm_AQVDiGi-ktKYT-I0uQAAAMI"]
[Wed Jul 29 10:51:13.335647 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cfile.php"] [unique_id "amm_AQVDiGi-ktKYT-I0uQAAAMI"]
[Wed Jul 29 10:51:13.336095 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/cfile.php"] [unique_id "amm_AQVDiGi-ktKYT-I0uQAAAMI"]
[Wed Jul 29 10:51:13.336220 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cfile.php"] [unique_id "amm_AQVDiGi-ktKYT-I0uQAAAMI"]
[Wed Jul 29 10:51:13.557895 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bless3.php"] [unique_id "amm_AQVDiGi-ktKYT-I0uwAAANY"]
[Wed Jul 29 10:51:13.558873 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bless3.php"] [unique_id "amm_AQVDiGi-ktKYT-I0uwAAANY"]
[Wed Jul 29 10:51:13.559297 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bless3.php"] [unique_id "amm_AQVDiGi-ktKYT-I0uwAAANY"]
[Wed Jul 29 10:51:13.559388 2026] [:error] [pid 29913:tid 139878931019520] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bless3.php"] [unique_id "amm_AQVDiGi-ktKYT-I0uwAAANY"]
[Wed Jul 29 10:51:13.734395 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bless.php"] [unique_id "amm_AQVDiGi-ktKYT-I0vQAAAM4"]
[Wed Jul 29 10:51:13.735570 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bless.php"] [unique_id "amm_AQVDiGi-ktKYT-I0vQAAAM4"]
[Wed Jul 29 10:51:13.735985 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bless.php"] [unique_id "amm_AQVDiGi-ktKYT-I0vQAAAM4"]
[Wed Jul 29 10:51:13.736107 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bless.php"] [unique_id "amm_AQVDiGi-ktKYT-I0vQAAAM4"]
[Wed Jul 29 10:51:13.864218 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/doti.php"] [unique_id "amm_AQVDiGi-ktKYT-I0vwAAAMM"]
[Wed Jul 29 10:51:13.865309 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/doti.php"] [unique_id "amm_AQVDiGi-ktKYT-I0vwAAAMM"]
[Wed Jul 29 10:51:13.865836 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/doti.php"] [unique_id "amm_AQVDiGi-ktKYT-I0vwAAAMM"]
[Wed Jul 29 10:51:13.865959 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/doti.php"] [unique_id "amm_AQVDiGi-ktKYT-I0vwAAAMM"]
[Wed Jul 29 10:51:14.048041 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/031.php"] [unique_id "amm_AgVDiGi-ktKYT-I0wgAAAMw"]
[Wed Jul 29 10:51:14.049067 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/031.php"] [unique_id "amm_AgVDiGi-ktKYT-I0wgAAAMw"]
[Wed Jul 29 10:51:14.049373 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/031.php"] [unique_id "amm_AgVDiGi-ktKYT-I0wgAAAMw"]
[Wed Jul 29 10:51:14.049437 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/031.php"] [unique_id "amm_AgVDiGi-ktKYT-I0wgAAAMw"]
[Wed Jul 29 10:51:14.145393 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wfile.php"] [unique_id "amm_AgVDiGi-ktKYT-I0xAAAAMo"]
[Wed Jul 29 10:51:14.146701 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wfile.php"] [unique_id "amm_AgVDiGi-ktKYT-I0xAAAAMo"]
[Wed Jul 29 10:51:14.147199 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wfile.php"] [unique_id "amm_AgVDiGi-ktKYT-I0xAAAAMo"]
[Wed Jul 29 10:51:14.147297 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wfile.php"] [unique_id "amm_AgVDiGi-ktKYT-I0xAAAAMo"]
[Wed Jul 29 10:51:14.335158 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/lala.php"] [unique_id "amm_AgVDiGi-ktKYT-I0xgAAAMA"]
[Wed Jul 29 10:51:14.336149 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/lala.php"] [unique_id "amm_AgVDiGi-ktKYT-I0xgAAAMA"]
[Wed Jul 29 10:51:14.336614 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/lala.php"] [unique_id "amm_AgVDiGi-ktKYT-I0xgAAAMA"]
[Wed Jul 29 10:51:14.336713 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/lala.php"] [unique_id "amm_AgVDiGi-ktKYT-I0xgAAAMA"]
[Wed Jul 29 10:51:14.471663 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mac.php"] [unique_id "amm_AgVDiGi-ktKYT-I0yAAAANE"]
[Wed Jul 29 10:51:14.472484 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mac.php"] [unique_id "amm_AgVDiGi-ktKYT-I0yAAAANE"]
[Wed Jul 29 10:51:14.472893 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/mac.php"] [unique_id "amm_AgVDiGi-ktKYT-I0yAAAANE"]
[Wed Jul 29 10:51:14.472999 2026] [:error] [pid 29913:tid 139878972983040] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mac.php"] [unique_id "amm_AgVDiGi-ktKYT-I0yAAAANE"]
[Wed Jul 29 10:51:14.849668 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/he.php"] [unique_id "amm_AgVDiGi-ktKYT-I0ygAAANM"]
[Wed Jul 29 10:51:14.850113 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/he.php"] [unique_id "amm_AgVDiGi-ktKYT-I0ygAAANM"]
[Wed Jul 29 10:51:14.850386 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/he.php"] [unique_id "amm_AgVDiGi-ktKYT-I0ygAAANM"]
[Wed Jul 29 10:51:14.850451 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/he.php"] [unique_id "amm_AgVDiGi-ktKYT-I0ygAAANM"]
[Wed Jul 29 10:51:14.977877 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/plss3.php"] [unique_id "amm_AgVDiGi-ktKYT-I0zAAAANc"]
[Wed Jul 29 10:51:14.978509 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/plss3.php"] [unique_id "amm_AgVDiGi-ktKYT-I0zAAAANc"]
[Wed Jul 29 10:51:14.978799 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/plss3.php"] [unique_id "amm_AgVDiGi-ktKYT-I0zAAAANc"]
[Wed Jul 29 10:51:14.978853 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/plss3.php"] [unique_id "amm_AgVDiGi-ktKYT-I0zAAAANc"]
[Wed Jul 29 10:51:15.171270 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ton.php"] [unique_id "amm_AwVDiGi-ktKYT-I0zQAAAM8"]
[Wed Jul 29 10:51:15.171882 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ton.php"] [unique_id "amm_AwVDiGi-ktKYT-I0zQAAAM8"]
[Wed Jul 29 10:51:15.172157 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ton.php"] [unique_id "amm_AwVDiGi-ktKYT-I0zQAAAM8"]
[Wed Jul 29 10:51:15.172211 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ton.php"] [unique_id "amm_AwVDiGi-ktKYT-I0zQAAAM8"]
[Wed Jul 29 10:51:15.273403 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/33.php"] [unique_id "amm_AwVDiGi-ktKYT-I0zgAAAMM"]
[Wed Jul 29 10:51:15.274078 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/33.php"] [unique_id "amm_AwVDiGi-ktKYT-I0zgAAAMM"]
[Wed Jul 29 10:51:15.274367 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/33.php"] [unique_id "amm_AwVDiGi-ktKYT-I0zgAAAMM"]
[Wed Jul 29 10:51:15.274440 2026] [:error] [pid 29913:tid 139879090480896] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/33.php"] [unique_id "amm_AwVDiGi-ktKYT-I0zgAAAMM"]
[Wed Jul 29 10:51:15.344508 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/nfile.php"] [unique_id "amm_AwVDiGi-ktKYT-I0zwAAANU"]
[Wed Jul 29 10:51:15.345196 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/nfile.php"] [unique_id "amm_AwVDiGi-ktKYT-I0zwAAANU"]
[Wed Jul 29 10:51:15.345462 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/nfile.php"] [unique_id "amm_AwVDiGi-ktKYT-I0zwAAANU"]
[Wed Jul 29 10:51:15.345531 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/nfile.php"] [unique_id "amm_AwVDiGi-ktKYT-I0zwAAANU"]
[Wed Jul 29 10:51:15.433968 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ffile.php"] [unique_id "amm_AwVDiGi-ktKYT-I00AAAAMw"]
[Wed Jul 29 10:51:15.434866 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ffile.php"] [unique_id "amm_AwVDiGi-ktKYT-I00AAAAMw"]
[Wed Jul 29 10:51:15.435256 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ffile.php"] [unique_id "amm_AwVDiGi-ktKYT-I00AAAAMw"]
[Wed Jul 29 10:51:15.435337 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ffile.php"] [unique_id "amm_AwVDiGi-ktKYT-I00AAAAMw"]
[Wed Jul 29 10:51:15.855769 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file18.php"] [unique_id "amm_AwVDiGi-ktKYT-I00wAAAMg"]
[Wed Jul 29 10:51:15.856762 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file18.php"] [unique_id "amm_AwVDiGi-ktKYT-I00wAAAMg"]
[Wed Jul 29 10:51:15.857172 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file18.php"] [unique_id "amm_AwVDiGi-ktKYT-I00wAAAMg"]
[Wed Jul 29 10:51:15.857261 2026] [:error] [pid 29913:tid 139879048517376] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file18.php"] [unique_id "amm_AwVDiGi-ktKYT-I00wAAAMg"]
[Wed Jul 29 10:51:16.345155 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file21.php"] [unique_id "amm_BAVDiGi-ktKYT-I01QAAAM4"]
[Wed Jul 29 10:51:16.345793 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file21.php"] [unique_id "amm_BAVDiGi-ktKYT-I01QAAAM4"]
[Wed Jul 29 10:51:16.346152 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file21.php"] [unique_id "amm_BAVDiGi-ktKYT-I01QAAAM4"]
[Wed Jul 29 10:51:16.346232 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file21.php"] [unique_id "amm_BAVDiGi-ktKYT-I01QAAAM4"]
[Wed Jul 29 10:51:16.465042 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/yellow.php"] [unique_id "amm_BAVDiGi-ktKYT-I02AAAANc"]
[Wed Jul 29 10:51:16.534481 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/yellow.php"] [unique_id "amm_BAVDiGi-ktKYT-I02AAAANc"]
[Wed Jul 29 10:51:16.535052 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/yellow.php"] [unique_id "amm_BAVDiGi-ktKYT-I02AAAANc"]
[Wed Jul 29 10:51:16.535153 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/yellow.php"] [unique_id "amm_BAVDiGi-ktKYT-I02AAAANc"]
[Wed Jul 29 10:51:16.849861 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file1.php"] [unique_id "amm_BAVDiGi-ktKYT-I03AAAANU"]
[Wed Jul 29 10:51:16.850873 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file1.php"] [unique_id "amm_BAVDiGi-ktKYT-I03AAAANU"]
[Wed Jul 29 10:51:16.851294 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file1.php"] [unique_id "amm_BAVDiGi-ktKYT-I03AAAANU"]
[Wed Jul 29 10:51:16.851381 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file1.php"] [unique_id "amm_BAVDiGi-ktKYT-I03AAAANU"]
[Wed Jul 29 10:51:17.174419 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/geck.php"] [unique_id "amm_BQVDiGi-ktKYT-I03wAAAMI"]
[Wed Jul 29 10:51:17.175088 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/geck.php"] [unique_id "amm_BQVDiGi-ktKYT-I03wAAAMI"]
[Wed Jul 29 10:51:17.175373 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/geck.php"] [unique_id "amm_BQVDiGi-ktKYT-I03wAAAMI"]
[Wed Jul 29 10:51:17.175444 2026] [:error] [pid 29913:tid 139879098873600] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/geck.php"] [unique_id "amm_BQVDiGi-ktKYT-I03wAAAMI"]
[Wed Jul 29 10:51:17.273448 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file4.php"] [unique_id "amm_BQVDiGi-ktKYT-I04AAAAMo"]
[Wed Jul 29 10:51:17.274105 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file4.php"] [unique_id "amm_BQVDiGi-ktKYT-I04AAAAMo"]
[Wed Jul 29 10:51:17.274376 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file4.php"] [unique_id "amm_BQVDiGi-ktKYT-I04AAAAMo"]
[Wed Jul 29 10:51:17.274426 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file4.php"] [unique_id "amm_BQVDiGi-ktKYT-I04AAAAMo"]
[Wed Jul 29 10:51:17.675411 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file88.php"] [unique_id "amm_BQVDiGi-ktKYT-I05AAAAM4"]
[Wed Jul 29 10:51:17.676156 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file88.php"] [unique_id "amm_BQVDiGi-ktKYT-I05AAAAM4"]
[Wed Jul 29 10:51:17.676438 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file88.php"] [unique_id "amm_BQVDiGi-ktKYT-I05AAAAM4"]
[Wed Jul 29 10:51:17.676532 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file88.php"] [unique_id "amm_BQVDiGi-ktKYT-I05AAAAM4"]
[Wed Jul 29 10:51:18.142471 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/7.php"] [unique_id "amm_BgVDiGi-ktKYT-I05gAAANc"]
[Wed Jul 29 10:51:18.143181 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/7.php"] [unique_id "amm_BgVDiGi-ktKYT-I05gAAANc"]
[Wed Jul 29 10:51:18.143485 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/7.php"] [unique_id "amm_BgVDiGi-ktKYT-I05gAAANc"]
[Wed Jul 29 10:51:18.143571 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/7.php"] [unique_id "amm_BgVDiGi-ktKYT-I05gAAANc"]
[Wed Jul 29 10:51:18.237507 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/size.php"] [unique_id "amm_BgVDiGi-ktKYT-I06AAAAM8"]
[Wed Jul 29 10:51:18.238162 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/size.php"] [unique_id "amm_BgVDiGi-ktKYT-I06AAAAM8"]
[Wed Jul 29 10:51:18.238480 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/size.php"] [unique_id "amm_BgVDiGi-ktKYT-I06AAAAM8"]
[Wed Jul 29 10:51:18.238601 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/size.php"] [unique_id "amm_BgVDiGi-ktKYT-I06AAAAM8"]
[Wed Jul 29 10:51:18.658517 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bolt.php"] [unique_id "amm_BgVDiGi-ktKYT-I07gAAAMo"]
[Wed Jul 29 10:51:18.659577 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bolt.php"] [unique_id "amm_BgVDiGi-ktKYT-I07gAAAMo"]
[Wed Jul 29 10:51:18.660020 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bolt.php"] [unique_id "amm_BgVDiGi-ktKYT-I07gAAAMo"]
[Wed Jul 29 10:51:18.660108 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bolt.php"] [unique_id "amm_BgVDiGi-ktKYT-I07gAAAMo"]
[Wed Jul 29 10:51:19.043224 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file8.php"] [unique_id "amm_BwVDiGi-ktKYT-I08QAAANM"]
[Wed Jul 29 10:51:19.044264 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file8.php"] [unique_id "amm_BwVDiGi-ktKYT-I08QAAANM"]
[Wed Jul 29 10:51:19.044689 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file8.php"] [unique_id "amm_BwVDiGi-ktKYT-I08QAAANM"]
[Wed Jul 29 10:51:19.044774 2026] [:error] [pid 29913:tid 139878956197632] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file8.php"] [unique_id "amm_BwVDiGi-ktKYT-I08QAAANM"]
[Wed Jul 29 10:51:19.171405 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file2.php"] [unique_id "amm_BwVDiGi-ktKYT-I08wAAAM4"]
[Wed Jul 29 10:51:19.172433 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file2.php"] [unique_id "amm_BwVDiGi-ktKYT-I08wAAAM4"]
[Wed Jul 29 10:51:19.172855 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file2.php"] [unique_id "amm_BwVDiGi-ktKYT-I08wAAAM4"]
[Wed Jul 29 10:51:19.172965 2026] [:error] [pid 29913:tid 139878998161152] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file2.php"] [unique_id "amm_BwVDiGi-ktKYT-I08wAAAM4"]
[Wed Jul 29 10:51:19.586134 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/vee.php"] [unique_id "amm_BwVDiGi-ktKYT-I09wAAAMo"]
[Wed Jul 29 10:51:19.586932 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/vee.php"] [unique_id "amm_BwVDiGi-ktKYT-I09wAAAMo"]
[Wed Jul 29 10:51:19.587226 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/vee.php"] [unique_id "amm_BwVDiGi-ktKYT-I09wAAAMo"]
[Wed Jul 29 10:51:19.587284 2026] [:error] [pid 29913:tid 139879031731968] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/vee.php"] [unique_id "amm_BwVDiGi-ktKYT-I09wAAAMo"]
[Wed Jul 29 10:51:19.691535 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/a2.php"] [unique_id "amm_BwVDiGi-ktKYT-I0-AAAAME"]
[Wed Jul 29 10:51:19.692367 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/a2.php"] [unique_id "amm_BwVDiGi-ktKYT-I0-AAAAME"]
[Wed Jul 29 10:51:19.692778 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/a2.php"] [unique_id "amm_BwVDiGi-ktKYT-I0-AAAAME"]
[Wed Jul 29 10:51:19.692876 2026] [:error] [pid 29913:tid 139879177004800] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/a2.php"] [unique_id "amm_BwVDiGi-ktKYT-I0-AAAAME"]
[Wed Jul 29 10:51:19.844421 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xxa.php"] [unique_id "amm_BwVDiGi-ktKYT-I0-gAAANI"]
[Wed Jul 29 10:51:19.845244 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xxa.php"] [unique_id "amm_BwVDiGi-ktKYT-I0-gAAANI"]
[Wed Jul 29 10:51:19.845577 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/xxa.php"] [unique_id "amm_BwVDiGi-ktKYT-I0-gAAANI"]
[Wed Jul 29 10:51:19.845651 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xxa.php"] [unique_id "amm_BwVDiGi-ktKYT-I0-gAAANI"]
[Wed Jul 29 10:51:20.235972 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mlex.php"] [unique_id "amm_CAVDiGi-ktKYT-I0-wAAAM0"]
[Wed Jul 29 10:51:20.236933 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mlex.php"] [unique_id "amm_CAVDiGi-ktKYT-I0-wAAAM0"]
[Wed Jul 29 10:51:20.237311 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/mlex.php"] [unique_id "amm_CAVDiGi-ktKYT-I0-wAAAM0"]
[Wed Jul 29 10:51:20.237421 2026] [:error] [pid 29913:tid 139879006553856] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mlex.php"] [unique_id "amm_CAVDiGi-ktKYT-I0-wAAAM0"]
[Wed Jul 29 10:51:20.787767 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/030.php"] [unique_id "amm_CAVDiGi-ktKYT-I1AAAAAM8"]
[Wed Jul 29 10:51:20.788451 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/030.php"] [unique_id "amm_CAVDiGi-ktKYT-I1AAAAAM8"]
[Wed Jul 29 10:51:20.788773 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/030.php"] [unique_id "amm_CAVDiGi-ktKYT-I1AAAAAM8"]
[Wed Jul 29 10:51:20.788839 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/030.php"] [unique_id "amm_CAVDiGi-ktKYT-I1AAAAAM8"]
[Wed Jul 29 10:51:21.168315 2026] [:error] [pid 29913:tid 139879023339264] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/haa.php"] [unique_id "amm_CQVDiGi-ktKYT-I1AgAAAMs"]
[Wed Jul 29 10:51:21.168945 2026] [:error] [pid 29913:tid 139879023339264] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/haa.php"] [unique_id "amm_CQVDiGi-ktKYT-I1AgAAAMs"]
[Wed Jul 29 10:51:21.169205 2026] [:error] [pid 29913:tid 139879023339264] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/haa.php"] [unique_id "amm_CQVDiGi-ktKYT-I1AgAAAMs"]
[Wed Jul 29 10:51:21.169262 2026] [:error] [pid 29913:tid 139879023339264] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/haa.php"] [unique_id "amm_CQVDiGi-ktKYT-I1AgAAAMs"]
[Wed Jul 29 10:51:21.336164 2026] [:error] [pid 29913:tid 139878914234112] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/xsox.php"] [unique_id "amm_CQVDiGi-ktKYT-I1AwAAANg"]
[Wed Jul 29 10:51:21.336747 2026] [:error] [pid 29913:tid 139878914234112] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/xsox.php"] [unique_id "amm_CQVDiGi-ktKYT-I1AwAAANg"]
[Wed Jul 29 10:51:21.337002 2026] [:error] [pid 29913:tid 139878914234112] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/xsox.php"] [unique_id "amm_CQVDiGi-ktKYT-I1AwAAANg"]
[Wed Jul 29 10:51:21.337051 2026] [:error] [pid 29913:tid 139878914234112] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/xsox.php"] [unique_id "amm_CQVDiGi-ktKYT-I1AwAAANg"]
[Wed Jul 29 10:51:21.434008 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/classgoto24.php"] [unique_id "amm_CQVDiGi-ktKYT-I1BAAAANI"]
[Wed Jul 29 10:51:21.434891 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/classgoto24.php"] [unique_id "amm_CQVDiGi-ktKYT-I1BAAAANI"]
[Wed Jul 29 10:51:21.435284 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/classgoto24.php"] [unique_id "amm_CQVDiGi-ktKYT-I1BAAAANI"]
[Wed Jul 29 10:51:21.435395 2026] [:error] [pid 29913:tid 139878964590336] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/classgoto24.php"] [unique_id "amm_CQVDiGi-ktKYT-I1BAAAANI"]
[Wed Jul 29 10:51:21.533863 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/inde.php"] [unique_id "amm_CQVDiGi-ktKYT-I1BgAAANc"]
[Wed Jul 29 10:51:21.534769 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/inde.php"] [unique_id "amm_CQVDiGi-ktKYT-I1BgAAANc"]
[Wed Jul 29 10:51:21.535147 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/inde.php"] [unique_id "amm_CQVDiGi-ktKYT-I1BgAAANc"]
[Wed Jul 29 10:51:21.535213 2026] [:error] [pid 29913:tid 139878922626816] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/inde.php"] [unique_id "amm_CQVDiGi-ktKYT-I1BgAAANc"]
[Wed Jul 29 10:51:21.635903 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/akk.php"] [unique_id "amm_CQVDiGi-ktKYT-I1BwAAANU"]
[Wed Jul 29 10:51:21.636531 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/akk.php"] [unique_id "amm_CQVDiGi-ktKYT-I1BwAAANU"]
[Wed Jul 29 10:51:21.636857 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/akk.php"] [unique_id "amm_CQVDiGi-ktKYT-I1BwAAANU"]
[Wed Jul 29 10:51:21.636914 2026] [:error] [pid 29913:tid 139878939412224] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/akk.php"] [unique_id "amm_CQVDiGi-ktKYT-I1BwAAANU"]
[Wed Jul 29 10:51:21.775452 2026] [:error] [pid 29913:tid 139878981375744] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/alpa.php"] [unique_id "amm_CQVDiGi-ktKYT-I1CQAAANA"]
[Wed Jul 29 10:51:21.776334 2026] [:error] [pid 29913:tid 139878981375744] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/alpa.php"] [unique_id "amm_CQVDiGi-ktKYT-I1CQAAANA"]
[Wed Jul 29 10:51:21.776693 2026] [:error] [pid 29913:tid 139878981375744] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/alpa.php"] [unique_id "amm_CQVDiGi-ktKYT-I1CQAAANA"]
[Wed Jul 29 10:51:21.776765 2026] [:error] [pid 29913:tid 139878981375744] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/alpa.php"] [unique_id "amm_CQVDiGi-ktKYT-I1CQAAANA"]
[Wed Jul 29 10:51:21.855940 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/finny.php"] [unique_id "amm_CQVDiGi-ktKYT-I1CgAAAMA"]
[Wed Jul 29 10:51:21.856925 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/finny.php"] [unique_id "amm_CQVDiGi-ktKYT-I1CgAAAMA"]
[Wed Jul 29 10:51:21.857237 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/finny.php"] [unique_id "amm_CQVDiGi-ktKYT-I1CgAAAMA"]
[Wed Jul 29 10:51:21.857301 2026] [:error] [pid 29913:tid 139879185397504] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/finny.php"] [unique_id "amm_CQVDiGi-ktKYT-I1CgAAAMA"]
[Wed Jul 29 10:51:21.945740 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file15.php"] [unique_id "amm_CQVDiGi-ktKYT-I1CwAAAMw"]
[Wed Jul 29 10:51:21.946875 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file15.php"] [unique_id "amm_CQVDiGi-ktKYT-I1CwAAAMw"]
[Wed Jul 29 10:51:21.947287 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file15.php"] [unique_id "amm_CQVDiGi-ktKYT-I1CwAAAMw"]
[Wed Jul 29 10:51:21.947382 2026] [:error] [pid 29913:tid 139879014946560] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file15.php"] [unique_id "amm_CQVDiGi-ktKYT-I1CwAAAMw"]
[Wed Jul 29 10:51:22.044925 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/0x0x.php"] [unique_id "amm_CgVDiGi-ktKYT-I1DAAAAM8"]
[Wed Jul 29 10:51:22.045972 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/0x0x.php"] [unique_id "amm_CgVDiGi-ktKYT-I1DAAAAM8"]
[Wed Jul 29 10:51:22.046390 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/0x0x.php"] [unique_id "amm_CgVDiGi-ktKYT-I1DAAAAM8"]
[Wed Jul 29 10:51:22.046487 2026] [:error] [pid 29913:tid 139878989768448] [client 188.114.111.226:11867] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/0x0x.php"] [unique_id "amm_CgVDiGi-ktKYT-I1DAAAAM8"]
[Wed Jul 29 10:51:22.237932 2026] [:error] [pid 12728:tid 139878939412224] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/2clas.php"] [unique_id "amm_CjqdFZ1TNKvQdY23zQAAAVU"]
[Wed Jul 29 10:51:22.238963 2026] [:error] [pid 12728:tid 139878939412224] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/2clas.php"] [unique_id "amm_CjqdFZ1TNKvQdY23zQAAAVU"]
[Wed Jul 29 10:51:22.239374 2026] [:error] [pid 12728:tid 139878939412224] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/2clas.php"] [unique_id "amm_CjqdFZ1TNKvQdY23zQAAAVU"]
[Wed Jul 29 10:51:22.239459 2026] [:error] [pid 12728:tid 139878939412224] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/2clas.php"] [unique_id "amm_CjqdFZ1TNKvQdY23zQAAAVU"]
[Wed Jul 29 10:51:22.333994 2026] [:error] [pid 12728:tid 139878914234112] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/file9.php"] [unique_id "amm_CjqdFZ1TNKvQdY23zgAAAVg"]
[Wed Jul 29 10:51:22.334645 2026] [:error] [pid 12728:tid 139878914234112] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/file9.php"] [unique_id "amm_CjqdFZ1TNKvQdY23zgAAAVg"]
[Wed Jul 29 10:51:22.334918 2026] [:error] [pid 12728:tid 139878914234112] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/file9.php"] [unique_id "amm_CjqdFZ1TNKvQdY23zgAAAVg"]
[Wed Jul 29 10:51:22.334970 2026] [:error] [pid 12728:tid 139878914234112] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/file9.php"] [unique_id "amm_CjqdFZ1TNKvQdY23zgAAAVg"]
[Wed Jul 29 10:51:24.047214 2026] [:error] [pid 12728:tid 139878998161152] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/aaa.php"] [unique_id "amm_DDqdFZ1TNKvQdY230AAAAU4"]
[Wed Jul 29 10:51:24.048136 2026] [:error] [pid 12728:tid 139878998161152] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/aaa.php"] [unique_id "amm_DDqdFZ1TNKvQdY230AAAAU4"]
[Wed Jul 29 10:51:24.048565 2026] [:error] [pid 12728:tid 139878998161152] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/aaa.php"] [unique_id "amm_DDqdFZ1TNKvQdY230AAAAU4"]
[Wed Jul 29 10:51:24.048658 2026] [:error] [pid 12728:tid 139878998161152] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/aaa.php"] [unique_id "amm_DDqdFZ1TNKvQdY230AAAAU4"]
[Wed Jul 29 10:51:24.144366 2026] [:error] [pid 12728:tid 139879065302784] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "amm_DDqdFZ1TNKvQdY230QAAAUY"]
[Wed Jul 29 10:51:24.145123 2026] [:error] [pid 12728:tid 139879065302784] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "amm_DDqdFZ1TNKvQdY230QAAAUY"]
[Wed Jul 29 10:51:24.145530 2026] [:error] [pid 12728:tid 139879065302784] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "amm_DDqdFZ1TNKvQdY230QAAAUY"]
[Wed Jul 29 10:51:24.145633 2026] [:error] [pid 12728:tid 139879065302784] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "amm_DDqdFZ1TNKvQdY230QAAAUY"]
[Wed Jul 29 10:51:24.242474 2026] [:error] [pid 12728:tid 139879031731968] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/js/"] [unique_id "amm_DDqdFZ1TNKvQdY230gAAAUo"]
[Wed Jul 29 10:51:24.243123 2026] [:error] [pid 12728:tid 139879031731968] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/js/"] [unique_id "amm_DDqdFZ1TNKvQdY230gAAAUo"]
[Wed Jul 29 10:51:24.243376 2026] [:error] [pid 12728:tid 139879031731968] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/js/"] [unique_id "amm_DDqdFZ1TNKvQdY230gAAAUo"]
[Wed Jul 29 10:51:24.243439 2026] [:error] [pid 12728:tid 139879031731968] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/js/"] [unique_id "amm_DDqdFZ1TNKvQdY230gAAAUo"]
[Wed Jul 29 10:51:24.342690 2026] [:error] [pid 12728:tid 139879090480896] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/"] [unique_id "amm_DDqdFZ1TNKvQdY230wAAAUM"]
[Wed Jul 29 10:51:24.343218 2026] [:error] [pid 12728:tid 139879090480896] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/"] [unique_id "amm_DDqdFZ1TNKvQdY230wAAAUM"]
[Wed Jul 29 10:51:24.343466 2026] [:error] [pid 12728:tid 139879090480896] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/"] [unique_id "amm_DDqdFZ1TNKvQdY230wAAAUM"]
[Wed Jul 29 10:51:24.343535 2026] [:error] [pid 12728:tid 139879090480896] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/"] [unique_id "amm_DDqdFZ1TNKvQdY230wAAAUM"]
[Wed Jul 29 10:51:24.440456 2026] [:error] [pid 12728:tid 139878947804928] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "amm_DDqdFZ1TNKvQdY231AAAAVQ"]
[Wed Jul 29 10:51:24.441299 2026] [:error] [pid 12728:tid 139878947804928] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "amm_DDqdFZ1TNKvQdY231AAAAVQ"]
[Wed Jul 29 10:51:24.441701 2026] [:error] [pid 12728:tid 139878947804928] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "amm_DDqdFZ1TNKvQdY231AAAAVQ"]
[Wed Jul 29 10:51:24.441778 2026] [:error] [pid 12728:tid 139878947804928] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "amm_DDqdFZ1TNKvQdY231AAAAVQ"]
[Wed Jul 29 10:51:25.146076 2026] [:error] [pid 12728:tid 139879082088192] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/pucci.php"] [unique_id "amm_DTqdFZ1TNKvQdY231gAAAUQ"]
[Wed Jul 29 10:51:25.146958 2026] [:error] [pid 12728:tid 139879082088192] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/pucci.php"] [unique_id "amm_DTqdFZ1TNKvQdY231gAAAUQ"]
[Wed Jul 29 10:51:25.147334 2026] [:error] [pid 12728:tid 139879082088192] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/pucci.php"] [unique_id "amm_DTqdFZ1TNKvQdY231gAAAUQ"]
[Wed Jul 29 10:51:25.147420 2026] [:error] [pid 12728:tid 139879082088192] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/pucci.php"] [unique_id "amm_DTqdFZ1TNKvQdY231gAAAUQ"]
[Wed Jul 29 10:51:25.242634 2026] [:error] [pid 12728:tid 139879014946560] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/details/"] [unique_id "amm_DTqdFZ1TNKvQdY232AAAAUw"]
[Wed Jul 29 10:51:25.243450 2026] [:error] [pid 12728:tid 139879014946560] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/details/"] [unique_id "amm_DTqdFZ1TNKvQdY232AAAAUw"]
[Wed Jul 29 10:51:25.243782 2026] [:error] [pid 12728:tid 139879014946560] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/details/"] [unique_id "amm_DTqdFZ1TNKvQdY232AAAAUw"]
[Wed Jul 29 10:51:25.243860 2026] [:error] [pid 12728:tid 139879014946560] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/details/"] [unique_id "amm_DTqdFZ1TNKvQdY232AAAAUw"]
[Wed Jul 29 10:51:25.334427 2026] [:error] [pid 12728:tid 139879040124672] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "amm_DTqdFZ1TNKvQdY232QAAAUk"]
[Wed Jul 29 10:51:25.335297 2026] [:error] [pid 12728:tid 139879040124672] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "amm_DTqdFZ1TNKvQdY232QAAAUk"]
[Wed Jul 29 10:51:25.335731 2026] [:error] [pid 12728:tid 139879040124672] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "amm_DTqdFZ1TNKvQdY232QAAAUk"]
[Wed Jul 29 10:51:25.335817 2026] [:error] [pid 12728:tid 139879040124672] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "amm_DTqdFZ1TNKvQdY232QAAAUk"]
[Wed Jul 29 10:51:25.442776 2026] [:error] [pid 12728:tid 139878922626816] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/100.php"] [unique_id "amm_DTqdFZ1TNKvQdY232gAAAVc"]
[Wed Jul 29 10:51:25.443408 2026] [:error] [pid 12728:tid 139878922626816] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/100.php"] [unique_id "amm_DTqdFZ1TNKvQdY232gAAAVc"]
[Wed Jul 29 10:51:25.443714 2026] [:error] [pid 12728:tid 139878922626816] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/100.php"] [unique_id "amm_DTqdFZ1TNKvQdY232gAAAVc"]
[Wed Jul 29 10:51:25.443769 2026] [:error] [pid 12728:tid 139878922626816] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/100.php"] [unique_id "amm_DTqdFZ1TNKvQdY232gAAAVc"]
[Wed Jul 29 10:51:25.538857 2026] [:error] [pid 12728:tid 139878956197632] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/"] [unique_id "amm_DTqdFZ1TNKvQdY233QAAAVM"]
[Wed Jul 29 10:51:25.539753 2026] [:error] [pid 12728:tid 139878956197632] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/"] [unique_id "amm_DTqdFZ1TNKvQdY233QAAAVM"]
[Wed Jul 29 10:51:25.540064 2026] [:error] [pid 12728:tid 139878956197632] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/"] [unique_id "amm_DTqdFZ1TNKvQdY233QAAAVM"]
[Wed Jul 29 10:51:25.540119 2026] [:error] [pid 12728:tid 139878956197632] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/l10n/"] [unique_id "amm_DTqdFZ1TNKvQdY233QAAAVM"]
[Wed Jul 29 10:51:25.641730 2026] [:error] [pid 12728:tid 139878931019520] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/uploads/"] [unique_id "amm_DTqdFZ1TNKvQdY233gAAAVY"]
[Wed Jul 29 10:51:25.642456 2026] [:error] [pid 12728:tid 139878931019520] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/uploads/"] [unique_id "amm_DTqdFZ1TNKvQdY233gAAAVY"]
[Wed Jul 29 10:51:25.642822 2026] [:error] [pid 12728:tid 139878931019520] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/uploads/"] [unique_id "amm_DTqdFZ1TNKvQdY233gAAAVY"]
[Wed Jul 29 10:51:25.642911 2026] [:error] [pid 12728:tid 139878931019520] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-content/uploads/"] [unique_id "amm_DTqdFZ1TNKvQdY233gAAAVY"]
[Wed Jul 29 10:51:26.236137 2026] [:error] [pid 12728:tid 139878939412224] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/cgi-bin/index.php"] [unique_id "amm_DjqdFZ1TNKvQdY233wAAAVU"]
[Wed Jul 29 10:51:26.236979 2026] [:error] [pid 12728:tid 139878939412224] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/cgi-bin/index.php"] [unique_id "amm_DjqdFZ1TNKvQdY233wAAAVU"]
[Wed Jul 29 10:51:26.237358 2026] [:error] [pid 12728:tid 139878939412224] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/cgi-bin/index.php"] [unique_id "amm_DjqdFZ1TNKvQdY233wAAAVU"]
[Wed Jul 29 10:51:26.237441 2026] [:error] [pid 12728:tid 139878939412224] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/cgi-bin/index.php"] [unique_id "amm_DjqdFZ1TNKvQdY233wAAAVU"]
[Wed Jul 29 10:51:26.555798 2026] [:error] [pid 12728:tid 139879048517376] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css/dist/"] [unique_id "amm_DjqdFZ1TNKvQdY234AAAAUg"]
[Wed Jul 29 10:51:26.556424 2026] [:error] [pid 12728:tid 139879048517376] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css/dist/"] [unique_id "amm_DjqdFZ1TNKvQdY234AAAAUg"]
[Wed Jul 29 10:51:26.556714 2026] [:error] [pid 12728:tid 139879048517376] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css/dist/"] [unique_id "amm_DjqdFZ1TNKvQdY234AAAAUg"]
[Wed Jul 29 10:51:26.556765 2026] [:error] [pid 12728:tid 139879048517376] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-includes/css/dist/"] [unique_id "amm_DjqdFZ1TNKvQdY234AAAAUg"]
[Wed Jul 29 10:51:26.634274 2026] [:error] [pid 12728:tid 139878998161152] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "amm_DjqdFZ1TNKvQdY234QAAAU4"]
[Wed Jul 29 10:51:26.634981 2026] [:error] [pid 12728:tid 139878998161152] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "amm_DjqdFZ1TNKvQdY234QAAAU4"]
[Wed Jul 29 10:51:26.635341 2026] [:error] [pid 12728:tid 139878998161152] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "amm_DjqdFZ1TNKvQdY234QAAAU4"]
[Wed Jul 29 10:51:26.635412 2026] [:error] [pid 12728:tid 139878998161152] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "amm_DjqdFZ1TNKvQdY234QAAAU4"]
[Wed Jul 29 10:51:26.744360 2026] [:error] [pid 12728:tid 139879065302784] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ilex.php"] [unique_id "amm_DjqdFZ1TNKvQdY234gAAAUY"]
[Wed Jul 29 10:51:26.745338 2026] [:error] [pid 12728:tid 139879065302784] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ilex.php"] [unique_id "amm_DjqdFZ1TNKvQdY234gAAAUY"]
[Wed Jul 29 10:51:26.745756 2026] [:error] [pid 12728:tid 139879065302784] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ilex.php"] [unique_id "amm_DjqdFZ1TNKvQdY234gAAAUY"]
[Wed Jul 29 10:51:26.745860 2026] [:error] [pid 12728:tid 139879065302784] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ilex.php"] [unique_id "amm_DjqdFZ1TNKvQdY234gAAAUY"]
[Wed Jul 29 10:51:27.253916 2026] [:error] [pid 12728:tid 139878964590336] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/tor.php"] [unique_id "amm_DzqdFZ1TNKvQdY235AAAAVI"]
[Wed Jul 29 10:51:27.255002 2026] [:error] [pid 12728:tid 139878964590336] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/tor.php"] [unique_id "amm_DzqdFZ1TNKvQdY235AAAAVI"]
[Wed Jul 29 10:51:27.255426 2026] [:error] [pid 12728:tid 139878964590336] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/tor.php"] [unique_id "amm_DzqdFZ1TNKvQdY235AAAAVI"]
[Wed Jul 29 10:51:27.255533 2026] [:error] [pid 12728:tid 139878964590336] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/tor.php"] [unique_id "amm_DzqdFZ1TNKvQdY235AAAAVI"]
[Wed Jul 29 10:51:27.345331 2026] [:error] [pid 12728:tid 139879090480896] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/klex.php"] [unique_id "amm_DzqdFZ1TNKvQdY235QAAAUM"]
[Wed Jul 29 10:51:27.346461 2026] [:error] [pid 12728:tid 139879090480896] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/klex.php"] [unique_id "amm_DzqdFZ1TNKvQdY235QAAAUM"]
[Wed Jul 29 10:51:27.346935 2026] [:error] [pid 12728:tid 139879090480896] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/klex.php"] [unique_id "amm_DzqdFZ1TNKvQdY235QAAAUM"]
[Wed Jul 29 10:51:27.347043 2026] [:error] [pid 12728:tid 139879090480896] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/klex.php"] [unique_id "amm_DzqdFZ1TNKvQdY235QAAAUM"]
[Wed Jul 29 10:51:27.435193 2026] [:error] [pid 12728:tid 139878947804928] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/shell1.php"] [unique_id "amm_DzqdFZ1TNKvQdY235gAAAVQ"]
[Wed Jul 29 10:51:27.436656 2026] [:error] [pid 12728:tid 139878947804928] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/shell1.php"] [unique_id "amm_DzqdFZ1TNKvQdY235gAAAVQ"]
[Wed Jul 29 10:51:27.437238 2026] [:error] [pid 12728:tid 139878947804928] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/shell1.php"] [unique_id "amm_DzqdFZ1TNKvQdY235gAAAVQ"]
[Wed Jul 29 10:51:27.437371 2026] [:error] [pid 12728:tid 139878947804928] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/shell1.php"] [unique_id "amm_DzqdFZ1TNKvQdY235gAAAVQ"]
[Wed Jul 29 10:51:27.751319 2026] [:error] [pid 12728:tid 139878972983040] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sec.php"] [unique_id "amm_DzqdFZ1TNKvQdY235wAAAVE"]
[Wed Jul 29 10:51:27.751946 2026] [:error] [pid 12728:tid 139878972983040] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sec.php"] [unique_id "amm_DzqdFZ1TNKvQdY235wAAAVE"]
[Wed Jul 29 10:51:27.752205 2026] [:error] [pid 12728:tid 139878972983040] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/sec.php"] [unique_id "amm_DzqdFZ1TNKvQdY235wAAAVE"]
[Wed Jul 29 10:51:27.752257 2026] [:error] [pid 12728:tid 139878972983040] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sec.php"] [unique_id "amm_DzqdFZ1TNKvQdY235wAAAVE"]
[Wed Jul 29 10:51:27.945810 2026] [:error] [pid 12728:tid 139879082088192] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/filesss.php"] [unique_id "amm_DzqdFZ1TNKvQdY236QAAAUQ"]
[Wed Jul 29 10:51:27.946395 2026] [:error] [pid 12728:tid 139879082088192] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/filesss.php"] [unique_id "amm_DzqdFZ1TNKvQdY236QAAAUQ"]
[Wed Jul 29 10:51:27.946708 2026] [:error] [pid 12728:tid 139879082088192] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/filesss.php"] [unique_id "amm_DzqdFZ1TNKvQdY236QAAAUQ"]
[Wed Jul 29 10:51:27.946775 2026] [:error] [pid 12728:tid 139879082088192] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/filesss.php"] [unique_id "amm_DzqdFZ1TNKvQdY236QAAAUQ"]
[Wed Jul 29 10:51:28.034519 2026] [:error] [pid 12728:tid 139879014946560] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ea.php"] [unique_id "amm_EDqdFZ1TNKvQdY236gAAAUw"]
[Wed Jul 29 10:51:28.035537 2026] [:error] [pid 12728:tid 139879014946560] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ea.php"] [unique_id "amm_EDqdFZ1TNKvQdY236gAAAUw"]
[Wed Jul 29 10:51:28.035924 2026] [:error] [pid 12728:tid 139879014946560] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ea.php"] [unique_id "amm_EDqdFZ1TNKvQdY236gAAAUw"]
[Wed Jul 29 10:51:28.036002 2026] [:error] [pid 12728:tid 139879014946560] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ea.php"] [unique_id "amm_EDqdFZ1TNKvQdY236gAAAUw"]
[Wed Jul 29 10:51:28.334027 2026] [:error] [pid 12728:tid 139879040124672] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gi.php"] [unique_id "amm_EDqdFZ1TNKvQdY236wAAAUk"]
[Wed Jul 29 10:51:28.334871 2026] [:error] [pid 12728:tid 139879040124672] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gi.php"] [unique_id "amm_EDqdFZ1TNKvQdY236wAAAUk"]
[Wed Jul 29 10:51:28.335296 2026] [:error] [pid 12728:tid 139879040124672] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/gi.php"] [unique_id "amm_EDqdFZ1TNKvQdY236wAAAUk"]
[Wed Jul 29 10:51:28.335397 2026] [:error] [pid 12728:tid 139879040124672] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gi.php"] [unique_id "amm_EDqdFZ1TNKvQdY236wAAAUk"]
[Wed Jul 29 10:51:28.944373 2026] [:error] [pid 12728:tid 139878981375744] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/10.php"] [unique_id "amm_EDqdFZ1TNKvQdY237QAAAVA"]
[Wed Jul 29 10:51:28.945037 2026] [:error] [pid 12728:tid 139878981375744] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/10.php"] [unique_id "amm_EDqdFZ1TNKvQdY237QAAAVA"]
[Wed Jul 29 10:51:28.945319 2026] [:error] [pid 12728:tid 139878981375744] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/10.php"] [unique_id "amm_EDqdFZ1TNKvQdY237QAAAVA"]
[Wed Jul 29 10:51:28.945377 2026] [:error] [pid 12728:tid 139878981375744] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/10.php"] [unique_id "amm_EDqdFZ1TNKvQdY237QAAAVA"]
[Wed Jul 29 10:51:29.044534 2026] [:error] [pid 12728:tid 139879023339264] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/11.php"] [unique_id "amm_ETqdFZ1TNKvQdY237gAAAUs"]
[Wed Jul 29 10:51:29.045082 2026] [:error] [pid 12728:tid 139879023339264] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/11.php"] [unique_id "amm_ETqdFZ1TNKvQdY237gAAAUs"]
[Wed Jul 29 10:51:29.045408 2026] [:error] [pid 12728:tid 139879023339264] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/11.php"] [unique_id "amm_ETqdFZ1TNKvQdY237gAAAUs"]
[Wed Jul 29 10:51:29.045513 2026] [:error] [pid 12728:tid 139879023339264] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/11.php"] [unique_id "amm_ETqdFZ1TNKvQdY237gAAAUs"]
[Wed Jul 29 10:51:29.138769 2026] [:error] [pid 12728:tid 139878956197632] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/12.php"] [unique_id "amm_ETqdFZ1TNKvQdY237wAAAVM"]
[Wed Jul 29 10:51:29.139430 2026] [:error] [pid 12728:tid 139878956197632] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/12.php"] [unique_id "amm_ETqdFZ1TNKvQdY237wAAAVM"]
[Wed Jul 29 10:51:29.139753 2026] [:error] [pid 12728:tid 139878956197632] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/12.php"] [unique_id "amm_ETqdFZ1TNKvQdY237wAAAVM"]
[Wed Jul 29 10:51:29.139811 2026] [:error] [pid 12728:tid 139878956197632] [client 188.114.111.226:12431] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/12.php"] [unique_id "amm_ETqdFZ1TNKvQdY237wAAAVM"]
[Wed Jul 29 10:51:29.234750 2026] [:error] [pid 32190:tid 139879090480896] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/13.php"] [unique_id "amm_EaGf2ExAGdIXvjPNRQAAAQM"]
[Wed Jul 29 10:51:29.235364 2026] [:error] [pid 32190:tid 139879090480896] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/13.php"] [unique_id "amm_EaGf2ExAGdIXvjPNRQAAAQM"]
[Wed Jul 29 10:51:29.235711 2026] [:error] [pid 32190:tid 139879090480896] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/13.php"] [unique_id "amm_EaGf2ExAGdIXvjPNRQAAAQM"]
[Wed Jul 29 10:51:29.235784 2026] [:error] [pid 32190:tid 139879090480896] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/13.php"] [unique_id "amm_EaGf2ExAGdIXvjPNRQAAAQM"]
[Wed Jul 29 10:51:29.485253 2026] [:error] [pid 32190:tid 139879048517376] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/hi.php"] [unique_id "amm_EaGf2ExAGdIXvjPNRgAAAQg"]
[Wed Jul 29 10:51:29.485846 2026] [:error] [pid 32190:tid 139879048517376] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/hi.php"] [unique_id "amm_EaGf2ExAGdIXvjPNRgAAAQg"]
[Wed Jul 29 10:51:29.486101 2026] [:error] [pid 32190:tid 139879048517376] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/hi.php"] [unique_id "amm_EaGf2ExAGdIXvjPNRgAAAQg"]
[Wed Jul 29 10:51:29.486154 2026] [:error] [pid 32190:tid 139879048517376] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/hi.php"] [unique_id "amm_EaGf2ExAGdIXvjPNRgAAAQg"]
[Wed Jul 29 10:51:29.555431 2026] [:error] [pid 32190:tid 139878989768448] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/v.php"] [unique_id "amm_EaGf2ExAGdIXvjPNRwAAAQ8"]
[Wed Jul 29 10:51:29.556317 2026] [:error] [pid 32190:tid 139878989768448] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/v.php"] [unique_id "amm_EaGf2ExAGdIXvjPNRwAAAQ8"]
[Wed Jul 29 10:51:29.556741 2026] [:error] [pid 32190:tid 139878989768448] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/v.php"] [unique_id "amm_EaGf2ExAGdIXvjPNRwAAAQ8"]
[Wed Jul 29 10:51:29.556831 2026] [:error] [pid 32190:tid 139878989768448] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/v.php"] [unique_id "amm_EaGf2ExAGdIXvjPNRwAAAQ8"]
[Wed Jul 29 10:51:29.641327 2026] [:error] [pid 32190:tid 139878947804928] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ar.php"] [unique_id "amm_EaGf2ExAGdIXvjPNSAAAARQ"]
[Wed Jul 29 10:51:29.641928 2026] [:error] [pid 32190:tid 139878947804928] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ar.php"] [unique_id "amm_EaGf2ExAGdIXvjPNSAAAARQ"]
[Wed Jul 29 10:51:29.642240 2026] [:error] [pid 32190:tid 139878947804928] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ar.php"] [unique_id "amm_EaGf2ExAGdIXvjPNSAAAARQ"]
[Wed Jul 29 10:51:29.642298 2026] [:error] [pid 32190:tid 139878947804928] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ar.php"] [unique_id "amm_EaGf2ExAGdIXvjPNSAAAARQ"]
[Wed Jul 29 10:51:30.296845 2026] [:error] [pid 32190:tid 139878964590336] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/chosen.php"] [unique_id "amm_EqGf2ExAGdIXvjPNSwAAARI"]
[Wed Jul 29 10:51:30.297728 2026] [:error] [pid 32190:tid 139878964590336] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/chosen.php"] [unique_id "amm_EqGf2ExAGdIXvjPNSwAAARI"]
[Wed Jul 29 10:51:30.298103 2026] [:error] [pid 32190:tid 139878964590336] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/chosen.php"] [unique_id "amm_EqGf2ExAGdIXvjPNSwAAARI"]
[Wed Jul 29 10:51:30.298183 2026] [:error] [pid 32190:tid 139878964590336] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/chosen.php"] [unique_id "amm_EqGf2ExAGdIXvjPNSwAAARI"]
[Wed Jul 29 10:51:30.744919 2026] [:error] [pid 32190:tid 139879073695488] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/155.php"] [unique_id "amm_EqGf2ExAGdIXvjPNTgAAAQU"]
[Wed Jul 29 10:51:30.745981 2026] [:error] [pid 32190:tid 139879073695488] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/155.php"] [unique_id "amm_EqGf2ExAGdIXvjPNTgAAAQU"]
[Wed Jul 29 10:51:30.746383 2026] [:error] [pid 32190:tid 139879073695488] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/155.php"] [unique_id "amm_EqGf2ExAGdIXvjPNTgAAAQU"]
[Wed Jul 29 10:51:30.746471 2026] [:error] [pid 32190:tid 139879073695488] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/155.php"] [unique_id "amm_EqGf2ExAGdIXvjPNTgAAAQU"]
[Wed Jul 29 10:51:30.834935 2026] [:error] [pid 32190:tid 139879014946560] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ppp.php"] [unique_id "amm_EqGf2ExAGdIXvjPNTwAAAQw"]
[Wed Jul 29 10:51:30.835756 2026] [:error] [pid 32190:tid 139879014946560] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ppp.php"] [unique_id "amm_EqGf2ExAGdIXvjPNTwAAAQw"]
[Wed Jul 29 10:51:30.836071 2026] [:error] [pid 32190:tid 139879014946560] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ppp.php"] [unique_id "amm_EqGf2ExAGdIXvjPNTwAAAQw"]
[Wed Jul 29 10:51:30.836141 2026] [:error] [pid 32190:tid 139879014946560] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ppp.php"] [unique_id "amm_EqGf2ExAGdIXvjPNTwAAAQw"]
[Wed Jul 29 10:51:30.944222 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/201.php"] [unique_id "amm_EqGf2ExAGdIXvjPNUAAAAQ0"]
[Wed Jul 29 10:51:30.944774 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/201.php"] [unique_id "amm_EqGf2ExAGdIXvjPNUAAAAQ0"]
[Wed Jul 29 10:51:30.945041 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/201.php"] [unique_id "amm_EqGf2ExAGdIXvjPNUAAAAQ0"]
[Wed Jul 29 10:51:30.945101 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/201.php"] [unique_id "amm_EqGf2ExAGdIXvjPNUAAAAQ0"]
[Wed Jul 29 10:51:31.044395 2026] [:error] [pid 32190:tid 139879082088192] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/install.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNUQAAAQQ"]
[Wed Jul 29 10:51:31.045104 2026] [:error] [pid 32190:tid 139879082088192] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/install.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNUQAAAQQ"]
[Wed Jul 29 10:51:31.045371 2026] [:error] [pid 32190:tid 139879082088192] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/install.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNUQAAAQQ"]
[Wed Jul 29 10:51:31.045424 2026] [:error] [pid 32190:tid 139879082088192] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/install.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNUQAAAQQ"]
[Wed Jul 29 10:51:31.345513 2026] [:error] [pid 32190:tid 139878981375744] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/max.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNUwAAARA"]
[Wed Jul 29 10:51:31.346588 2026] [:error] [pid 32190:tid 139878981375744] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/max.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNUwAAARA"]
[Wed Jul 29 10:51:31.347008 2026] [:error] [pid 32190:tid 139878981375744] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/max.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNUwAAARA"]
[Wed Jul 29 10:51:31.347104 2026] [:error] [pid 32190:tid 139878981375744] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/max.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNUwAAARA"]
[Wed Jul 29 10:51:31.567760 2026] [:error] [pid 32190:tid 139879177004800] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/1.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNVQAAAQE"]
[Wed Jul 29 10:51:31.568370 2026] [:error] [pid 32190:tid 139879177004800] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/1.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNVQAAAQE"]
[Wed Jul 29 10:51:31.568780 2026] [:error] [pid 32190:tid 139879177004800] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/1.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNVQAAAQE"]
[Wed Jul 29 10:51:31.568875 2026] [:error] [pid 32190:tid 139879177004800] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/1.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNVQAAAQE"]
[Wed Jul 29 10:51:31.687004 2026] [:error] [pid 32190:tid 139878939412224] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/bak.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNVgAAARU"]
[Wed Jul 29 10:51:31.688320 2026] [:error] [pid 32190:tid 139878939412224] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/bak.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNVgAAARU"]
[Wed Jul 29 10:51:31.688776 2026] [:error] [pid 32190:tid 139878939412224] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/bak.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNVgAAARU"]
[Wed Jul 29 10:51:31.688883 2026] [:error] [pid 32190:tid 139878939412224] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/bak.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNVgAAARU"]
[Wed Jul 29 10:51:31.857792 2026] [:error] [pid 32190:tid 139878989768448] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ini.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNWAAAAQ8"]
[Wed Jul 29 10:51:31.858481 2026] [:error] [pid 32190:tid 139878989768448] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ini.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNWAAAAQ8"]
[Wed Jul 29 10:51:31.858922 2026] [:error] [pid 32190:tid 139878989768448] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ini.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNWAAAAQ8"]
[Wed Jul 29 10:51:31.859005 2026] [:error] [pid 32190:tid 139878989768448] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ini.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNWAAAAQ8"]
[Wed Jul 29 10:51:31.952844 2026] [:error] [pid 32190:tid 139879056910080] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mail.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNWQAAAQc"]
[Wed Jul 29 10:51:31.953834 2026] [:error] [pid 32190:tid 139879056910080] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mail.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNWQAAAQc"]
[Wed Jul 29 10:51:31.954286 2026] [:error] [pid 32190:tid 139879056910080] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/mail.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNWQAAAQc"]
[Wed Jul 29 10:51:31.954385 2026] [:error] [pid 32190:tid 139879056910080] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mail.php"] [unique_id "amm_E6Gf2ExAGdIXvjPNWQAAAQc"]
[Wed Jul 29 10:51:32.648176 2026] [:error] [pid 32190:tid 139879185397504] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dlu.php"] [unique_id "amm_FKGf2ExAGdIXvjPNXgAAAQA"]
[Wed Jul 29 10:51:32.649244 2026] [:error] [pid 32190:tid 139879185397504] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dlu.php"] [unique_id "amm_FKGf2ExAGdIXvjPNXgAAAQA"]
[Wed Jul 29 10:51:32.649631 2026] [:error] [pid 32190:tid 139879185397504] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/dlu.php"] [unique_id "amm_FKGf2ExAGdIXvjPNXgAAAQA"]
[Wed Jul 29 10:51:32.649713 2026] [:error] [pid 32190:tid 139879185397504] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dlu.php"] [unique_id "amm_FKGf2ExAGdIXvjPNXgAAAQA"]
[Wed Jul 29 10:51:33.176278 2026] [:error] [pid 32190:tid 139878922626816] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/zde.php"] [unique_id "amm_FaGf2ExAGdIXvjPNYAAAARc"]
[Wed Jul 29 10:51:33.177238 2026] [:error] [pid 32190:tid 139878922626816] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/zde.php"] [unique_id "amm_FaGf2ExAGdIXvjPNYAAAARc"]
[Wed Jul 29 10:51:33.177674 2026] [:error] [pid 32190:tid 139878922626816] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/zde.php"] [unique_id "amm_FaGf2ExAGdIXvjPNYAAAARc"]
[Wed Jul 29 10:51:33.177764 2026] [:error] [pid 32190:tid 139878922626816] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/zde.php"] [unique_id "amm_FaGf2ExAGdIXvjPNYAAAARc"]
[Wed Jul 29 10:51:33.642526 2026] [:error] [pid 32190:tid 139879014946560] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ifm.php"] [unique_id "amm_FaGf2ExAGdIXvjPNYgAAAQw"]
[Wed Jul 29 10:51:33.643341 2026] [:error] [pid 32190:tid 139879014946560] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ifm.php"] [unique_id "amm_FaGf2ExAGdIXvjPNYgAAAQw"]
[Wed Jul 29 10:51:33.643741 2026] [:error] [pid 32190:tid 139879014946560] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ifm.php"] [unique_id "amm_FaGf2ExAGdIXvjPNYgAAAQw"]
[Wed Jul 29 10:51:33.643832 2026] [:error] [pid 32190:tid 139879014946560] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ifm.php"] [unique_id "amm_FaGf2ExAGdIXvjPNYgAAAQw"]
[Wed Jul 29 10:51:33.744773 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/redi.php"] [unique_id "amm_FaGf2ExAGdIXvjPNYwAAAQ0"]
[Wed Jul 29 10:51:33.745631 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/redi.php"] [unique_id "amm_FaGf2ExAGdIXvjPNYwAAAQ0"]
[Wed Jul 29 10:51:33.746021 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/redi.php"] [unique_id "amm_FaGf2ExAGdIXvjPNYwAAAQ0"]
[Wed Jul 29 10:51:33.746126 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/redi.php"] [unique_id "amm_FaGf2ExAGdIXvjPNYwAAAQ0"]
[Wed Jul 29 10:51:33.836436 2026] [:error] [pid 32190:tid 139878972983040] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fns.php"] [unique_id "amm_FaGf2ExAGdIXvjPNZAAAARE"]
[Wed Jul 29 10:51:33.837122 2026] [:error] [pid 32190:tid 139878972983040] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fns.php"] [unique_id "amm_FaGf2ExAGdIXvjPNZAAAARE"]
[Wed Jul 29 10:51:33.837482 2026] [:error] [pid 32190:tid 139878972983040] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fns.php"] [unique_id "amm_FaGf2ExAGdIXvjPNZAAAARE"]
[Wed Jul 29 10:51:33.837616 2026] [:error] [pid 32190:tid 139878972983040] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/fns.php"] [unique_id "amm_FaGf2ExAGdIXvjPNZAAAARE"]
[Wed Jul 29 10:51:33.982036 2026] [:error] [pid 32190:tid 139878981375744] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/pent.php"] [unique_id "amm_FaGf2ExAGdIXvjPNZQAAARA"]
[Wed Jul 29 10:51:33.982980 2026] [:error] [pid 32190:tid 139878981375744] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/pent.php"] [unique_id "amm_FaGf2ExAGdIXvjPNZQAAARA"]
[Wed Jul 29 10:51:33.983345 2026] [:error] [pid 32190:tid 139878981375744] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/pent.php"] [unique_id "amm_FaGf2ExAGdIXvjPNZQAAARA"]
[Wed Jul 29 10:51:33.983408 2026] [:error] [pid 32190:tid 139878981375744] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/pent.php"] [unique_id "amm_FaGf2ExAGdIXvjPNZQAAARA"]
[Wed Jul 29 10:51:34.076793 2026] [:error] [pid 32190:tid 139879023339264] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wsx.php"] [unique_id "amm_FqGf2ExAGdIXvjPNZwAAAQs"]
[Wed Jul 29 10:51:34.077696 2026] [:error] [pid 32190:tid 139879023339264] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wsx.php"] [unique_id "amm_FqGf2ExAGdIXvjPNZwAAAQs"]
[Wed Jul 29 10:51:34.078084 2026] [:error] [pid 32190:tid 139879023339264] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wsx.php"] [unique_id "amm_FqGf2ExAGdIXvjPNZwAAAQs"]
[Wed Jul 29 10:51:34.078178 2026] [:error] [pid 32190:tid 139879023339264] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wsx.php"] [unique_id "amm_FqGf2ExAGdIXvjPNZwAAAQs"]
[Wed Jul 29 10:51:34.256604 2026] [:error] [pid 32190:tid 139879177004800] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/r79.php"] [unique_id "amm_FqGf2ExAGdIXvjPNaAAAAQE"]
[Wed Jul 29 10:51:34.257442 2026] [:error] [pid 32190:tid 139879177004800] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/r79.php"] [unique_id "amm_FqGf2ExAGdIXvjPNaAAAAQE"]
[Wed Jul 29 10:51:34.257853 2026] [:error] [pid 32190:tid 139879177004800] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/r79.php"] [unique_id "amm_FqGf2ExAGdIXvjPNaAAAAQE"]
[Wed Jul 29 10:51:34.257937 2026] [:error] [pid 32190:tid 139879177004800] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/r79.php"] [unique_id "amm_FqGf2ExAGdIXvjPNaAAAAQE"]
[Wed Jul 29 10:51:34.645003 2026] [:error] [pid 32190:tid 139879056910080] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mpxct.php"] [unique_id "amm_FqGf2ExAGdIXvjPNawAAAQc"]
[Wed Jul 29 10:51:34.646037 2026] [:error] [pid 32190:tid 139879056910080] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mpxct.php"] [unique_id "amm_FqGf2ExAGdIXvjPNawAAAQc"]
[Wed Jul 29 10:51:34.646454 2026] [:error] [pid 32190:tid 139879056910080] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/mpxct.php"] [unique_id "amm_FqGf2ExAGdIXvjPNawAAAQc"]
[Wed Jul 29 10:51:34.646595 2026] [:error] [pid 32190:tid 139879056910080] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mpxct.php"] [unique_id "amm_FqGf2ExAGdIXvjPNawAAAQc"]
[Wed Jul 29 10:51:34.741080 2026] [:error] [pid 32190:tid 139879098873600] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/x3.php"] [unique_id "amm_FqGf2ExAGdIXvjPNbAAAAQI"]
[Wed Jul 29 10:51:34.742216 2026] [:error] [pid 32190:tid 139879098873600] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/x3.php"] [unique_id "amm_FqGf2ExAGdIXvjPNbAAAAQI"]
[Wed Jul 29 10:51:34.742720 2026] [:error] [pid 32190:tid 139879098873600] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/x3.php"] [unique_id "amm_FqGf2ExAGdIXvjPNbAAAAQI"]
[Wed Jul 29 10:51:34.742818 2026] [:error] [pid 32190:tid 139879098873600] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/x3.php"] [unique_id "amm_FqGf2ExAGdIXvjPNbAAAAQI"]
[Wed Jul 29 10:51:34.836911 2026] [:error] [pid 32190:tid 139878998161152] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wan.php"] [unique_id "amm_FqGf2ExAGdIXvjPNbQAAAQ4"]
[Wed Jul 29 10:51:34.837714 2026] [:error] [pid 32190:tid 139878998161152] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wan.php"] [unique_id "amm_FqGf2ExAGdIXvjPNbQAAAQ4"]
[Wed Jul 29 10:51:34.838123 2026] [:error] [pid 32190:tid 139878998161152] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wan.php"] [unique_id "amm_FqGf2ExAGdIXvjPNbQAAAQ4"]
[Wed Jul 29 10:51:34.838222 2026] [:error] [pid 32190:tid 139878998161152] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wan.php"] [unique_id "amm_FqGf2ExAGdIXvjPNbQAAAQ4"]
[Wed Jul 29 10:51:34.935702 2026] [:error] [pid 32190:tid 139879185397504] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/iov.php"] [unique_id "amm_FqGf2ExAGdIXvjPNbwAAAQA"]
[Wed Jul 29 10:51:34.936720 2026] [:error] [pid 32190:tid 139879185397504] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/iov.php"] [unique_id "amm_FqGf2ExAGdIXvjPNbwAAAQA"]
[Wed Jul 29 10:51:34.937167 2026] [:error] [pid 32190:tid 139879185397504] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/iov.php"] [unique_id "amm_FqGf2ExAGdIXvjPNbwAAAQA"]
[Wed Jul 29 10:51:34.937259 2026] [:error] [pid 32190:tid 139879185397504] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/iov.php"] [unique_id "amm_FqGf2ExAGdIXvjPNbwAAAQA"]
[Wed Jul 29 10:51:35.534679 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/RsR.php"] [unique_id "amm_F6Gf2ExAGdIXvjPNdAAAAQ0"]
[Wed Jul 29 10:51:35.535668 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/RsR.php"] [unique_id "amm_F6Gf2ExAGdIXvjPNdAAAAQ0"]
[Wed Jul 29 10:51:35.536052 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/RsR.php"] [unique_id "amm_F6Gf2ExAGdIXvjPNdAAAAQ0"]
[Wed Jul 29 10:51:35.536130 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/RsR.php"] [unique_id "amm_F6Gf2ExAGdIXvjPNdAAAAQ0"]
[Wed Jul 29 10:51:35.644882 2026] [:error] [pid 32190:tid 139878972983040] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ouh.php"] [unique_id "amm_F6Gf2ExAGdIXvjPNdQAAARE"]
[Wed Jul 29 10:51:35.645837 2026] [:error] [pid 32190:tid 139878972983040] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ouh.php"] [unique_id "amm_F6Gf2ExAGdIXvjPNdQAAARE"]
[Wed Jul 29 10:51:35.646235 2026] [:error] [pid 32190:tid 139878972983040] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ouh.php"] [unique_id "amm_F6Gf2ExAGdIXvjPNdQAAARE"]
[Wed Jul 29 10:51:35.646332 2026] [:error] [pid 32190:tid 139878972983040] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ouh.php"] [unique_id "amm_F6Gf2ExAGdIXvjPNdQAAARE"]
[Wed Jul 29 10:51:35.736062 2026] [:error] [pid 32190:tid 139878914234112] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/133.php"] [unique_id "amm_F6Gf2ExAGdIXvjPNdgAAARg"]
[Wed Jul 29 10:51:35.736571 2026] [:error] [pid 32190:tid 139878914234112] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/133.php"] [unique_id "amm_F6Gf2ExAGdIXvjPNdgAAARg"]
[Wed Jul 29 10:51:35.736840 2026] [:error] [pid 32190:tid 139878914234112] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/133.php"] [unique_id "amm_F6Gf2ExAGdIXvjPNdgAAARg"]
[Wed Jul 29 10:51:35.736905 2026] [:error] [pid 32190:tid 139878914234112] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/133.php"] [unique_id "amm_F6Gf2ExAGdIXvjPNdgAAARg"]
[Wed Jul 29 10:51:36.095996 2026] [:error] [pid 32190:tid 139878947804928] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/x0.php"] [unique_id "amm_GKGf2ExAGdIXvjPNeAAAARQ"]
[Wed Jul 29 10:51:36.154741 2026] [:error] [pid 32190:tid 139878947804928] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/x0.php"] [unique_id "amm_GKGf2ExAGdIXvjPNeAAAARQ"]
[Wed Jul 29 10:51:36.155083 2026] [:error] [pid 32190:tid 139878947804928] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/x0.php"] [unique_id "amm_GKGf2ExAGdIXvjPNeAAAARQ"]
[Wed Jul 29 10:51:36.155157 2026] [:error] [pid 32190:tid 139878947804928] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/x0.php"] [unique_id "amm_GKGf2ExAGdIXvjPNeAAAARQ"]
[Wed Jul 29 10:51:36.261405 2026] [:error] [pid 32190:tid 139879177004800] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wsr2.php"] [unique_id "amm_GKGf2ExAGdIXvjPNeQAAAQE"]
[Wed Jul 29 10:51:36.262033 2026] [:error] [pid 32190:tid 139879177004800] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wsr2.php"] [unique_id "amm_GKGf2ExAGdIXvjPNeQAAAQE"]
[Wed Jul 29 10:51:36.262302 2026] [:error] [pid 32190:tid 139879177004800] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wsr2.php"] [unique_id "amm_GKGf2ExAGdIXvjPNeQAAAQE"]
[Wed Jul 29 10:51:36.262354 2026] [:error] [pid 32190:tid 139879177004800] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wsr2.php"] [unique_id "amm_GKGf2ExAGdIXvjPNeQAAAQE"]
[Wed Jul 29 10:51:36.334389 2026] [:error] [pid 32190:tid 139878931019520] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/hq.php"] [unique_id "amm_GKGf2ExAGdIXvjPNegAAARY"]
[Wed Jul 29 10:51:36.335196 2026] [:error] [pid 32190:tid 139878931019520] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/hq.php"] [unique_id "amm_GKGf2ExAGdIXvjPNegAAARY"]
[Wed Jul 29 10:51:36.335606 2026] [:error] [pid 32190:tid 139878931019520] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/hq.php"] [unique_id "amm_GKGf2ExAGdIXvjPNegAAARY"]
[Wed Jul 29 10:51:36.335689 2026] [:error] [pid 32190:tid 139878931019520] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/hq.php"] [unique_id "amm_GKGf2ExAGdIXvjPNegAAARY"]
[Wed Jul 29 10:51:36.941129 2026] [:error] [pid 32190:tid 139878998161152] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/blox.php"] [unique_id "amm_GKGf2ExAGdIXvjPNfAAAAQ4"]
[Wed Jul 29 10:51:36.941884 2026] [:error] [pid 32190:tid 139878998161152] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/blox.php"] [unique_id "amm_GKGf2ExAGdIXvjPNfAAAAQ4"]
[Wed Jul 29 10:51:36.942300 2026] [:error] [pid 32190:tid 139878998161152] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/blox.php"] [unique_id "amm_GKGf2ExAGdIXvjPNfAAAAQ4"]
[Wed Jul 29 10:51:36.942394 2026] [:error] [pid 32190:tid 139878998161152] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/blox.php"] [unique_id "amm_GKGf2ExAGdIXvjPNfAAAAQ4"]
[Wed Jul 29 10:51:37.035155 2026] [:error] [pid 32190:tid 139879065302784] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ant.php"] [unique_id "amm_GaGf2ExAGdIXvjPNfgAAAQY"]
[Wed Jul 29 10:51:37.036356 2026] [:error] [pid 32190:tid 139879065302784] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ant.php"] [unique_id "amm_GaGf2ExAGdIXvjPNfgAAAQY"]
[Wed Jul 29 10:51:37.036929 2026] [:error] [pid 32190:tid 139879065302784] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/ant.php"] [unique_id "amm_GaGf2ExAGdIXvjPNfgAAAQY"]
[Wed Jul 29 10:51:37.037037 2026] [:error] [pid 32190:tid 139879065302784] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ant.php"] [unique_id "amm_GaGf2ExAGdIXvjPNfgAAAQY"]
[Wed Jul 29 10:51:37.140225 2026] [:error] [pid 32190:tid 139879090480896] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/fso.php"] [unique_id "amm_GaGf2ExAGdIXvjPNgAAAAQM"]
[Wed Jul 29 10:51:37.140994 2026] [:error] [pid 32190:tid 139879090480896] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/fso.php"] [unique_id "amm_GaGf2ExAGdIXvjPNgAAAAQM"]
[Wed Jul 29 10:51:37.141350 2026] [:error] [pid 32190:tid 139879090480896] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/fso.php"] [unique_id "amm_GaGf2ExAGdIXvjPNgAAAAQM"]
[Wed Jul 29 10:51:37.141461 2026] [:error] [pid 32190:tid 139879090480896] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/fso.php"] [unique_id "amm_GaGf2ExAGdIXvjPNgAAAAQM"]
[Wed Jul 29 10:51:37.236044 2026] [:error] [pid 32190:tid 139879031731968] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-content/admin.php"] [unique_id "amm_GaGf2ExAGdIXvjPNgQAAAQo"]
[Wed Jul 29 10:51:37.241106 2026] [:error] [pid 32190:tid 139879031731968] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-content/admin.php"] [unique_id "amm_GaGf2ExAGdIXvjPNgQAAAQo"]
[Wed Jul 29 10:51:37.244197 2026] [:error] [pid 32190:tid 139879031731968] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/wp-content/admin.php"] [unique_id "amm_GaGf2ExAGdIXvjPNgQAAAQo"]
[Wed Jul 29 10:51:37.244320 2026] [:error] [pid 32190:tid 139879031731968] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-content/admin.php"] [unique_id "amm_GaGf2ExAGdIXvjPNgQAAAQo"]
[Wed Jul 29 10:51:37.306997 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/2P.php"] [unique_id "amm_GaGf2ExAGdIXvjPNgwAAAQ0"]
[Wed Jul 29 10:51:37.308162 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/2P.php"] [unique_id "amm_GaGf2ExAGdIXvjPNgwAAAQ0"]
[Wed Jul 29 10:51:37.308663 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1281"] [id "920320"] [msg "Missing User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "sbf-consultancy.com"] [uri "/2P.php"] [unique_id "amm_GaGf2ExAGdIXvjPNgwAAAQ0"]
[Wed Jul 29 10:51:37.308766 2026] [:error] [pid 32190:tid 139879006553856] [client 188.114.111.227:11111] [client 188.114.111.227] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/2P.php"] [unique_id "amm_GaGf2ExAGdIXvjPNgwAAAQ0"]
[Wed Jul 29 11:05:57.558733 2026] [:error] [pid 29817:tid 139879090480896] [client 104.23.239.17:10051] [client 104.23.239.17] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amnCdYpuIafV02klyJI42gAAAEM"]
[Wed Jul 29 11:05:57.559669 2026] [:error] [pid 29817:tid 139879090480896] [client 104.23.239.17:10051] [client 104.23.239.17] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amnCdYpuIafV02klyJI42gAAAEM"]
[Wed Jul 29 11:05:57.560257 2026] [:error] [pid 29817:tid 139879090480896] [client 104.23.239.17:10051] [client 104.23.239.17] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amnCdYpuIafV02klyJI42gAAAEM"]
[Wed Jul 29 11:14:09.760629 2026] [:error] [pid 29913:tid 139879090480896] [client 104.22.24.171:12220] [client 104.22.24.171] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amnEYQVDiGi-ktKYT-JIPgAAAMM"]
[Wed Jul 29 11:14:09.761630 2026] [:error] [pid 29913:tid 139879090480896] [client 104.22.24.171:12220] [client 104.22.24.171] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amnEYQVDiGi-ktKYT-JIPgAAAMM"]
[Wed Jul 29 11:14:09.762160 2026] [:error] [pid 29913:tid 139879090480896] [client 104.22.24.171:12220] [client 104.22.24.171] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amnEYQVDiGi-ktKYT-JIPgAAAMM"]
[Wed Jul 29 11:14:10.355577 2026] [:error] [pid 32190:tid 139879031731968] [client 104.22.24.56:10022] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnEYqGf2ExAGdIXvjPYxQAAAQo"]
[Wed Jul 29 11:14:10.356403 2026] [:error] [pid 32190:tid 139879031731968] [client 104.22.24.56:10022] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnEYqGf2ExAGdIXvjPYxQAAAQo"]
[Wed Jul 29 11:14:10.356948 2026] [:error] [pid 32190:tid 139879031731968] [client 104.22.24.56:10022] [client 104.22.24.56] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:From outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:From=googlebot(at)googlebot.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnEYqGf2ExAGdIXvjPYxQAAAQo"]
[Wed Jul 29 11:14:10.357034 2026] [:error] [pid 32190:tid 139879031731968] [client 104.22.24.56:10022] [client 104.22.24.56] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnEYqGf2ExAGdIXvjPYxQAAAQo"]
[Wed Jul 29 11:27:17.170241 2026] [:error] [pid 12782:tid 139879031731968] [client 104.22.24.56:11418] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnHdUFdlBZRl6Abom3hfwAAAco"]
[Wed Jul 29 11:27:17.171015 2026] [:error] [pid 12782:tid 139879031731968] [client 104.22.24.56:11418] [client 104.22.24.56] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnHdUFdlBZRl6Abom3hfwAAAco"]
[Wed Jul 29 11:27:17.171430 2026] [:error] [pid 12782:tid 139879031731968] [client 104.22.24.56:11418] [client 104.22.24.56] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:From outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:From=googlebot(at)googlebot.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnHdUFdlBZRl6Abom3hfwAAAco"]
[Wed Jul 29 11:27:17.171484 2026] [:error] [pid 12782:tid 139879031731968] [client 104.22.24.56:11418] [client 104.22.24.56] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnHdUFdlBZRl6Abom3hfwAAAco"]
[Wed Jul 29 11:27:17.975631 2026] [:error] [pid 29817:tid 139879040124672] [client 104.22.57.45:10871] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnHdYpuIafV02klyJJA5gAAAEk"]
[Wed Jul 29 11:27:17.976417 2026] [:error] [pid 29817:tid 139879040124672] [client 104.22.57.45:10871] [client 104.22.57.45] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnHdYpuIafV02klyJJA5gAAAEk"]
[Wed Jul 29 11:27:17.977012 2026] [:error] [pid 29817:tid 139879040124672] [client 104.22.57.45:10871] [client 104.22.57.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:From outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:From=googlebot(at)googlebot.com"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnHdYpuIafV02klyJJA5gAAAEk"]
[Wed Jul 29 11:27:17.977056 2026] [:error] [pid 29817:tid 139879040124672] [client 104.22.57.45:10871] [client 104.22.57.45] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnHdYpuIafV02klyJJA5gAAAEk"]
[Wed Jul 29 11:38:40.434488 2026] [:error] [pid 12782:tid 139878939412224] [client 104.23.243.18:12517] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amnKIEFdlBZRl6Abom3lqgAAAdU"]
[Wed Jul 29 11:38:40.461833 2026] [:error] [pid 12782:tid 139878939412224] [client 104.23.243.18:12517] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amnKIEFdlBZRl6Abom3lqgAAAdU"]
[Wed Jul 29 11:38:40.462233 2026] [:error] [pid 12782:tid 139878939412224] [client 104.23.243.18:12517] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amnKIEFdlBZRl6Abom3lqgAAAdU"]
[Wed Jul 29 11:38:47.356667 2026] [:error] [pid 29913:tid 139878989768448] [client 172.70.248.24:12779] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amnKJwVDiGi-ktKYT-JVOAAAAM8"]
[Wed Jul 29 11:38:47.357593 2026] [:error] [pid 29913:tid 139878989768448] [client 172.70.248.24:12779] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amnKJwVDiGi-ktKYT-JVOAAAAM8"]
[Wed Jul 29 11:38:47.358192 2026] [:error] [pid 29913:tid 139878989768448] [client 172.70.248.24:12779] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amnKJwVDiGi-ktKYT-JVOAAAAM8"]
[Wed Jul 29 11:38:47.448859 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amnKJ6Gf2ExAGdIXvjPibgAAAQ8"]
[Wed Jul 29 11:38:47.449590 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amnKJ6Gf2ExAGdIXvjPibgAAAQ8"]
[Wed Jul 29 11:38:47.450062 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amnKJ6Gf2ExAGdIXvjPibgAAAQ8"]
[Wed Jul 29 11:38:47.450288 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/config"] [unique_id "amnKJ6Gf2ExAGdIXvjPibgAAAQ8"]
[Wed Jul 29 11:38:47.562906 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amnKJ6Gf2ExAGdIXvjPicAAAARY"]
[Wed Jul 29 11:38:47.563915 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "POST"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amnKJ6Gf2ExAGdIXvjPicAAAARY"]
[Wed Jul 29 11:38:47.564210 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "956"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|application/x-www-form-urlencoded|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amnKJ6Gf2ExAGdIXvjPicAAAARY"]
[Wed Jul 29 11:38:47.564609 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amnKJ6Gf2ExAGdIXvjPicAAAARY"]
[Wed Jul 29 11:38:47.644817 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amnKJ6Gf2ExAGdIXvjPicgAAAQM"]
[Wed Jul 29 11:38:47.645951 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amnKJ6Gf2ExAGdIXvjPicgAAAQM"]
[Wed Jul 29 11:38:47.646730 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amnKJ6Gf2ExAGdIXvjPicgAAAQM"]
[Wed Jul 29 11:38:47.646982 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env"] [unique_id "amnKJ6Gf2ExAGdIXvjPicgAAAQM"]
[Wed Jul 29 11:38:47.686051 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amnKJ6Gf2ExAGdIXvjPicwAAARg"]
[Wed Jul 29 11:38:47.686847 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amnKJ6Gf2ExAGdIXvjPicwAAARg"]
[Wed Jul 29 11:38:47.687326 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amnKJ6Gf2ExAGdIXvjPicwAAARg"]
[Wed Jul 29 11:38:47.687488 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.local"] [unique_id "amnKJ6Gf2ExAGdIXvjPicwAAARg"]
[Wed Jul 29 11:38:47.759038 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amnKJ6Gf2ExAGdIXvjPidAAAAQU"]
[Wed Jul 29 11:38:47.760431 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amnKJ6Gf2ExAGdIXvjPidAAAAQU"]
[Wed Jul 29 11:38:47.761207 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amnKJ6Gf2ExAGdIXvjPidAAAAQU"]
[Wed Jul 29 11:38:47.761435 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.production"] [unique_id "amnKJ6Gf2ExAGdIXvjPidAAAAQU"]
[Wed Jul 29 11:38:47.795680 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amnKJ6Gf2ExAGdIXvjPidQAAARI"]
[Wed Jul 29 11:38:47.796532 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amnKJ6Gf2ExAGdIXvjPidQAAARI"]
[Wed Jul 29 11:38:47.797067 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amnKJ6Gf2ExAGdIXvjPidQAAARI"]
[Wed Jul 29 11:38:47.797257 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.staging"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.staging"] [unique_id "amnKJ6Gf2ExAGdIXvjPidQAAARI"]
[Wed Jul 29 11:38:47.875752 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amnKJ6Gf2ExAGdIXvjPidgAAAQs"]
[Wed Jul 29 11:38:47.876697 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amnKJ6Gf2ExAGdIXvjPidgAAAQs"]
[Wed Jul 29 11:38:47.877268 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amnKJ6Gf2ExAGdIXvjPidgAAAQs"]
[Wed Jul 29 11:38:47.877524 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.development"] [unique_id "amnKJ6Gf2ExAGdIXvjPidgAAAQs"]
[Wed Jul 29 11:38:47.934466 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amnKJ6Gf2ExAGdIXvjPidwAAARM"]
[Wed Jul 29 11:38:47.935366 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amnKJ6Gf2ExAGdIXvjPidwAAARM"]
[Wed Jul 29 11:38:47.936076 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amnKJ6Gf2ExAGdIXvjPidwAAARM"]
[Wed Jul 29 11:38:47.936332 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.test"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.test"] [unique_id "amnKJ6Gf2ExAGdIXvjPidwAAARM"]
[Wed Jul 29 11:38:48.052429 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "amnKKKGf2ExAGdIXvjPieAAAARQ"]
[Wed Jul 29 11:38:48.053074 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "amnKKKGf2ExAGdIXvjPieAAAARQ"]
[Wed Jul 29 11:38:48.053449 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "amnKKKGf2ExAGdIXvjPieAAAARQ"]
[Wed Jul 29 11:38:48.053614 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.remote"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.remote"] [unique_id "amnKKKGf2ExAGdIXvjPieAAAARQ"]
[Wed Jul 29 11:38:48.084991 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amnKKKGf2ExAGdIXvjPieQAAARc"]
[Wed Jul 29 11:38:48.085672 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amnKKKGf2ExAGdIXvjPieQAAARc"]
[Wed Jul 29 11:38:48.086283 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amnKKKGf2ExAGdIXvjPieQAAARc"]
[Wed Jul 29 11:38:48.086583 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.bak"] [unique_id "amnKKKGf2ExAGdIXvjPieQAAARc"]
[Wed Jul 29 11:38:48.135439 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amnKKKGf2ExAGdIXvjPiegAAAQE"]
[Wed Jul 29 11:38:48.136333 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amnKKKGf2ExAGdIXvjPiegAAAQE"]
[Wed Jul 29 11:38:48.136874 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amnKKKGf2ExAGdIXvjPiegAAAQE"]
[Wed Jul 29 11:38:48.137076 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup"] [unique_id "amnKKKGf2ExAGdIXvjPiegAAAQE"]
[Wed Jul 29 11:38:48.169621 2026] [:error] [pid 32190:tid 139879006553856] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amnKKKGf2ExAGdIXvjPiewAAAQ0"]
[Wed Jul 29 11:38:48.170413 2026] [:error] [pid 32190:tid 139879006553856] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amnKKKGf2ExAGdIXvjPiewAAAQ0"]
[Wed Jul 29 11:38:48.170993 2026] [:error] [pid 32190:tid 139879006553856] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amnKKKGf2ExAGdIXvjPiewAAAQ0"]
[Wed Jul 29 11:38:48.171227 2026] [:error] [pid 32190:tid 139879006553856] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.save"] [unique_id "amnKKKGf2ExAGdIXvjPiewAAAQ0"]
[Wed Jul 29 11:38:48.246138 2026] [:error] [pid 32190:tid 139879185397504] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amnKKKGf2ExAGdIXvjPifAAAAQA"]
[Wed Jul 29 11:38:48.247006 2026] [:error] [pid 32190:tid 139879185397504] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amnKKKGf2ExAGdIXvjPifAAAAQA"]
[Wed Jul 29 11:38:48.247572 2026] [:error] [pid 32190:tid 139879185397504] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amnKKKGf2ExAGdIXvjPifAAAAQA"]
[Wed Jul 29 11:38:48.247824 2026] [:error] [pid 32190:tid 139879185397504] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.old"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.old"] [unique_id "amnKKKGf2ExAGdIXvjPifAAAAQA"]
[Wed Jul 29 11:38:48.283690 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amnKKKGf2ExAGdIXvjPifQAAAQc"]
[Wed Jul 29 11:38:48.284509 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amnKKKGf2ExAGdIXvjPifQAAAQc"]
[Wed Jul 29 11:38:48.285097 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amnKKKGf2ExAGdIXvjPifQAAAQc"]
[Wed Jul 29 11:38:48.285331 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.sample"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.sample"] [unique_id "amnKKKGf2ExAGdIXvjPifQAAAQc"]
[Wed Jul 29 11:38:48.341641 2026] [:error] [pid 32190:tid 139879040124672] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amnKKKGf2ExAGdIXvjPifgAAAQk"]
[Wed Jul 29 11:38:48.342610 2026] [:error] [pid 32190:tid 139879040124672] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amnKKKGf2ExAGdIXvjPifgAAAQk"]
[Wed Jul 29 11:38:48.343210 2026] [:error] [pid 32190:tid 139879040124672] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amnKKKGf2ExAGdIXvjPifgAAAQk"]
[Wed Jul 29 11:38:48.343459 2026] [:error] [pid 32190:tid 139879040124672] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.example"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.example"] [unique_id "amnKKKGf2ExAGdIXvjPifgAAAQk"]
[Wed Jul 29 11:38:48.379901 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amnKKKGf2ExAGdIXvjPigAAAARA"]
[Wed Jul 29 11:38:48.380598 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amnKKKGf2ExAGdIXvjPigAAAARA"]
[Wed Jul 29 11:38:48.381083 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amnKKKGf2ExAGdIXvjPigAAAARA"]
[Wed Jul 29 11:38:48.381236 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dev"] [unique_id "amnKKKGf2ExAGdIXvjPigAAAARA"]
[Wed Jul 29 11:38:48.435402 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amnKKKGf2ExAGdIXvjPigQAAAQ8"]
[Wed Jul 29 11:38:48.436490 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amnKKKGf2ExAGdIXvjPigQAAAQ8"]
[Wed Jul 29 11:38:48.437052 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amnKKKGf2ExAGdIXvjPigQAAAQ8"]
[Wed Jul 29 11:38:48.437278 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.prod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.prod"] [unique_id "amnKKKGf2ExAGdIXvjPigQAAAQ8"]
[Wed Jul 29 11:38:48.466145 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amnKKKGf2ExAGdIXvjPiggAAARY"]
[Wed Jul 29 11:38:48.467113 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amnKKKGf2ExAGdIXvjPiggAAARY"]
[Wed Jul 29 11:38:48.467727 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amnKKKGf2ExAGdIXvjPiggAAARY"]
[Wed Jul 29 11:38:48.467971 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.stage"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.stage"] [unique_id "amnKKKGf2ExAGdIXvjPiggAAARY"]
[Wed Jul 29 11:38:48.544808 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "amnKKKGf2ExAGdIXvjPigwAAAQM"]
[Wed Jul 29 11:38:48.545837 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "amnKKKGf2ExAGdIXvjPigwAAAQM"]
[Wed Jul 29 11:38:48.546396 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "amnKKKGf2ExAGdIXvjPigwAAAQM"]
[Wed Jul 29 11:38:48.546632 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.ci"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.ci"] [unique_id "amnKKKGf2ExAGdIXvjPigwAAAQM"]
[Wed Jul 29 11:38:48.583884 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "amnKKKGf2ExAGdIXvjPihAAAARg"]
[Wed Jul 29 11:38:48.584811 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "amnKKKGf2ExAGdIXvjPihAAAARg"]
[Wed Jul 29 11:38:48.585386 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "amnKKKGf2ExAGdIXvjPihAAAARg"]
[Wed Jul 29 11:38:48.585664 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.docker"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.docker"] [unique_id "amnKKKGf2ExAGdIXvjPihAAAARg"]
[Wed Jul 29 11:38:48.644631 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amnKKKGf2ExAGdIXvjPihQAAAQU"]
[Wed Jul 29 11:38:48.645586 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amnKKKGf2ExAGdIXvjPihQAAAQU"]
[Wed Jul 29 11:38:48.646341 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amnKKKGf2ExAGdIXvjPihQAAAQU"]
[Wed Jul 29 11:38:48.646600 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.live"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.live"] [unique_id "amnKKKGf2ExAGdIXvjPihQAAAQU"]
[Wed Jul 29 11:38:48.684689 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "amnKKKGf2ExAGdIXvjPihgAAARI"]
[Wed Jul 29 11:38:48.685457 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "amnKKKGf2ExAGdIXvjPihgAAARI"]
[Wed Jul 29 11:38:48.685863 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "amnKKKGf2ExAGdIXvjPihgAAARI"]
[Wed Jul 29 11:38:48.686264 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.preprod"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.preprod"] [unique_id "amnKKKGf2ExAGdIXvjPihgAAARI"]
[Wed Jul 29 11:38:48.744618 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "amnKKKGf2ExAGdIXvjPihwAAAQs"]
[Wed Jul 29 11:38:48.745486 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "amnKKKGf2ExAGdIXvjPihwAAAQs"]
[Wed Jul 29 11:38:48.746054 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "amnKKKGf2ExAGdIXvjPihwAAAQs"]
[Wed Jul 29 11:38:48.746302 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.uat"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.uat"] [unique_id "amnKKKGf2ExAGdIXvjPihwAAAQs"]
[Wed Jul 29 11:38:48.776027 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amnKKKGf2ExAGdIXvjPiiAAAARM"]
[Wed Jul 29 11:38:48.776630 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amnKKKGf2ExAGdIXvjPiiAAAARM"]
[Wed Jul 29 11:38:48.777026 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amnKKKGf2ExAGdIXvjPiiAAAARM"]
[Wed Jul 29 11:38:48.777177 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.dist"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.dist"] [unique_id "amnKKKGf2ExAGdIXvjPiiAAAARM"]
[Wed Jul 29 11:38:48.839907 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amnKKKGf2ExAGdIXvjPiiQAAARQ"]
[Wed Jul 29 11:38:48.840805 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amnKKKGf2ExAGdIXvjPiiQAAARQ"]
[Wed Jul 29 11:38:48.841334 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amnKKKGf2ExAGdIXvjPiiQAAARQ"]
[Wed Jul 29 11:38:48.841588 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.swp"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.swp"] [unique_id "amnKKKGf2ExAGdIXvjPiiQAAARQ"]
[Wed Jul 29 11:38:48.873540 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amnKKKGf2ExAGdIXvjPiigAAARc"]
[Wed Jul 29 11:38:48.874151 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amnKKKGf2ExAGdIXvjPiigAAARc"]
[Wed Jul 29 11:38:48.874382 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Pattern match "\\\\.[^.~]+~(?:/.*|)$" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1060"] [id "920500"] [msg "Attempt to access a backup or working file"] [data ".env~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amnKKKGf2ExAGdIXvjPiigAAARc"]
[Wed Jul 29 11:38:48.874661 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amnKKKGf2ExAGdIXvjPiigAAARc"]
[Wed Jul 29 11:38:48.874828 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env~"] [unique_id "amnKKKGf2ExAGdIXvjPiigAAARc"]
[Wed Jul 29 11:38:48.944921 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env1"] [unique_id "amnKKKGf2ExAGdIXvjPiiwAAAQE"]
[Wed Jul 29 11:38:48.945501 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env1"] [unique_id "amnKKKGf2ExAGdIXvjPiiwAAAQE"]
[Wed Jul 29 11:38:48.946018 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env1"] [unique_id "amnKKKGf2ExAGdIXvjPiiwAAAQE"]
[Wed Jul 29 11:38:48.946278 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env1"] [unique_id "amnKKKGf2ExAGdIXvjPiiwAAAQE"]
[Wed Jul 29 11:38:48.990522 2026] [:error] [pid 32190:tid 139878939412224] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env2"] [unique_id "amnKKKGf2ExAGdIXvjPijAAAARU"]
[Wed Jul 29 11:38:48.991342 2026] [:error] [pid 32190:tid 139878939412224] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env2"] [unique_id "amnKKKGf2ExAGdIXvjPijAAAARU"]
[Wed Jul 29 11:38:48.991880 2026] [:error] [pid 32190:tid 139878939412224] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env2"] [unique_id "amnKKKGf2ExAGdIXvjPijAAAARU"]
[Wed Jul 29 11:38:48.992095 2026] [:error] [pid 32190:tid 139878939412224] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env2"] [unique_id "amnKKKGf2ExAGdIXvjPijAAAARU"]
[Wed Jul 29 11:38:49.049738 2026] [:error] [pid 32190:tid 139879006553856] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amnKKaGf2ExAGdIXvjPijQAAAQ0"]
[Wed Jul 29 11:38:49.050639 2026] [:error] [pid 32190:tid 139879006553856] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amnKKaGf2ExAGdIXvjPijQAAAQ0"]
[Wed Jul 29 11:38:49.051224 2026] [:error] [pid 32190:tid 139879006553856] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amnKKaGf2ExAGdIXvjPijQAAAQ0"]
[Wed Jul 29 11:38:49.051474 2026] [:error] [pid 32190:tid 139879006553856] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env_copy"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env_copy"] [unique_id "amnKKaGf2ExAGdIXvjPijQAAAQ0"]
[Wed Jul 29 11:38:49.145133 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amnKKaGf2ExAGdIXvjPijwAAAQc"]
[Wed Jul 29 11:38:49.146198 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amnKKaGf2ExAGdIXvjPijwAAAQc"]
[Wed Jul 29 11:38:49.146916 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amnKKaGf2ExAGdIXvjPijwAAAQc"]
[Wed Jul 29 11:38:49.147379 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.txt"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.txt"] [unique_id "amnKKaGf2ExAGdIXvjPijwAAAQc"]
[Wed Jul 29 11:38:49.180499 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.json"] [unique_id "amnKKaGf2ExAGdIXvjPikAAAARA"]
[Wed Jul 29 11:38:49.181348 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.json"] [unique_id "amnKKaGf2ExAGdIXvjPikAAAARA"]
[Wed Jul 29 11:38:49.181922 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.json"] [unique_id "amnKKaGf2ExAGdIXvjPikAAAARA"]
[Wed Jul 29 11:38:49.182149 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.json"] [unique_id "amnKKaGf2ExAGdIXvjPikAAAARA"]
[Wed Jul 29 11:38:49.282902 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "amnKKaGf2ExAGdIXvjPikgAAAQ8"]
[Wed Jul 29 11:38:49.283882 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "amnKKaGf2ExAGdIXvjPikgAAAQ8"]
[Wed Jul 29 11:38:49.284540 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "amnKKaGf2ExAGdIXvjPikgAAAQ8"]
[Wed Jul 29 11:38:49.284817 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yaml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yaml"] [unique_id "amnKKaGf2ExAGdIXvjPikgAAAQ8"]
[Wed Jul 29 11:38:49.344311 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "amnKKaGf2ExAGdIXvjPikwAAAQM"]
[Wed Jul 29 11:38:49.345115 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "amnKKaGf2ExAGdIXvjPikwAAAQM"]
[Wed Jul 29 11:38:49.345722 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "amnKKaGf2ExAGdIXvjPikwAAAQM"]
[Wed Jul 29 11:38:49.345945 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.yml"] [unique_id "amnKKaGf2ExAGdIXvjPikwAAAQM"]
[Wed Jul 29 11:38:49.384897 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilAAAARg"]
[Wed Jul 29 11:38:49.385720 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilAAAARg"]
[Wed Jul 29 11:38:49.386255 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilAAAARg"]
[Wed Jul 29 11:38:49.386418 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/app/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilAAAARg"]
[Wed Jul 29 11:38:49.438877 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilQAAAQU"]
[Wed Jul 29 11:38:49.439964 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilQAAAQU"]
[Wed Jul 29 11:38:49.440671 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilQAAAQU"]
[Wed Jul 29 11:38:49.441007 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /apps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/apps/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilQAAAQU"]
[Wed Jul 29 11:38:49.491112 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilgAAARI"]
[Wed Jul 29 11:38:49.492071 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilgAAARI"]
[Wed Jul 29 11:38:49.492669 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilgAAARI"]
[Wed Jul 29 11:38:49.492917 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/api/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilgAAARI"]
[Wed Jul 29 11:38:49.537845 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilwAAAQs"]
[Wed Jul 29 11:38:49.538501 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilwAAAQs"]
[Wed Jul 29 11:38:49.538957 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilwAAAQs"]
[Wed Jul 29 11:38:49.539109 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /web/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/web/.env"] [unique_id "amnKKaGf2ExAGdIXvjPilwAAAQs"]
[Wed Jul 29 11:38:49.577805 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/site/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimAAAARM"]
[Wed Jul 29 11:38:49.578979 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/site/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimAAAARM"]
[Wed Jul 29 11:38:49.579598 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/site/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimAAAARM"]
[Wed Jul 29 11:38:49.579862 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /site/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/site/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimAAAARM"]
[Wed Jul 29 11:38:49.634911 2026] [:error] [pid 32190:tid 139879065302784] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimQAAAQY"]
[Wed Jul 29 11:38:49.635860 2026] [:error] [pid 32190:tid 139879065302784] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimQAAAQY"]
[Wed Jul 29 11:38:49.636600 2026] [:error] [pid 32190:tid 139879065302784] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimQAAAQY"]
[Wed Jul 29 11:38:49.636883 2026] [:error] [pid 32190:tid 139879065302784] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/public/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimQAAAQY"]
[Wed Jul 29 11:38:49.667171 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimgAAARc"]
[Wed Jul 29 11:38:49.668103 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimgAAARc"]
[Wed Jul 29 11:38:49.668786 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimgAAARc"]
[Wed Jul 29 11:38:49.669026 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/admin/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimgAAARc"]
[Wed Jul 29 11:38:49.744941 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimwAAAQE"]
[Wed Jul 29 11:38:49.745985 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimwAAAQE"]
[Wed Jul 29 11:38:49.746637 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimwAAAQE"]
[Wed Jul 29 11:38:49.746905 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/backend/.env"] [unique_id "amnKKaGf2ExAGdIXvjPimwAAAQE"]
[Wed Jul 29 11:38:49.778605 2026] [:error] [pid 32190:tid 139878939412224] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amnKKaGf2ExAGdIXvjPinQAAARU"]
[Wed Jul 29 11:38:49.779545 2026] [:error] [pid 32190:tid 139878939412224] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amnKKaGf2ExAGdIXvjPinQAAARU"]
[Wed Jul 29 11:38:49.780338 2026] [:error] [pid 32190:tid 139878939412224] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amnKKaGf2ExAGdIXvjPinQAAARU"]
[Wed Jul 29 11:38:49.780570 2026] [:error] [pid 32190:tid 139878939412224] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /server/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/server/.env"] [unique_id "amnKKaGf2ExAGdIXvjPinQAAARU"]
[Wed Jul 29 11:38:50.055922 2026] [:error] [pid 32190:tid 139878998161152] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amnKKqGf2ExAGdIXvjPingAAAQ4"]
[Wed Jul 29 11:38:50.057031 2026] [:error] [pid 32190:tid 139878998161152] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amnKKqGf2ExAGdIXvjPingAAAQ4"]
[Wed Jul 29 11:38:50.057673 2026] [:error] [pid 32190:tid 139878998161152] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amnKKqGf2ExAGdIXvjPingAAAQ4"]
[Wed Jul 29 11:38:50.057973 2026] [:error] [pid 32190:tid 139878998161152] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /frontend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/frontend/.env"] [unique_id "amnKKqGf2ExAGdIXvjPingAAAQ4"]
[Wed Jul 29 11:38:50.091930 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amnKKqGf2ExAGdIXvjPinwAAAQc"]
[Wed Jul 29 11:38:50.092887 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amnKKqGf2ExAGdIXvjPinwAAAQc"]
[Wed Jul 29 11:38:50.093573 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amnKKqGf2ExAGdIXvjPinwAAAQc"]
[Wed Jul 29 11:38:50.093851 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /src/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/src/.env"] [unique_id "amnKKqGf2ExAGdIXvjPinwAAAQc"]
[Wed Jul 29 11:38:50.144793 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amnKKqGf2ExAGdIXvjPioAAAARA"]
[Wed Jul 29 11:38:50.145780 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amnKKqGf2ExAGdIXvjPioAAAARA"]
[Wed Jul 29 11:38:50.146380 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amnKKqGf2ExAGdIXvjPioAAAARA"]
[Wed Jul 29 11:38:50.146613 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/core/.env"] [unique_id "amnKKqGf2ExAGdIXvjPioAAAARA"]
[Wed Jul 29 11:38:50.182119 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "amnKKqGf2ExAGdIXvjPioQAAARY"]
[Wed Jul 29 11:38:50.182816 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "amnKKqGf2ExAGdIXvjPioQAAARY"]
[Wed Jul 29 11:38:50.183272 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "amnKKqGf2ExAGdIXvjPioQAAARY"]
[Wed Jul 29 11:38:50.183427 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/core/app/.env"] [unique_id "amnKKqGf2ExAGdIXvjPioQAAARY"]
[Wed Jul 29 11:38:50.235090 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiogAAAQ8"]
[Wed Jul 29 11:38:50.236390 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiogAAAQ8"]
[Wed Jul 29 11:38:50.237122 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiogAAAQ8"]
[Wed Jul 29 11:38:50.237382 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/config/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiogAAAQ8"]
[Wed Jul 29 11:38:50.282437 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipAAAAQM"]
[Wed Jul 29 11:38:50.283243 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipAAAAQM"]
[Wed Jul 29 11:38:50.283697 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipAAAAQM"]
[Wed Jul 29 11:38:50.283860 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /private/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/private/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipAAAAQM"]
[Wed Jul 29 11:38:50.345954 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipQAAARg"]
[Wed Jul 29 11:38:50.346943 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipQAAARg"]
[Wed Jul 29 11:38:50.347516 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipQAAARg"]
[Wed Jul 29 11:38:50.347781 2026] [:error] [pid 32190:tid 139878914234112] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /application/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/application/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipQAAARg"]
[Wed Jul 29 11:38:50.389522 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipgAAAQU"]
[Wed Jul 29 11:38:50.390610 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipgAAAQU"]
[Wed Jul 29 11:38:50.391147 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipgAAAQU"]
[Wed Jul 29 11:38:50.391303 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /bootstrap/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/bootstrap/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipgAAAQU"]
[Wed Jul 29 11:38:50.476613 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/database/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipwAAAQo"]
[Wed Jul 29 11:38:50.477583 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/database/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipwAAAQo"]
[Wed Jul 29 11:38:50.478225 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/database/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipwAAAQo"]
[Wed Jul 29 11:38:50.478509 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /database/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/database/.env"] [unique_id "amnKKqGf2ExAGdIXvjPipwAAAQo"]
[Wed Jul 29 11:38:50.534948 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiqAAAARI"]
[Wed Jul 29 11:38:50.535950 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiqAAAARI"]
[Wed Jul 29 11:38:50.536616 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiqAAAARI"]
[Wed Jul 29 11:38:50.536860 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /storage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/storage/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiqAAAARI"]
[Wed Jul 29 11:38:50.578989 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiqQAAAQs"]
[Wed Jul 29 11:38:50.579850 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiqQAAAQs"]
[Wed Jul 29 11:38:50.580441 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiqQAAAQs"]
[Wed Jul 29 11:38:50.580709 2026] [:error] [pid 32190:tid 139879023339264] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /var/www/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiqQAAAQs"]
[Wed Jul 29 11:38:50.635891 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiqwAAARQ"]
[Wed Jul 29 11:38:50.636689 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiqwAAARQ"]
[Wed Jul 29 11:38:50.637141 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiqwAAARQ"]
[Wed Jul 29 11:38:50.637334 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /var/www/html/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/var/www/html/.env"] [unique_id "amnKKqGf2ExAGdIXvjPiqwAAARQ"]
[Wed Jul 29 11:38:50.758088 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/current/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirAAAARc"]
[Wed Jul 29 11:38:50.759212 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/current/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirAAAARc"]
[Wed Jul 29 11:38:50.759868 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/current/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirAAAARc"]
[Wed Jul 29 11:38:50.760156 2026] [:error] [pid 32190:tid 139878922626816] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /current/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/current/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirAAAARc"]
[Wed Jul 29 11:38:50.834803 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/release/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirQAAAQE"]
[Wed Jul 29 11:38:50.836290 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/release/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirQAAAQE"]
[Wed Jul 29 11:38:50.837049 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/release/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirQAAAQE"]
[Wed Jul 29 11:38:50.837317 2026] [:error] [pid 32190:tid 139879177004800] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /release/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/release/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirQAAAQE"]
[Wed Jul 29 11:38:50.877370 2026] [:error] [pid 32190:tid 139878939412224] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirgAAARU"]
[Wed Jul 29 11:38:50.878408 2026] [:error] [pid 32190:tid 139878939412224] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirgAAARU"]
[Wed Jul 29 11:38:50.879073 2026] [:error] [pid 32190:tid 139878939412224] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirgAAARU"]
[Wed Jul 29 11:38:50.879302 2026] [:error] [pid 32190:tid 139878939412224] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /releases/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/releases/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirgAAARU"]
[Wed Jul 29 11:38:50.934218 2026] [:error] [pid 32190:tid 139878998161152] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirwAAAQ4"]
[Wed Jul 29 11:38:50.935013 2026] [:error] [pid 32190:tid 139878998161152] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirwAAAQ4"]
[Wed Jul 29 11:38:50.935529 2026] [:error] [pid 32190:tid 139878998161152] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirwAAAQ4"]
[Wed Jul 29 11:38:50.935738 2026] [:error] [pid 32190:tid 139878998161152] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /shared/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/shared/.env"] [unique_id "amnKKqGf2ExAGdIXvjPirwAAAQ4"]
[Wed Jul 29 11:38:50.963748 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "amnKKqGf2ExAGdIXvjPisAAAAQc"]
[Wed Jul 29 11:38:50.964833 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "amnKKqGf2ExAGdIXvjPisAAAAQc"]
[Wed Jul 29 11:38:50.965434 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "amnKKqGf2ExAGdIXvjPisAAAAQc"]
[Wed Jul 29 11:38:50.965638 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /deploy/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/deploy/.env"] [unique_id "amnKKqGf2ExAGdIXvjPisAAAAQc"]
[Wed Jul 29 11:38:50.997511 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/build/.env"] [unique_id "amnKKqGf2ExAGdIXvjPisQAAARA"]
[Wed Jul 29 11:38:50.998196 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/build/.env"] [unique_id "amnKKqGf2ExAGdIXvjPisQAAARA"]
[Wed Jul 29 11:38:50.998716 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/build/.env"] [unique_id "amnKKqGf2ExAGdIXvjPisQAAARA"]
[Wed Jul 29 11:38:50.998955 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /build/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/build/.env"] [unique_id "amnKKqGf2ExAGdIXvjPisQAAARA"]
[Wed Jul 29 11:38:51.046235 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "amnKK6Gf2ExAGdIXvjPisgAAARY"]
[Wed Jul 29 11:38:51.047105 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "amnKK6Gf2ExAGdIXvjPisgAAARY"]
[Wed Jul 29 11:38:51.047664 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "amnKK6Gf2ExAGdIXvjPisgAAARY"]
[Wed Jul 29 11:38:51.047927 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.2:11971] [client 172.70.248.2] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /dist/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/dist/.env"] [unique_id "amnKK6Gf2ExAGdIXvjPisgAAARY"]
[Wed Jul 29 11:38:51.144858 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OdgAAAUU"]
[Wed Jul 29 11:38:51.145499 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OdgAAAUU"]
[Wed Jul 29 11:38:51.146029 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OdgAAAUU"]
[Wed Jul 29 11:38:51.146250 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /public_html/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/public_html/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OdgAAAUU"]
[Wed Jul 29 11:38:51.178644 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OdwAAAUg"]
[Wed Jul 29 11:38:51.179340 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OdwAAAUg"]
[Wed Jul 29 11:38:51.179738 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OdwAAAUg"]
[Wed Jul 29 11:38:51.179917 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /htdocs/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/htdocs/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OdwAAAUg"]
[Wed Jul 29 11:38:51.253806 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/www/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OeQAAAVQ"]
[Wed Jul 29 11:38:51.254756 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/www/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OeQAAAVQ"]
[Wed Jul 29 11:38:51.255322 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/www/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OeQAAAVQ"]
[Wed Jul 29 11:38:51.255542 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /www/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/www/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OeQAAAVQ"]
[Wed Jul 29 11:38:51.294827 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/html/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OegAAAUo"]
[Wed Jul 29 11:38:51.295835 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/html/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OegAAAUo"]
[Wed Jul 29 11:38:51.296272 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/html/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OegAAAUo"]
[Wed Jul 29 11:38:51.296444 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /html/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/html/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OegAAAUo"]
[Wed Jul 29 11:38:51.374363 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/live/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OewAAAUc"]
[Wed Jul 29 11:38:51.374997 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/live/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OewAAAUc"]
[Wed Jul 29 11:38:51.375538 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/live/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OewAAAUc"]
[Wed Jul 29 11:38:51.375718 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /live/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/live/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OewAAAUc"]
[Wed Jul 29 11:38:51.437817 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfAAAAU8"]
[Wed Jul 29 11:38:51.438664 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfAAAAU8"]
[Wed Jul 29 11:38:51.439219 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfAAAAU8"]
[Wed Jul 29 11:38:51.439484 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prod/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/prod/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfAAAAU8"]
[Wed Jul 29 11:38:51.485717 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfQAAAVE"]
[Wed Jul 29 11:38:51.486497 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfQAAAVE"]
[Wed Jul 29 11:38:51.492828 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfQAAAVE"]
[Wed Jul 29 11:38:51.493094 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /dev/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/dev/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfQAAAVE"]
[Wed Jul 29 11:38:51.541964 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfgAAAUs"]
[Wed Jul 29 11:38:51.542539 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfgAAAUs"]
[Wed Jul 29 11:38:51.542960 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfgAAAUs"]
[Wed Jul 29 11:38:51.543112 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /staging/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/staging/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfgAAAUs"]
[Wed Jul 29 11:38:51.582191 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfwAAAU0"]
[Wed Jul 29 11:38:51.583480 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfwAAAU0"]
[Wed Jul 29 11:38:51.584669 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfwAAAU0"]
[Wed Jul 29 11:38:51.585028 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /opt/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/opt/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OfwAAAU0"]
[Wed Jul 29 11:38:51.650206 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OgAAAAUA"]
[Wed Jul 29 11:38:51.655157 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OgAAAAUA"]
[Wed Jul 29 11:38:51.656386 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OgAAAAUA"]
[Wed Jul 29 11:38:51.656965 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/laravel/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OgAAAAUA"]
[Wed Jul 29 11:38:51.696481 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OgQAAAVM"]
[Wed Jul 29 11:38:51.697399 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OgQAAAVM"]
[Wed Jul 29 11:38:51.697963 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OgQAAAVM"]
[Wed Jul 29 11:38:51.698206 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /symfony/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/symfony/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OgQAAAVM"]
[Wed Jul 29 11:38:51.745364 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OggAAAUw"]
[Wed Jul 29 11:38:51.751100 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OggAAAUw"]
[Wed Jul 29 11:38:51.754906 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OggAAAUw"]
[Wed Jul 29 11:38:51.755205 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wordpress/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/wordpress/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OggAAAUw"]
[Wed Jul 29 11:38:51.797660 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OgwAAAVI"]
[Wed Jul 29 11:38:51.798538 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OgwAAAVI"]
[Wed Jul 29 11:38:51.799111 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OgwAAAVI"]
[Wed Jul 29 11:38:51.799360 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /wp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/wp/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OgwAAAVI"]
[Wed Jul 29 11:38:51.853823 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OhAAAAUE"]
[Wed Jul 29 11:38:51.855276 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OhAAAAUE"]
[Wed Jul 29 11:38:51.855893 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OhAAAAUE"]
[Wed Jul 29 11:38:51.856181 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cms/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/cms/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OhAAAAUE"]
[Wed Jul 29 11:38:51.934763 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OhQAAAUI"]
[Wed Jul 29 11:38:51.935851 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OhQAAAUI"]
[Wed Jul 29 11:38:51.936371 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OhQAAAUI"]
[Wed Jul 29 11:38:51.936533 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /drupal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/drupal/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OhQAAAUI"]
[Wed Jul 29 11:38:51.973483 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OhgAAAUM"]
[Wed Jul 29 11:38:51.974302 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OhgAAAUM"]
[Wed Jul 29 11:38:51.974779 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OhgAAAUM"]
[Wed Jul 29 11:38:51.975024 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /joomla/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/joomla/.env"] [unique_id "amnKKzqdFZ1TNKvQdY3OhgAAAUM"]
[Wed Jul 29 11:38:52.041202 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OhwAAAVA"]
[Wed Jul 29 11:38:52.042568 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OhwAAAVA"]
[Wed Jul 29 11:38:52.043038 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OhwAAAVA"]
[Wed Jul 29 11:38:52.043211 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /magento/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/magento/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OhwAAAVA"]
[Wed Jul 29 11:38:52.183365 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OiQAAAVc"]
[Wed Jul 29 11:38:52.184698 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OiQAAAVc"]
[Wed Jul 29 11:38:52.185390 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OiQAAAVc"]
[Wed Jul 29 11:38:52.185735 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /shopify/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/shopify/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OiQAAAVc"]
[Wed Jul 29 11:38:52.249009 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OigAAAU4"]
[Wed Jul 29 11:38:52.250093 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OigAAAU4"]
[Wed Jul 29 11:38:52.250736 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OigAAAU4"]
[Wed Jul 29 11:38:52.250995 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /prestashop/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/prestashop/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OigAAAU4"]
[Wed Jul 29 11:38:52.291905 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OiwAAAUY"]
[Wed Jul 29 11:38:52.292889 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OiwAAAUY"]
[Wed Jul 29 11:38:52.293483 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OiwAAAUY"]
[Wed Jul 29 11:38:52.293750 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /codeigniter/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/codeigniter/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OiwAAAUY"]
[Wed Jul 29 11:38:52.334966 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjAAAAVg"]
[Wed Jul 29 11:38:52.335949 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjAAAAVg"]
[Wed Jul 29 11:38:52.336625 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjAAAAVg"]
[Wed Jul 29 11:38:52.337234 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cakephp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/cakephp/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjAAAAVg"]
[Wed Jul 29 11:38:52.380063 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjQAAAUU"]
[Wed Jul 29 11:38:52.381192 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjQAAAUU"]
[Wed Jul 29 11:38:52.381897 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjQAAAUU"]
[Wed Jul 29 11:38:52.382188 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /zend/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/zend/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjQAAAUU"]
[Wed Jul 29 11:38:52.444595 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjgAAAUg"]
[Wed Jul 29 11:38:52.445447 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjgAAAUg"]
[Wed Jul 29 11:38:52.445994 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjgAAAUg"]
[Wed Jul 29 11:38:52.446254 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /yii/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/yii/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjgAAAUg"]
[Wed Jul 29 11:38:52.489753 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjwAAAVQ"]
[Wed Jul 29 11:38:52.490645 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjwAAAVQ"]
[Wed Jul 29 11:38:52.491211 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjwAAAVQ"]
[Wed Jul 29 11:38:52.491462 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /laravel5/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/laravel5/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OjwAAAVQ"]
[Wed Jul 29 11:38:52.534807 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkAAAAUo"]
[Wed Jul 29 11:38:52.535747 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkAAAAUo"]
[Wed Jul 29 11:38:52.536397 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkAAAAUo"]
[Wed Jul 29 11:38:52.536681 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/v1/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkAAAAUo"]
[Wed Jul 29 11:38:52.574410 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkQAAAUc"]
[Wed Jul 29 11:38:52.575068 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkQAAAUc"]
[Wed Jul 29 11:38:52.575455 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkQAAAUc"]
[Wed Jul 29 11:38:52.575634 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/v2/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkQAAAUc"]
[Wed Jul 29 11:38:52.634578 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkgAAAU8"]
[Wed Jul 29 11:38:52.635421 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkgAAAU8"]
[Wed Jul 29 11:38:52.635991 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkgAAAU8"]
[Wed Jul 29 11:38:52.636236 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /v3/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/v3/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkgAAAU8"]
[Wed Jul 29 11:38:52.678741 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkwAAAVE"]
[Wed Jul 29 11:38:52.679579 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkwAAAVE"]
[Wed Jul 29 11:38:52.680137 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkwAAAVE"]
[Wed Jul 29 11:38:52.680364 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/v1/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/api/v1/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OkwAAAVE"]
[Wed Jul 29 11:38:52.755747 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlAAAAUs"]
[Wed Jul 29 11:38:52.756704 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlAAAAUs"]
[Wed Jul 29 11:38:52.757278 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlAAAAUs"]
[Wed Jul 29 11:38:52.757505 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/v2/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/api/v2/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlAAAAUs"]
[Wed Jul 29 11:38:52.834277 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlQAAAU0"]
[Wed Jul 29 11:38:52.835164 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlQAAAU0"]
[Wed Jul 29 11:38:52.835726 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlQAAAU0"]
[Wed Jul 29 11:38:52.835993 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /rest/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/rest/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlQAAAU0"]
[Wed Jul 29 11:38:52.878964 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlgAAAUA"]
[Wed Jul 29 11:38:52.879816 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlgAAAUA"]
[Wed Jul 29 11:38:52.880349 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlgAAAUA"]
[Wed Jul 29 11:38:52.880608 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /graphql/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/graphql/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlgAAAUA"]
[Wed Jul 29 11:38:52.953721 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlwAAAVM"]
[Wed Jul 29 11:38:52.954599 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlwAAAVM"]
[Wed Jul 29 11:38:52.955651 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlwAAAVM"]
[Wed Jul 29 11:38:52.955906 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /gateway/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/gateway/.env"] [unique_id "amnKLDqdFZ1TNKvQdY3OlwAAAVM"]
[Wed Jul 29 11:38:53.035363 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmAAAAUw"]
[Wed Jul 29 11:38:53.036298 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmAAAAUw"]
[Wed Jul 29 11:38:53.036886 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmAAAAUw"]
[Wed Jul 29 11:38:53.037146 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /microservice/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/microservice/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmAAAAUw"]
[Wed Jul 29 11:38:53.081668 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/service/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmQAAAVI"]
[Wed Jul 29 11:38:53.082506 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/service/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmQAAAVI"]
[Wed Jul 29 11:38:53.083060 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/service/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmQAAAVI"]
[Wed Jul 29 11:38:53.083325 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /service/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/service/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmQAAAVI"]
[Wed Jul 29 11:38:53.134875 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmgAAAUE"]
[Wed Jul 29 11:38:53.135762 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmgAAAUE"]
[Wed Jul 29 11:38:53.136311 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmgAAAUE"]
[Wed Jul 29 11:38:53.136572 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/v3/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/api/v3/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmgAAAUE"]
[Wed Jul 29 11:38:53.174405 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmwAAAUM"]
[Wed Jul 29 11:38:53.175048 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmwAAAUM"]
[Wed Jul 29 11:38:53.175420 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmwAAAUM"]
[Wed Jul 29 11:38:53.175583 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/dev/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/api/dev/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OmwAAAUM"]
[Wed Jul 29 11:38:53.245507 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OnAAAAVA"]
[Wed Jul 29 11:38:53.246300 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OnAAAAVA"]
[Wed Jul 29 11:38:53.246756 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OnAAAAVA"]
[Wed Jul 29 11:38:53.246994 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /api/staging/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/api/staging/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OnAAAAVA"]
[Wed Jul 29 11:38:53.277622 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OnQAAAVc"]
[Wed Jul 29 11:38:53.278392 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OnQAAAVc"]
[Wed Jul 29 11:38:53.278849 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OnQAAAVc"]
[Wed Jul 29 11:38:53.279050 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /vendor/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/vendor/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OnQAAAVc"]
[Wed Jul 29 11:38:53.334476 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OngAAAU4"]
[Wed Jul 29 11:38:53.345605 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OngAAAU4"]
[Wed Jul 29 11:38:53.346001 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OngAAAU4"]
[Wed Jul 29 11:38:53.346226 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lib/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/lib/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OngAAAU4"]
[Wed Jul 29 11:38:53.386529 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OnwAAAUY"]
[Wed Jul 29 11:38:53.387295 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OnwAAAUY"]
[Wed Jul 29 11:38:53.387788 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OnwAAAUY"]
[Wed Jul 29 11:38:53.388024 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /resources/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/resources/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OnwAAAUY"]
[Wed Jul 29 11:38:53.444643 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OoAAAAVg"]
[Wed Jul 29 11:38:53.445410 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OoAAAAVg"]
[Wed Jul 29 11:38:53.445941 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OoAAAAVg"]
[Wed Jul 29 11:38:53.446184 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /assets/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/assets/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OoAAAAVg"]
[Wed Jul 29 11:38:53.480086 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OoQAAAUU"]
[Wed Jul 29 11:38:53.480659 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OoQAAAUU"]
[Wed Jul 29 11:38:53.481017 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OoQAAAUU"]
[Wed Jul 29 11:38:53.481182 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uploads/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/uploads/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OoQAAAUU"]
[Wed Jul 29 11:38:53.534405 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OogAAAUg"]
[Wed Jul 29 11:38:53.535089 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OogAAAUg"]
[Wed Jul 29 11:38:53.535502 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OogAAAUg"]
[Wed Jul 29 11:38:53.535689 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /internal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/internal/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OogAAAUg"]
[Wed Jul 29 11:38:53.571823 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OowAAAVQ"]
[Wed Jul 29 11:38:53.572641 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OowAAAVQ"]
[Wed Jul 29 11:38:53.573129 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OowAAAVQ"]
[Wed Jul 29 11:38:53.573368 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tools/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/tools/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OowAAAVQ"]
[Wed Jul 29 11:38:53.639202 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpAAAAUo"]
[Wed Jul 29 11:38:53.640003 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpAAAAUo"]
[Wed Jul 29 11:38:53.640523 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpAAAAUo"]
[Wed Jul 29 11:38:53.640747 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /scripts/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/scripts/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpAAAAUo"]
[Wed Jul 29 11:38:53.682181 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpQAAAUc"]
[Wed Jul 29 11:38:53.682815 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpQAAAUc"]
[Wed Jul 29 11:38:53.683204 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpQAAAUc"]
[Wed Jul 29 11:38:53.683373 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /bin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/bin/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpQAAAUc"]
[Wed Jul 29 11:38:53.760732 2026] [:error] [pid 29816:tid 139878998161152] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "amnKLbiIh7LJBqOi9DwAuQAAAA4"]
[Wed Jul 29 11:38:53.761595 2026] [:error] [pid 29816:tid 139878998161152] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "amnKLbiIh7LJBqOi9DwAuQAAAA4"]
[Wed Jul 29 11:38:53.762159 2026] [:error] [pid 29816:tid 139878998161152] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "amnKLbiIh7LJBqOi9DwAuQAAAA4"]
[Wed Jul 29 11:38:53.762399 2026] [:error] [pid 29816:tid 139878998161152] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sbin/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/sbin/.env"] [unique_id "amnKLbiIh7LJBqOi9DwAuQAAAA4"]
[Wed Jul 29 11:38:53.844837 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/local/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpgAAAVE"]
[Wed Jul 29 11:38:53.845785 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/local/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpgAAAVE"]
[Wed Jul 29 11:38:53.846323 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/local/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpgAAAVE"]
[Wed Jul 29 11:38:53.846598 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /local/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/local/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpgAAAVE"]
[Wed Jul 29 11:38:53.896618 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpwAAAUs"]
[Wed Jul 29 11:38:53.897433 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpwAAAUs"]
[Wed Jul 29 11:38:53.897983 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpwAAAUs"]
[Wed Jul 29 11:38:53.898229 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.3:13227] [client 172.70.248.3] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /portal/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/portal/.env"] [unique_id "amnKLTqdFZ1TNKvQdY3OpwAAAUs"]
[Wed Jul 29 11:38:53.946006 2026] [:error] [pid 29816:tid 139879056910080] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "amnKLbiIh7LJBqOi9DwAvQAAAAc"]
[Wed Jul 29 11:38:53.947044 2026] [:error] [pid 29816:tid 139879056910080] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "amnKLbiIh7LJBqOi9DwAvQAAAAc"]
[Wed Jul 29 11:38:53.947691 2026] [:error] [pid 29816:tid 139879056910080] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "amnKLbiIh7LJBqOi9DwAvQAAAAc"]
[Wed Jul 29 11:38:53.947967 2026] [:error] [pid 29816:tid 139879056910080] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /dashboard/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/dashboard/.env"] [unique_id "amnKLbiIh7LJBqOi9DwAvQAAAAc"]
[Wed Jul 29 11:38:54.156097 2026] [:error] [pid 29816:tid 139878939412224] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAvwAAABU"]
[Wed Jul 29 11:38:54.157283 2026] [:error] [pid 29816:tid 139878939412224] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAvwAAABU"]
[Wed Jul 29 11:38:54.157968 2026] [:error] [pid 29816:tid 139878939412224] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAvwAAABU"]
[Wed Jul 29 11:38:54.158233 2026] [:error] [pid 29816:tid 139878939412224] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAvwAAABU"]
[Wed Jul 29 11:38:54.248122 2026] [:error] [pid 29816:tid 139879023339264] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "amnKLriIh7LJBqOi9DwAwQAAAAs"]
[Wed Jul 29 11:38:54.248865 2026] [:error] [pid 29816:tid 139879023339264] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "amnKLriIh7LJBqOi9DwAwQAAAAs"]
[Wed Jul 29 11:38:54.249295 2026] [:error] [pid 29816:tid 139879023339264] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "amnKLriIh7LJBqOi9DwAwQAAAAs"]
[Wed Jul 29 11:38:54.251371 2026] [:error] [pid 29816:tid 139879023339264] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /crm/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/crm/.env"] [unique_id "amnKLriIh7LJBqOi9DwAwQAAAAs"]
[Wed Jul 29 11:38:54.281663 2026] [:error] [pid 29816:tid 139878922626816] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "amnKLriIh7LJBqOi9DwAwgAAABc"]
[Wed Jul 29 11:38:54.282415 2026] [:error] [pid 29816:tid 139878922626816] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "amnKLriIh7LJBqOi9DwAwgAAABc"]
[Wed Jul 29 11:38:54.282966 2026] [:error] [pid 29816:tid 139878922626816] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "amnKLriIh7LJBqOi9DwAwgAAABc"]
[Wed Jul 29 11:38:54.283120 2026] [:error] [pid 29816:tid 139878922626816] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /erp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/erp/.env"] [unique_id "amnKLriIh7LJBqOi9DwAwgAAABc"]
[Wed Jul 29 11:38:54.339613 2026] [:error] [pid 29816:tid 139879006553856] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "amnKLriIh7LJBqOi9DwAwwAAAA0"]
[Wed Jul 29 11:38:54.340601 2026] [:error] [pid 29816:tid 139879006553856] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "amnKLriIh7LJBqOi9DwAwwAAAA0"]
[Wed Jul 29 11:38:54.341299 2026] [:error] [pid 29816:tid 139879006553856] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "amnKLriIh7LJBqOi9DwAwwAAAA0"]
[Wed Jul 29 11:38:54.341583 2026] [:error] [pid 29816:tid 139879006553856] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /shop/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/shop/.env"] [unique_id "amnKLriIh7LJBqOi9DwAwwAAAA0"]
[Wed Jul 29 11:38:54.538730 2026] [:error] [pid 29816:tid 139879014946560] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/store/.env"] [unique_id "amnKLriIh7LJBqOi9DwAxQAAAAw"]
[Wed Jul 29 11:38:54.539522 2026] [:error] [pid 29816:tid 139879014946560] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/store/.env"] [unique_id "amnKLriIh7LJBqOi9DwAxQAAAAw"]
[Wed Jul 29 11:38:54.540067 2026] [:error] [pid 29816:tid 139879014946560] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/store/.env"] [unique_id "amnKLriIh7LJBqOi9DwAxQAAAAw"]
[Wed Jul 29 11:38:54.540232 2026] [:error] [pid 29816:tid 139879014946560] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /store/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/store/.env"] [unique_id "amnKLriIh7LJBqOi9DwAxQAAAAw"]
[Wed Jul 29 11:38:54.577242 2026] [:error] [pid 29816:tid 139879048517376] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "amnKLriIh7LJBqOi9DwAxgAAAAg"]
[Wed Jul 29 11:38:54.577935 2026] [:error] [pid 29816:tid 139879048517376] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "amnKLriIh7LJBqOi9DwAxgAAAAg"]
[Wed Jul 29 11:38:54.578356 2026] [:error] [pid 29816:tid 139879048517376] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "amnKLriIh7LJBqOi9DwAxgAAAAg"]
[Wed Jul 29 11:38:54.578505 2026] [:error] [pid 29816:tid 139879048517376] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /saas/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/saas/.env"] [unique_id "amnKLriIh7LJBqOi9DwAxgAAAAg"]
[Wed Jul 29 11:38:54.639889 2026] [:error] [pid 29816:tid 139879082088192] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amnKLriIh7LJBqOi9DwAxwAAAAQ"]
[Wed Jul 29 11:38:54.640962 2026] [:error] [pid 29816:tid 139879082088192] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amnKLriIh7LJBqOi9DwAxwAAAAQ"]
[Wed Jul 29 11:38:54.641607 2026] [:error] [pid 29816:tid 139879082088192] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amnKLriIh7LJBqOi9DwAxwAAAAQ"]
[Wed Jul 29 11:38:54.641866 2026] [:error] [pid 29816:tid 139879082088192] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /client/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/client/.env"] [unique_id "amnKLriIh7LJBqOi9DwAxwAAAAQ"]
[Wed Jul 29 11:38:54.689640 2026] [:error] [pid 29816:tid 139878964590336] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/project/.env"] [unique_id "amnKLriIh7LJBqOi9DwAyAAAABI"]
[Wed Jul 29 11:38:54.690439 2026] [:error] [pid 29816:tid 139878964590336] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/project/.env"] [unique_id "amnKLriIh7LJBqOi9DwAyAAAABI"]
[Wed Jul 29 11:38:54.690999 2026] [:error] [pid 29816:tid 139878964590336] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/project/.env"] [unique_id "amnKLriIh7LJBqOi9DwAyAAAABI"]
[Wed Jul 29 11:38:54.691275 2026] [:error] [pid 29816:tid 139878964590336] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /project/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/project/.env"] [unique_id "amnKLriIh7LJBqOi9DwAyAAAABI"]
[Wed Jul 29 11:38:54.734910 2026] [:error] [pid 29816:tid 139878998161152] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAyQAAAA4"]
[Wed Jul 29 11:38:54.735651 2026] [:error] [pid 29816:tid 139878998161152] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAyQAAAA4"]
[Wed Jul 29 11:38:54.736223 2026] [:error] [pid 29816:tid 139878998161152] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAyQAAAA4"]
[Wed Jul 29 11:38:54.736386 2026] [:error] [pid 29816:tid 139878998161152] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /admin-panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/admin-panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAyQAAAA4"]
[Wed Jul 29 11:38:54.864228 2026] [:error] [pid 29816:tid 139878972983040] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAzAAAABE"]
[Wed Jul 29 11:38:54.865094 2026] [:error] [pid 29816:tid 139878972983040] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAzAAAABE"]
[Wed Jul 29 11:38:54.865579 2026] [:error] [pid 29816:tid 139878972983040] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAzAAAABE"]
[Wed Jul 29 11:38:54.865735 2026] [:error] [pid 29816:tid 139878972983040] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /control-panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/control-panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAzAAAABE"]
[Wed Jul 29 11:38:54.934511 2026] [:error] [pid 29816:tid 139879056910080] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAzQAAAAc"]
[Wed Jul 29 11:38:54.935504 2026] [:error] [pid 29816:tid 139879056910080] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAzQAAAAc"]
[Wed Jul 29 11:38:54.936416 2026] [:error] [pid 29816:tid 139879056910080] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAzQAAAAc"]
[Wed Jul 29 11:38:54.936731 2026] [:error] [pid 29816:tid 139879056910080] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /user-panel/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/user-panel/.env"] [unique_id "amnKLriIh7LJBqOi9DwAzQAAAAc"]
[Wed Jul 29 11:38:54.994508 2026] [:error] [pid 29816:tid 139879098873600] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/node/.env"] [unique_id "amnKLriIh7LJBqOi9DwAzwAAAAI"]
[Wed Jul 29 11:38:55.134405 2026] [:error] [pid 29816:tid 139879098873600] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/node/.env"] [unique_id "amnKLriIh7LJBqOi9DwAzwAAAAI"]
[Wed Jul 29 11:38:55.135794 2026] [:error] [pid 29816:tid 139879098873600] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/node/.env"] [unique_id "amnKLriIh7LJBqOi9DwAzwAAAAI"]
[Wed Jul 29 11:38:55.136261 2026] [:error] [pid 29816:tid 139879098873600] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /node/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/node/.env"] [unique_id "amnKLriIh7LJBqOi9DwAzwAAAAI"]
[Wed Jul 29 11:38:55.183032 2026] [:error] [pid 29816:tid 139879023339264] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/express/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0AAAAAs"]
[Wed Jul 29 11:38:55.184239 2026] [:error] [pid 29816:tid 139879023339264] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/express/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0AAAAAs"]
[Wed Jul 29 11:38:55.185261 2026] [:error] [pid 29816:tid 139879023339264] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/express/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0AAAAAs"]
[Wed Jul 29 11:38:55.185646 2026] [:error] [pid 29816:tid 139879023339264] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /express/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/express/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0AAAAAs"]
[Wed Jul 29 11:38:55.237171 2026] [:error] [pid 29816:tid 139878922626816] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/next/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0QAAABc"]
[Wed Jul 29 11:38:55.238599 2026] [:error] [pid 29816:tid 139878922626816] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/next/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0QAAABc"]
[Wed Jul 29 11:38:55.239681 2026] [:error] [pid 29816:tid 139878922626816] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/next/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0QAAABc"]
[Wed Jul 29 11:38:55.239976 2026] [:error] [pid 29816:tid 139878922626816] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /next/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/next/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0QAAABc"]
[Wed Jul 29 11:38:55.281042 2026] [:error] [pid 29816:tid 139878956197632] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0gAAABM"]
[Wed Jul 29 11:38:55.282537 2026] [:error] [pid 29816:tid 139878956197632] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0gAAABM"]
[Wed Jul 29 11:38:55.283419 2026] [:error] [pid 29816:tid 139878956197632] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0gAAABM"]
[Wed Jul 29 11:38:55.283645 2026] [:error] [pid 29816:tid 139878956197632] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nuxt/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/nuxt/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0gAAABM"]
[Wed Jul 29 11:38:55.334424 2026] [:error] [pid 29816:tid 139879006553856] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0wAAAA0"]
[Wed Jul 29 11:38:55.335324 2026] [:error] [pid 29816:tid 139879006553856] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0wAAAA0"]
[Wed Jul 29 11:38:55.335934 2026] [:error] [pid 29816:tid 139879006553856] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0wAAAA0"]
[Wed Jul 29 11:38:55.336134 2026] [:error] [pid 29816:tid 139879006553856] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /nest/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/nest/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA0wAAAA0"]
[Wed Jul 29 11:38:55.374922 2026] [:error] [pid 29816:tid 139879014946560] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/react/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1AAAAAw"]
[Wed Jul 29 11:38:55.375686 2026] [:error] [pid 29816:tid 139879014946560] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/react/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1AAAAAw"]
[Wed Jul 29 11:38:55.376153 2026] [:error] [pid 29816:tid 139879014946560] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/react/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1AAAAAw"]
[Wed Jul 29 11:38:55.376310 2026] [:error] [pid 29816:tid 139879014946560] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /react/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/react/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1AAAAAw"]
[Wed Jul 29 11:38:55.434434 2026] [:error] [pid 29816:tid 139879073695488] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1QAAAAU"]
[Wed Jul 29 11:38:55.435271 2026] [:error] [pid 29816:tid 139879073695488] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1QAAAAU"]
[Wed Jul 29 11:38:55.435748 2026] [:error] [pid 29816:tid 139879073695488] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1QAAAAU"]
[Wed Jul 29 11:38:55.435932 2026] [:error] [pid 29816:tid 139879073695488] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /vue/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/vue/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1QAAAAU"]
[Wed Jul 29 11:38:55.471539 2026] [:error] [pid 29816:tid 139879048517376] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1gAAAAg"]
[Wed Jul 29 11:38:55.472437 2026] [:error] [pid 29816:tid 139879048517376] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1gAAAAg"]
[Wed Jul 29 11:38:55.472908 2026] [:error] [pid 29816:tid 139879048517376] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1gAAAAg"]
[Wed Jul 29 11:38:55.473076 2026] [:error] [pid 29816:tid 139879048517376] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /angular/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/angular/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1gAAAAg"]
[Wed Jul 29 11:38:55.546890 2026] [:error] [pid 29816:tid 139879082088192] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1wAAAAQ"]
[Wed Jul 29 11:38:55.547652 2026] [:error] [pid 29816:tid 139879082088192] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1wAAAAQ"]
[Wed Jul 29 11:38:55.548246 2026] [:error] [pid 29816:tid 139879082088192] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1wAAAAQ"]
[Wed Jul 29 11:38:55.548498 2026] [:error] [pid 29816:tid 139879082088192] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /svelte/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/svelte/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA1wAAAAQ"]
[Wed Jul 29 11:38:55.592831 2026] [:error] [pid 29816:tid 139879040124672] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA2AAAAAk"]
[Wed Jul 29 11:38:55.593926 2026] [:error] [pid 29816:tid 139879040124672] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA2AAAAAk"]
[Wed Jul 29 11:38:55.594622 2026] [:error] [pid 29816:tid 139879040124672] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA2AAAAAk"]
[Wed Jul 29 11:38:55.594886 2026] [:error] [pid 29816:tid 139879040124672] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /vite/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/vite/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA2AAAAAk"]
[Wed Jul 29 11:38:55.844647 2026] [:error] [pid 29816:tid 139878964590336] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA2QAAABI"]
[Wed Jul 29 11:38:55.845360 2026] [:error] [pid 29816:tid 139878964590336] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA2QAAABI"]
[Wed Jul 29 11:38:55.845912 2026] [:error] [pid 29816:tid 139878964590336] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA2QAAABI"]
[Wed Jul 29 11:38:55.846135 2026] [:error] [pid 29816:tid 139878964590336] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backup/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/backup/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA2QAAABI"]
[Wed Jul 29 11:38:55.898097 2026] [:error] [pid 29816:tid 139879031731968] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA2gAAAAo"]
[Wed Jul 29 11:38:55.898685 2026] [:error] [pid 29816:tid 139879031731968] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA2gAAAAo"]
[Wed Jul 29 11:38:55.962622 2026] [:error] [pid 29816:tid 139879031731968] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA2gAAAAo"]
[Wed Jul 29 11:38:55.962839 2026] [:error] [pid 29816:tid 139879031731968] [client 172.70.248.24:13054] [client 172.70.248.24] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /backups/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/backups/.env"] [unique_id "amnKL7iIh7LJBqOi9DwA2gAAAAo"]
[Wed Jul 29 11:38:56.054846 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqAAAAUQ"]
[Wed Jul 29 11:38:56.055638 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqAAAAUQ"]
[Wed Jul 29 11:38:56.056213 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqAAAAUQ"]
[Wed Jul 29 11:38:56.056452 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /old/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/old/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqAAAAUQ"]
[Wed Jul 29 11:38:56.093735 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqQAAAUw"]
[Wed Jul 29 11:38:56.094588 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqQAAAUw"]
[Wed Jul 29 11:38:56.095106 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqQAAAUw"]
[Wed Jul 29 11:38:56.095353 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /tmp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/tmp/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqQAAAUw"]
[Wed Jul 29 11:38:56.146230 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqgAAAVI"]
[Wed Jul 29 11:38:56.147183 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqgAAAVI"]
[Wed Jul 29 11:38:56.147537 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqgAAAVI"]
[Wed Jul 29 11:38:56.147724 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /temp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/temp/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqgAAAVI"]
[Wed Jul 29 11:38:56.189338 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqwAAAUE"]
[Wed Jul 29 11:38:56.190334 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqwAAAUE"]
[Wed Jul 29 11:38:56.190857 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqwAAAUE"]
[Wed Jul 29 11:38:56.191092 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /lab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/lab/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OqwAAAUE"]
[Wed Jul 29 11:38:56.235212 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrAAAAUI"]
[Wed Jul 29 11:38:56.236272 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrAAAAUI"]
[Wed Jul 29 11:38:56.238167 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrAAAAUI"]
[Wed Jul 29 11:38:56.238480 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cronlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/cronlab/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrAAAAUI"]
[Wed Jul 29 11:38:56.276346 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrQAAAUM"]
[Wed Jul 29 11:38:56.276914 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrQAAAUM"]
[Wed Jul 29 11:38:56.277328 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrQAAAUM"]
[Wed Jul 29 11:38:56.277501 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cron/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/cron/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrQAAAUM"]
[Wed Jul 29 11:38:56.344582 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/en/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrgAAAVA"]
[Wed Jul 29 11:38:56.345381 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/en/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrgAAAVA"]
[Wed Jul 29 11:38:56.345941 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/en/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrgAAAVA"]
[Wed Jul 29 11:38:56.346189 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /en/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/en/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrgAAAVA"]
[Wed Jul 29 11:38:56.375143 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrwAAAVc"]
[Wed Jul 29 11:38:56.375964 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrwAAAVc"]
[Wed Jul 29 11:38:56.376451 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrwAAAVc"]
[Wed Jul 29 11:38:56.376696 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /administrator/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/administrator/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OrwAAAVc"]
[Wed Jul 29 11:38:56.444849 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OsAAAAU4"]
[Wed Jul 29 11:38:56.445677 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OsAAAAU4"]
[Wed Jul 29 11:38:56.446186 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OsAAAAU4"]
[Wed Jul 29 11:38:56.446480 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /psnlink/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/psnlink/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OsAAAAU4"]
[Wed Jul 29 11:38:56.476189 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OsQAAAUY"]
[Wed Jul 29 11:38:56.476945 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OsQAAAUY"]
[Wed Jul 29 11:38:56.477409 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OsQAAAUY"]
[Wed Jul 29 11:38:56.477655 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /exapi/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/exapi/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OsQAAAUY"]
[Wed Jul 29 11:38:56.544490 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OsgAAAVg"]
[Wed Jul 29 11:38:56.545260 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OsgAAAVg"]
[Wed Jul 29 11:38:56.545780 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OsgAAAVg"]
[Wed Jul 29 11:38:56.546025 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sitemaps/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemaps/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OsgAAAVg"]
[Wed Jul 29 11:38:56.584268 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "amnKMDqdFZ1TNKvQdY3OswAAAUU"]
[Wed Jul 29 11:38:56.585100 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "amnKMDqdFZ1TNKvQdY3OswAAAUU"]
[Wed Jul 29 11:38:56.585620 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "amnKMDqdFZ1TNKvQdY3OswAAAUU"]
[Wed Jul 29 11:38:56.585876 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup1"] [unique_id "amnKMDqdFZ1TNKvQdY3OswAAAUU"]
[Wed Jul 29 11:38:56.634632 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "amnKMDqdFZ1TNKvQdY3OtAAAAUg"]
[Wed Jul 29 11:38:56.635501 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "amnKMDqdFZ1TNKvQdY3OtAAAAUg"]
[Wed Jul 29 11:38:56.636044 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "amnKMDqdFZ1TNKvQdY3OtAAAAUg"]
[Wed Jul 29 11:38:56.636297 2026] [:error] [pid 12728:tid 139879048517376] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.backup2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.env.backup2"] [unique_id "amnKMDqdFZ1TNKvQdY3OtAAAAUg"]
[Wed Jul 29 11:38:56.674858 2026] [:error] [pid 12728:tid 139879040124672] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OtQAAAUk"]
[Wed Jul 29 11:38:56.675747 2026] [:error] [pid 12728:tid 139879040124672] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OtQAAAUk"]
[Wed Jul 29 11:38:56.676316 2026] [:error] [pid 12728:tid 139879040124672] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OtQAAAUk"]
[Wed Jul 29 11:38:56.676580 2026] [:error] [pid 12728:tid 139879040124672] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /logs/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/logs/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OtQAAAUk"]
[Wed Jul 29 11:38:56.739402 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OtgAAAUo"]
[Wed Jul 29 11:38:56.740216 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OtgAAAUo"]
[Wed Jul 29 11:38:56.740756 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OtgAAAUo"]
[Wed Jul 29 11:38:56.741014 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cache/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/cache/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OtgAAAUo"]
[Wed Jul 29 11:38:56.773704 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OtwAAAUc"]
[Wed Jul 29 11:38:56.774281 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OtwAAAUc"]
[Wed Jul 29 11:38:56.774669 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OtwAAAUc"]
[Wed Jul 29 11:38:56.774834 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailer/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mailer/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OtwAAAUc"]
[Wed Jul 29 11:38:56.844478 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OuAAAAU8"]
[Wed Jul 29 11:38:56.845101 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OuAAAAU8"]
[Wed Jul 29 11:38:56.845522 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OuAAAAU8"]
[Wed Jul 29 11:38:56.845713 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mail/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mail/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OuAAAAU8"]
[Wed Jul 29 11:38:56.881750 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/email/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OuQAAAVE"]
[Wed Jul 29 11:38:56.882613 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/email/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OuQAAAVE"]
[Wed Jul 29 11:38:56.883146 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/email/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OuQAAAVE"]
[Wed Jul 29 11:38:56.883394 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /email/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/email/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OuQAAAVE"]
[Wed Jul 29 11:38:56.934858 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OugAAAUs"]
[Wed Jul 29 11:38:56.935485 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OugAAAUs"]
[Wed Jul 29 11:38:56.935923 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OugAAAUs"]
[Wed Jul 29 11:38:56.936093 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /smtp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/smtp/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OugAAAUs"]
[Wed Jul 29 11:38:56.964104 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OuwAAAU0"]
[Wed Jul 29 11:38:56.964857 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OuwAAAU0"]
[Wed Jul 29 11:38:56.965281 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OuwAAAU0"]
[Wed Jul 29 11:38:56.965435 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailing/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mailing/.env"] [unique_id "amnKMDqdFZ1TNKvQdY3OuwAAAU0"]
[Wed Jul 29 11:38:57.034951 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvAAAAUA"]
[Wed Jul 29 11:38:57.036129 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvAAAAUA"]
[Wed Jul 29 11:38:57.036898 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvAAAAUA"]
[Wed Jul 29 11:38:57.037262 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /notifications/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/notifications/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvAAAAUA"]
[Wed Jul 29 11:38:57.076725 2026] [:error] [pid 12728:tid 139878939412224] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvQAAAVU"]
[Wed Jul 29 11:38:57.077535 2026] [:error] [pid 12728:tid 139878939412224] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvQAAAVU"]
[Wed Jul 29 11:38:57.078239 2026] [:error] [pid 12728:tid 139878939412224] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvQAAAVU"]
[Wed Jul 29 11:38:57.078495 2026] [:error] [pid 12728:tid 139878939412224] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /notify/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/notify/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvQAAAVU"]
[Wed Jul 29 11:38:57.150310 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvgAAAVM"]
[Wed Jul 29 11:38:57.150988 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvgAAAVM"]
[Wed Jul 29 11:38:57.151339 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvgAAAVM"]
[Wed Jul 29 11:38:57.151486 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sender/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/sender/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvgAAAVM"]
[Wed Jul 29 11:38:57.192710 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvwAAAUQ"]
[Wed Jul 29 11:38:57.193438 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvwAAAUQ"]
[Wed Jul 29 11:38:57.193961 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvwAAAUQ"]
[Wed Jul 29 11:38:57.194191 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /campaign/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/campaign/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OvwAAAUQ"]
[Wed Jul 29 11:38:57.241109 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OwQAAAUw"]
[Wed Jul 29 11:38:57.271488 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OwQAAAUw"]
[Wed Jul 29 11:38:57.271977 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OwQAAAUw"]
[Wed Jul 29 11:38:57.272146 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /newsletter/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/newsletter/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OwQAAAUw"]
[Wed Jul 29 11:38:57.344500 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OwgAAAVI"]
[Wed Jul 29 11:38:57.345314 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OwgAAAVI"]
[Wed Jul 29 11:38:57.345978 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OwgAAAVI"]
[Wed Jul 29 11:38:57.346199 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /ses/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/ses/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OwgAAAVI"]
[Wed Jul 29 11:38:57.394483 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OwwAAAUE"]
[Wed Jul 29 11:38:57.395217 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OwwAAAUE"]
[Wed Jul 29 11:38:57.395655 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OwwAAAUE"]
[Wed Jul 29 11:38:57.395834 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sendgrid/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/sendgrid/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OwwAAAUE"]
[Wed Jul 29 11:38:57.444941 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxAAAAUI"]
[Wed Jul 29 11:38:57.445969 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxAAAAUI"]
[Wed Jul 29 11:38:57.446672 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxAAAAUI"]
[Wed Jul 29 11:38:57.446965 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /sparkpost/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/sparkpost/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxAAAAUI"]
[Wed Jul 29 11:38:57.478243 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxQAAAUM"]
[Wed Jul 29 11:38:57.479145 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxQAAAUM"]
[Wed Jul 29 11:38:57.479673 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxQAAAUM"]
[Wed Jul 29 11:38:57.479899 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /postmark/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/postmark/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxQAAAUM"]
[Wed Jul 29 11:38:57.551167 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxgAAAVA"]
[Wed Jul 29 11:38:57.552137 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxgAAAVA"]
[Wed Jul 29 11:38:57.552794 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxgAAAVA"]
[Wed Jul 29 11:38:57.553046 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailgun/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mailgun/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxgAAAVA"]
[Wed Jul 29 11:38:57.581989 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxwAAAVc"]
[Wed Jul 29 11:38:57.582778 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxwAAAVc"]
[Wed Jul 29 11:38:57.583326 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxwAAAVc"]
[Wed Jul 29 11:38:57.583510 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mandrill/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mandrill/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OxwAAAVc"]
[Wed Jul 29 11:38:57.634816 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OyAAAAU4"]
[Wed Jul 29 11:38:57.635973 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OyAAAAU4"]
[Wed Jul 29 11:38:57.636655 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OyAAAAU4"]
[Wed Jul 29 11:38:57.636893 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mailjet/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mailjet/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OyAAAAU4"]
[Wed Jul 29 11:38:57.675109 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OyQAAAUY"]
[Wed Jul 29 11:38:57.676037 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OyQAAAUY"]
[Wed Jul 29 11:38:57.676619 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OyQAAAUY"]
[Wed Jul 29 11:38:57.676866 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /brevo/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/brevo/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OyQAAAUY"]
[Wed Jul 29 11:38:57.737850 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OygAAAVg"]
[Wed Jul 29 11:38:57.738685 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OygAAAVg"]
[Wed Jul 29 11:38:57.739231 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OygAAAVg"]
[Wed Jul 29 11:38:57.739481 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /transactional/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/transactional/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OygAAAVg"]
[Wed Jul 29 11:38:57.770956 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OywAAAUU"]
[Wed Jul 29 11:38:57.771832 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OywAAAUU"]
[Wed Jul 29 11:38:57.772374 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OywAAAUU"]
[Wed Jul 29 11:38:57.772634 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /bulk/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/bulk/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OywAAAUU"]
[Wed Jul 29 11:38:57.835089 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzAAAAVQ"]
[Wed Jul 29 11:38:57.835921 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzAAAAVQ"]
[Wed Jul 29 11:38:57.836612 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzAAAAVQ"]
[Wed Jul 29 11:38:57.836913 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /aws/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/aws/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzAAAAVQ"]
[Wed Jul 29 11:38:57.873326 2026] [:error] [pid 12728:tid 139879040124672] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzQAAAUk"]
[Wed Jul 29 11:38:57.873957 2026] [:error] [pid 12728:tid 139879040124672] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzQAAAUk"]
[Wed Jul 29 11:38:57.874333 2026] [:error] [pid 12728:tid 139879040124672] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzQAAAUk"]
[Wed Jul 29 11:38:57.874497 2026] [:error] [pid 12728:tid 139879040124672] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /azure/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/azure/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzQAAAUk"]
[Wed Jul 29 11:38:57.942516 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzgAAAUo"]
[Wed Jul 29 11:38:57.943214 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzgAAAUo"]
[Wed Jul 29 11:38:57.943599 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzgAAAUo"]
[Wed Jul 29 11:38:57.943764 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /gcp/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/gcp/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzgAAAUo"]
[Wed Jul 29 11:38:57.976441 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzwAAAU8"]
[Wed Jul 29 11:38:57.977127 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzwAAAU8"]
[Wed Jul 29 11:38:57.977547 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzwAAAU8"]
[Wed Jul 29 11:38:57.977720 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cloud/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/cloud/.env"] [unique_id "amnKMTqdFZ1TNKvQdY3OzwAAAU8"]
[Wed Jul 29 11:38:58.044489 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0AAAAVE"]
[Wed Jul 29 11:38:58.045261 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0AAAAVE"]
[Wed Jul 29 11:38:58.045764 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0AAAAVE"]
[Wed Jul 29 11:38:58.045958 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /infrastructure/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/infrastructure/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0AAAAVE"]
[Wed Jul 29 11:38:58.093824 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0QAAAUs"]
[Wed Jul 29 11:38:58.094414 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0QAAAUs"]
[Wed Jul 29 11:38:58.094859 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0QAAAUs"]
[Wed Jul 29 11:38:58.095029 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /docker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/docker/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0QAAAUs"]
[Wed Jul 29 11:38:58.144612 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0gAAAU0"]
[Wed Jul 29 11:38:58.145403 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0gAAAU0"]
[Wed Jul 29 11:38:58.145986 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0gAAAU0"]
[Wed Jul 29 11:38:58.146232 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /k8s/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/k8s/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0gAAAU0"]
[Wed Jul 29 11:38:58.181893 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0wAAAUA"]
[Wed Jul 29 11:38:58.182712 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0wAAAUA"]
[Wed Jul 29 11:38:58.183245 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0wAAAUA"]
[Wed Jul 29 11:38:58.183563 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kubernetes/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/kubernetes/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O0wAAAUA"]
[Wed Jul 29 11:38:58.234818 2026] [:error] [pid 12728:tid 139878939412224] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O1AAAAVU"]
[Wed Jul 29 11:38:58.235692 2026] [:error] [pid 12728:tid 139878939412224] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O1AAAAVU"]
[Wed Jul 29 11:38:58.236286 2026] [:error] [pid 12728:tid 139878939412224] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O1AAAAVU"]
[Wed Jul 29 11:38:58.236533 2026] [:error] [pid 12728:tid 139878939412224] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /terraform/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/terraform/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O1AAAAVU"]
[Wed Jul 29 11:38:58.267730 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O1QAAAVM"]
[Wed Jul 29 11:38:58.268383 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O1QAAAVM"]
[Wed Jul 29 11:38:58.268825 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O1QAAAVM"]
[Wed Jul 29 11:38:58.269018 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /ansible/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/ansible/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O1QAAAVM"]
[Wed Jul 29 11:38:58.334654 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O1gAAAUQ"]
[Wed Jul 29 11:38:58.335473 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O1gAAAUQ"]
[Wed Jul 29 11:38:58.336054 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O1gAAAUQ"]
[Wed Jul 29 11:38:58.336300 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/.git/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O1gAAAUQ"]
[Wed Jul 29 11:38:58.380192 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2AAAAUw"]
[Wed Jul 29 11:38:58.381172 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2AAAAUw"]
[Wed Jul 29 11:38:58.381780 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2AAAAUw"]
[Wed Jul 29 11:38:58.382000 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /ci/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/ci/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2AAAAUw"]
[Wed Jul 29 11:38:58.444844 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2QAAAVI"]
[Wed Jul 29 11:38:58.445796 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2QAAAVI"]
[Wed Jul 29 11:38:58.446400 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2QAAAVI"]
[Wed Jul 29 11:38:58.446672 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cd/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/cd/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2QAAAVI"]
[Wed Jul 29 11:38:58.479542 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2gAAAUE"]
[Wed Jul 29 11:38:58.480268 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2gAAAUE"]
[Wed Jul 29 11:38:58.480753 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2gAAAUE"]
[Wed Jul 29 11:38:58.480940 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /jenkins/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/jenkins/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2gAAAUE"]
[Wed Jul 29 11:38:58.545850 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2wAAAUI"]
[Wed Jul 29 11:38:58.546845 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2wAAAUI"]
[Wed Jul 29 11:38:58.547448 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2wAAAUI"]
[Wed Jul 29 11:38:58.547720 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /gitlab/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/gitlab/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O2wAAAUI"]
[Wed Jul 29 11:38:58.634542 2026] [:error] [pid 12728:tid 139878931019520] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/github/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3AAAAVY"]
[Wed Jul 29 11:38:58.635594 2026] [:error] [pid 12728:tid 139878931019520] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/github/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3AAAAVY"]
[Wed Jul 29 11:38:58.636216 2026] [:error] [pid 12728:tid 139878931019520] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/github/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3AAAAVY"]
[Wed Jul 29 11:38:58.636456 2026] [:error] [pid 12728:tid 139878931019520] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /github/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/github/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3AAAAVY"]
[Wed Jul 29 11:38:58.667227 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3QAAAUM"]
[Wed Jul 29 11:38:58.667875 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3QAAAUM"]
[Wed Jul 29 11:38:58.668273 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3QAAAUM"]
[Wed Jul 29 11:38:58.668422 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /actions/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/actions/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3QAAAUM"]
[Wed Jul 29 11:38:58.744425 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3gAAAVA"]
[Wed Jul 29 11:38:58.745216 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3gAAAVA"]
[Wed Jul 29 11:38:58.745739 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3gAAAVA"]
[Wed Jul 29 11:38:58.746024 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /circleci/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/circleci/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3gAAAVA"]
[Wed Jul 29 11:38:58.785423 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3wAAAVc"]
[Wed Jul 29 11:38:58.786045 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3wAAAVc"]
[Wed Jul 29 11:38:58.786429 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3wAAAVc"]
[Wed Jul 29 11:38:58.786592 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /travis/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/travis/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O3wAAAVc"]
[Wed Jul 29 11:38:58.844634 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4AAAAU4"]
[Wed Jul 29 11:38:58.845438 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4AAAAU4"]
[Wed Jul 29 11:38:58.845987 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4AAAAU4"]
[Wed Jul 29 11:38:58.846219 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /buildkite/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/buildkite/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4AAAAU4"]
[Wed Jul 29 11:38:58.884649 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4QAAAUY"]
[Wed Jul 29 11:38:58.885493 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4QAAAUY"]
[Wed Jul 29 11:38:58.886087 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4QAAAUY"]
[Wed Jul 29 11:38:58.886335 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mysql/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mysql/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4QAAAUY"]
[Wed Jul 29 11:38:58.934661 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4gAAAUU"]
[Wed Jul 29 11:38:58.935467 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4gAAAUU"]
[Wed Jul 29 11:38:58.936027 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4gAAAUU"]
[Wed Jul 29 11:38:58.936292 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /postgres/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/postgres/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4gAAAUU"]
[Wed Jul 29 11:38:58.980585 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4wAAAUo"]
[Wed Jul 29 11:38:58.981486 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4wAAAUo"]
[Wed Jul 29 11:38:58.982059 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4wAAAUo"]
[Wed Jul 29 11:38:58.982301 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /mongodb/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/mongodb/.env"] [unique_id "amnKMjqdFZ1TNKvQdY3O4wAAAUo"]
[Wed Jul 29 11:38:59.044650 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5AAAAU8"]
[Wed Jul 29 11:38:59.045491 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5AAAAU8"]
[Wed Jul 29 11:38:59.046053 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5AAAAU8"]
[Wed Jul 29 11:38:59.046305 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /redis/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/redis/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5AAAAU8"]
[Wed Jul 29 11:38:59.083693 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5QAAAVE"]
[Wed Jul 29 11:38:59.084591 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5QAAAVE"]
[Wed Jul 29 11:38:59.085164 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5QAAAVE"]
[Wed Jul 29 11:38:59.085410 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /elasticsearch/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/elasticsearch/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5QAAAVE"]
[Wed Jul 29 11:38:59.140232 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5gAAAUs"]
[Wed Jul 29 11:38:59.140972 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5gAAAUs"]
[Wed Jul 29 11:38:59.141435 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5gAAAUs"]
[Wed Jul 29 11:38:59.141710 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /rabbitmq/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/rabbitmq/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5gAAAUs"]
[Wed Jul 29 11:38:59.178692 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5wAAAU0"]
[Wed Jul 29 11:38:59.179501 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5wAAAU0"]
[Wed Jul 29 11:38:59.180059 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5wAAAU0"]
[Wed Jul 29 11:38:59.180301 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /kafka/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/kafka/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O5wAAAU0"]
[Wed Jul 29 11:38:59.234469 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6AAAAUA"]
[Wed Jul 29 11:38:59.235274 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6AAAAUA"]
[Wed Jul 29 11:38:59.235664 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6AAAAUA"]
[Wed Jul 29 11:38:59.235836 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /queue/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/queue/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6AAAAUA"]
[Wed Jul 29 11:38:59.272647 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6QAAAVM"]
[Wed Jul 29 11:38:59.273529 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6QAAAVM"]
[Wed Jul 29 11:38:59.274094 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6QAAAVM"]
[Wed Jul 29 11:38:59.274344 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /worker/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/worker/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6QAAAVM"]
[Wed Jul 29 11:38:59.338343 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/job/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6gAAAUQ"]
[Wed Jul 29 11:38:59.339004 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/job/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6gAAAUQ"]
[Wed Jul 29 11:38:59.339487 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/job/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6gAAAUQ"]
[Wed Jul 29 11:38:59.339759 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /job/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/job/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6gAAAUQ"]
[Wed Jul 29 11:38:59.376464 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/test/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6wAAAUw"]
[Wed Jul 29 11:38:59.377288 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/test/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6wAAAUw"]
[Wed Jul 29 11:38:59.377790 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/test/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6wAAAUw"]
[Wed Jul 29 11:38:59.378027 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /test/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/test/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O6wAAAUw"]
[Wed Jul 29 11:38:59.444498 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7AAAAVI"]
[Wed Jul 29 11:38:59.445286 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7AAAAVI"]
[Wed Jul 29 11:38:59.445831 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7AAAAVI"]
[Wed Jul 29 11:38:59.446076 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /qa/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/qa/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7AAAAVI"]
[Wed Jul 29 11:38:59.486618 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7QAAAUE"]
[Wed Jul 29 11:38:59.487482 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7QAAAUE"]
[Wed Jul 29 11:38:59.488055 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7QAAAUE"]
[Wed Jul 29 11:38:59.488332 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /preview/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/preview/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7QAAAUE"]
[Wed Jul 29 11:38:59.544310 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7gAAAUI"]
[Wed Jul 29 11:38:59.545004 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7gAAAUI"]
[Wed Jul 29 11:38:59.545466 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7gAAAUI"]
[Wed Jul 29 11:38:59.545762 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /beta/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/beta/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7gAAAUI"]
[Wed Jul 29 11:38:59.581987 2026] [:error] [pid 12728:tid 139878931019520] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7wAAAVY"]
[Wed Jul 29 11:38:59.582491 2026] [:error] [pid 12728:tid 139878931019520] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7wAAAVY"]
[Wed Jul 29 11:38:59.582881 2026] [:error] [pid 12728:tid 139878931019520] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7wAAAVY"]
[Wed Jul 29 11:38:59.583032 2026] [:error] [pid 12728:tid 139878931019520] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /uat/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/uat/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O7wAAAVY"]
[Wed Jul 29 11:38:59.644291 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8AAAAUM"]
[Wed Jul 29 11:38:59.644903 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8AAAAUM"]
[Wed Jul 29 11:38:59.645290 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8AAAAUM"]
[Wed Jul 29 11:38:59.645444 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /stage/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/stage/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8AAAAUM"]
[Wed Jul 29 11:38:59.734168 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/development/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8QAAAVA"]
[Wed Jul 29 11:38:59.735046 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/development/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8QAAAVA"]
[Wed Jul 29 11:38:59.735749 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/development/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8QAAAVA"]
[Wed Jul 29 11:38:59.736048 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /development/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/development/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8QAAAVA"]
[Wed Jul 29 11:38:59.775567 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/production/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8gAAAVc"]
[Wed Jul 29 11:38:59.776351 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/production/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8gAAAVc"]
[Wed Jul 29 11:38:59.776945 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/production/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8gAAAVc"]
[Wed Jul 29 11:38:59.777212 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /production/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/production/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8gAAAVc"]
[Wed Jul 29 11:38:59.835058 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8wAAAU4"]
[Wed Jul 29 11:38:59.835843 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8wAAAU4"]
[Wed Jul 29 11:38:59.836411 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8wAAAU4"]
[Wed Jul 29 11:38:59.836711 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "124"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /config/app/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.sbf-consultancy.com"] [uri "/config/app/.env"] [unique_id "amnKMzqdFZ1TNKvQdY3O8wAAAU4"]
[Wed Jul 29 11:38:59.869908 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amnKMzqdFZ1TNKvQdY3O9AAAAUY"]
[Wed Jul 29 11:38:59.870828 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amnKMzqdFZ1TNKvQdY3O9AAAAUY"]
[Wed Jul 29 11:38:59.871397 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php"] [unique_id "amnKMzqdFZ1TNKvQdY3O9AAAAUY"]
[Wed Jul 29 11:38:59.934495 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/info.php"] [unique_id "amnKMzqdFZ1TNKvQdY3O9QAAAUU"]
[Wed Jul 29 11:38:59.935498 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/info.php"] [unique_id "amnKMzqdFZ1TNKvQdY3O9QAAAUU"]
[Wed Jul 29 11:38:59.936044 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/info.php"] [unique_id "amnKMzqdFZ1TNKvQdY3O9QAAAUU"]
[Wed Jul 29 11:38:59.982235 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/php.php"] [unique_id "amnKMzqdFZ1TNKvQdY3O9gAAAVQ"]
[Wed Jul 29 11:38:59.982781 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/php.php"] [unique_id "amnKMzqdFZ1TNKvQdY3O9gAAAVQ"]
[Wed Jul 29 11:38:59.983162 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/php.php"] [unique_id "amnKMzqdFZ1TNKvQdY3O9gAAAVQ"]
[Wed Jul 29 11:39:00.044638 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/i.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O9wAAAVg"]
[Wed Jul 29 11:39:00.045543 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/i.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O9wAAAVg"]
[Wed Jul 29 11:39:00.046177 2026] [:error] [pid 12728:tid 139878914234112] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/i.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O9wAAAVg"]
[Wed Jul 29 11:39:00.089536 2026] [:error] [pid 12728:tid 139879040124672] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/pi.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O-AAAAUk"]
[Wed Jul 29 11:39:00.090166 2026] [:error] [pid 12728:tid 139879040124672] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/pi.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O-AAAAUk"]
[Wed Jul 29 11:39:00.090533 2026] [:error] [pid 12728:tid 139879040124672] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/pi.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O-AAAAUk"]
[Wed Jul 29 11:39:00.144577 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/pinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O-QAAAUo"]
[Wed Jul 29 11:39:00.145614 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/pinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O-QAAAUo"]
[Wed Jul 29 11:39:00.146155 2026] [:error] [pid 12728:tid 139879031731968] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/pinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O-QAAAUo"]
[Wed Jul 29 11:39:00.188235 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/test.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O-gAAAU8"]
[Wed Jul 29 11:39:00.188791 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/test.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O-gAAAU8"]
[Wed Jul 29 11:39:00.189118 2026] [:error] [pid 12728:tid 139878989768448] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/test.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O-gAAAU8"]
[Wed Jul 29 11:39:00.244740 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo"] [unique_id "amnKNDqdFZ1TNKvQdY3O-wAAAUc"]
[Wed Jul 29 11:39:00.245727 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo"] [unique_id "amnKNDqdFZ1TNKvQdY3O-wAAAUc"]
[Wed Jul 29 11:39:00.246277 2026] [:error] [pid 12728:tid 139879056910080] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo"] [unique_id "amnKNDqdFZ1TNKvQdY3O-wAAAUc"]
[Wed Jul 29 11:39:00.355743 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/p.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O_AAAAVE"]
[Wed Jul 29 11:39:00.356579 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/p.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O_AAAAVE"]
[Wed Jul 29 11:39:00.357089 2026] [:error] [pid 12728:tid 139878972983040] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/p.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O_AAAAVE"]
[Wed Jul 29 11:39:00.434040 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/debug.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O_QAAAUs"]
[Wed Jul 29 11:39:00.434841 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/debug.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O_QAAAUs"]
[Wed Jul 29 11:39:00.435326 2026] [:error] [pid 12728:tid 139879023339264] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/debug.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O_QAAAUs"]
[Wed Jul 29 11:39:00.473137 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/admin/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O_gAAAU0"]
[Wed Jul 29 11:39:00.473868 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/admin/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O_gAAAU0"]
[Wed Jul 29 11:39:00.474366 2026] [:error] [pid 12728:tid 139879006553856] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/admin/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O_gAAAU0"]
[Wed Jul 29 11:39:00.534546 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/test/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O_wAAAUA"]
[Wed Jul 29 11:39:00.535410 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/test/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O_wAAAUA"]
[Wed Jul 29 11:39:00.536081 2026] [:error] [pid 12728:tid 139879185397504] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/test/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3O_wAAAUA"]
[Wed Jul 29 11:39:00.574984 2026] [:error] [pid 12728:tid 139878939412224] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/dev/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PAAAAAVU"]
[Wed Jul 29 11:39:00.575878 2026] [:error] [pid 12728:tid 139878939412224] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/dev/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PAAAAAVU"]
[Wed Jul 29 11:39:00.576431 2026] [:error] [pid 12728:tid 139878939412224] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/dev/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PAAAAAVU"]
[Wed Jul 29 11:39:00.643649 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/old/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PAQAAAVM"]
[Wed Jul 29 11:39:00.644430 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/old/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PAQAAAVM"]
[Wed Jul 29 11:39:00.644962 2026] [:error] [pid 12728:tid 139878956197632] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/old/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PAQAAAVM"]
[Wed Jul 29 11:39:00.690390 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/tmp/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PAgAAAUQ"]
[Wed Jul 29 11:39:00.691283 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/tmp/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PAgAAAUQ"]
[Wed Jul 29 11:39:00.691717 2026] [:error] [pid 12728:tid 139879082088192] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/tmp/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PAgAAAUQ"]
[Wed Jul 29 11:39:00.744518 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/public/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PAwAAAUw"]
[Wed Jul 29 11:39:00.745309 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/public/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PAwAAAUw"]
[Wed Jul 29 11:39:00.745872 2026] [:error] [pid 12728:tid 139879014946560] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/public/phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PAwAAAUw"]
[Wed Jul 29 11:39:00.787293 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/info"] [unique_id "amnKNDqdFZ1TNKvQdY3PBAAAAVI"]
[Wed Jul 29 11:39:00.787968 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/info"] [unique_id "amnKNDqdFZ1TNKvQdY3PBAAAAVI"]
[Wed Jul 29 11:39:00.788331 2026] [:error] [pid 12728:tid 139878964590336] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/info"] [unique_id "amnKNDqdFZ1TNKvQdY3PBAAAAVI"]
[Wed Jul 29 11:39:00.844543 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PBQAAAUE"]
[Wed Jul 29 11:39:00.845533 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PBQAAAUE"]
[Wed Jul 29 11:39:00.846214 2026] [:error] [pid 12728:tid 139879177004800] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/php-info.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PBQAAAUE"]
[Wed Jul 29 11:39:00.876563 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpversion.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PBgAAAUI"]
[Wed Jul 29 11:39:00.877352 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpversion.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PBgAAAUI"]
[Wed Jul 29 11:39:00.877859 2026] [:error] [pid 12728:tid 139879098873600] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpversion.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PBgAAAUI"]
[Wed Jul 29 11:39:00.935150 2026] [:error] [pid 12728:tid 139878931019520] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/_phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PBwAAAVY"]
[Wed Jul 29 11:39:00.935954 2026] [:error] [pid 12728:tid 139878931019520] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/_phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PBwAAAVY"]
[Wed Jul 29 11:39:00.936426 2026] [:error] [pid 12728:tid 139878931019520] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/_phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PBwAAAVY"]
[Wed Jul 29 11:39:00.986679 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/old_phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PCAAAAUM"]
[Wed Jul 29 11:39:00.987455 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/old_phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PCAAAAUM"]
[Wed Jul 29 11:39:00.987962 2026] [:error] [pid 12728:tid 139879090480896] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/old_phpinfo.php"] [unique_id "amnKNDqdFZ1TNKvQdY3PCAAAAUM"]
[Wed Jul 29 11:39:01.044523 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/server-info.php"] [unique_id "amnKNTqdFZ1TNKvQdY3PCQAAAVA"]
[Wed Jul 29 11:39:01.045234 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/server-info.php"] [unique_id "amnKNTqdFZ1TNKvQdY3PCQAAAVA"]
[Wed Jul 29 11:39:01.045737 2026] [:error] [pid 12728:tid 139878981375744] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/server-info.php"] [unique_id "amnKNTqdFZ1TNKvQdY3PCQAAAVA"]
[Wed Jul 29 11:39:01.077617 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/server-status.php"] [unique_id "amnKNTqdFZ1TNKvQdY3PCgAAAVc"]
[Wed Jul 29 11:39:01.078384 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/server-status.php"] [unique_id "amnKNTqdFZ1TNKvQdY3PCgAAAVc"]
[Wed Jul 29 11:39:01.078924 2026] [:error] [pid 12728:tid 139878922626816] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/server-status.php"] [unique_id "amnKNTqdFZ1TNKvQdY3PCgAAAVc"]
[Wed Jul 29 11:39:01.134511 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/_profiler/phpinfo"] [unique_id "amnKNTqdFZ1TNKvQdY3PCwAAAU4"]
[Wed Jul 29 11:39:01.135337 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/_profiler/phpinfo"] [unique_id "amnKNTqdFZ1TNKvQdY3PCwAAAU4"]
[Wed Jul 29 11:39:01.135875 2026] [:error] [pid 12728:tid 139878998161152] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/_profiler/phpinfo"] [unique_id "amnKNTqdFZ1TNKvQdY3PCwAAAU4"]
[Wed Jul 29 11:39:01.171285 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/_environment"] [unique_id "amnKNTqdFZ1TNKvQdY3PDAAAAUY"]
[Wed Jul 29 11:39:01.172093 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/_environment"] [unique_id "amnKNTqdFZ1TNKvQdY3PDAAAAUY"]
[Wed Jul 29 11:39:01.172620 2026] [:error] [pid 12728:tid 139879065302784] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/_environment"] [unique_id "amnKNTqdFZ1TNKvQdY3PDAAAAUY"]
[Wed Jul 29 11:39:01.234753 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/webroot/index.php/_environment"] [unique_id "amnKNTqdFZ1TNKvQdY3PDQAAAUU"]
[Wed Jul 29 11:39:01.235647 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/webroot/index.php/_environment"] [unique_id "amnKNTqdFZ1TNKvQdY3PDQAAAUU"]
[Wed Jul 29 11:39:01.236025 2026] [:error] [pid 12728:tid 139879073695488] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/webroot/index.php/_environment"] [unique_id "amnKNTqdFZ1TNKvQdY3PDQAAAUU"]
[Wed Jul 29 11:39:01.272751 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/mail/phpinfo.php"] [unique_id "amnKNTqdFZ1TNKvQdY3PDgAAAVQ"]
[Wed Jul 29 11:39:01.273348 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/mail/phpinfo.php"] [unique_id "amnKNTqdFZ1TNKvQdY3PDgAAAVQ"]
[Wed Jul 29 11:39:01.273761 2026] [:error] [pid 12728:tid 139878947804928] [client 172.70.248.25:9717] [client 172.70.248.25] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/mail/phpinfo.php"] [unique_id "amnKNTqdFZ1TNKvQdY3PDgAAAVQ"]
[Wed Jul 29 11:39:01.368013 2026] [:error] [pid 32190:tid 139878972983040] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/cpanel/phpinfo.php"] [unique_id "amnKNaGf2ExAGdIXvjPixwAAARE"]
[Wed Jul 29 11:39:01.437837 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/hosting/phpinfo.php"] [unique_id "amnKNaGf2ExAGdIXvjPiyQAAAQo"]
[Wed Jul 29 11:39:01.438789 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/hosting/phpinfo.php"] [unique_id "amnKNaGf2ExAGdIXvjPiyQAAAQo"]
[Wed Jul 29 11:39:01.439353 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/hosting/phpinfo.php"] [unique_id "amnKNaGf2ExAGdIXvjPiyQAAAQo"]
[Wed Jul 29 11:39:01.650170 2026] [:error] [pid 32190:tid 139879082088192] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/webmail/phpinfo.php"] [unique_id "amnKNaGf2ExAGdIXvjPiygAAAQQ"]
[Wed Jul 29 11:39:01.651193 2026] [:error] [pid 32190:tid 139879082088192] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/webmail/phpinfo.php"] [unique_id "amnKNaGf2ExAGdIXvjPiygAAAQQ"]
[Wed Jul 29 11:39:01.652911 2026] [:error] [pid 32190:tid 139879082088192] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/webmail/phpinfo.php"] [unique_id "amnKNaGf2ExAGdIXvjPiygAAAQQ"]
[Wed Jul 29 11:39:01.682886 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/smtp/phpinfo.php"] [unique_id "amnKNaGf2ExAGdIXvjPiywAAARI"]
[Wed Jul 29 11:39:01.683818 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/smtp/phpinfo.php"] [unique_id "amnKNaGf2ExAGdIXvjPiywAAARI"]
[Wed Jul 29 11:39:01.684421 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/smtp/phpinfo.php"] [unique_id "amnKNaGf2ExAGdIXvjPiywAAARI"]
[Wed Jul 29 11:39:01.745083 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amnKNaGf2ExAGdIXvjPizAAAARA"]
[Wed Jul 29 11:39:01.745969 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amnKNaGf2ExAGdIXvjPizAAAARA"]
[Wed Jul 29 11:39:01.746602 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.bak"] [unique_id "amnKNaGf2ExAGdIXvjPizAAAARA"]
[Wed Jul 29 11:39:01.789688 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.old"] [unique_id "amnKNaGf2ExAGdIXvjPizQAAARQ"]
[Wed Jul 29 11:39:01.790645 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.old"] [unique_id "amnKNaGf2ExAGdIXvjPizQAAARQ"]
[Wed Jul 29 11:39:01.791141 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.old"] [unique_id "amnKNaGf2ExAGdIXvjPizQAAARQ"]
[Wed Jul 29 11:39:01.845099 2026] [:error] [pid 32190:tid 139879040124672] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "amnKNaGf2ExAGdIXvjPizgAAAQk"]
[Wed Jul 29 11:39:01.846239 2026] [:error] [pid 32190:tid 139879040124672] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "amnKNaGf2ExAGdIXvjPizgAAAQk"]
[Wed Jul 29 11:39:01.846596 2026] [:error] [pid 32190:tid 139879040124672] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Pattern match "\\\\.[^.~]+~(?:/.*|)$" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1060"] [id "920500"] [msg "Attempt to access a backup or working file"] [data ".php~"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "amnKNaGf2ExAGdIXvjPizgAAAQk"]
[Wed Jul 29 11:39:01.846956 2026] [:error] [pid 32190:tid 139879040124672] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php~"] [unique_id "amnKNaGf2ExAGdIXvjPizgAAAQk"]
[Wed Jul 29 11:39:01.935048 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amnKNaGf2ExAGdIXvjPizwAAAQ8"]
[Wed Jul 29 11:39:01.936100 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amnKNaGf2ExAGdIXvjPizwAAAQ8"]
[Wed Jul 29 11:39:01.936790 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/info.php.bak"] [unique_id "amnKNaGf2ExAGdIXvjPizwAAAQ8"]
[Wed Jul 29 11:39:02.054347 2026] [:error] [pid 32190:tid 139879065302784] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.save"] [unique_id "amnKNqGf2ExAGdIXvjPi0QAAAQY"]
[Wed Jul 29 11:39:02.055094 2026] [:error] [pid 32190:tid 139879065302784] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.save"] [unique_id "amnKNqGf2ExAGdIXvjPi0QAAAQY"]
[Wed Jul 29 11:39:02.055609 2026] [:error] [pid 32190:tid 139879065302784] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/phpinfo.php.save"] [unique_id "amnKNqGf2ExAGdIXvjPi0QAAAQY"]
[Wed Jul 29 11:39:02.086252 2026] [:error] [pid 32190:tid 139878972983040] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/staging/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi0gAAARE"]
[Wed Jul 29 11:39:02.087249 2026] [:error] [pid 32190:tid 139878972983040] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/staging/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi0gAAARE"]
[Wed Jul 29 11:39:02.087883 2026] [:error] [pid 32190:tid 139878972983040] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/staging/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi0gAAARE"]
[Wed Jul 29 11:39:02.135212 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/beta/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi0wAAAQo"]
[Wed Jul 29 11:39:02.136016 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/beta/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi0wAAAQo"]
[Wed Jul 29 11:39:02.136625 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/beta/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi0wAAAQo"]
[Wed Jul 29 11:39:02.168571 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/uat/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi1AAAARY"]
[Wed Jul 29 11:39:02.169387 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/uat/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi1AAAARY"]
[Wed Jul 29 11:39:02.169870 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/uat/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi1AAAARY"]
[Wed Jul 29 11:39:02.236576 2026] [:error] [pid 32190:tid 139879082088192] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/qa/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi1QAAAQQ"]
[Wed Jul 29 11:39:02.237512 2026] [:error] [pid 32190:tid 139879082088192] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/qa/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi1QAAAQQ"]
[Wed Jul 29 11:39:02.238159 2026] [:error] [pid 32190:tid 139879082088192] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/qa/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi1QAAAQQ"]
[Wed Jul 29 11:39:02.277967 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/preview/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi1gAAARI"]
[Wed Jul 29 11:39:02.278646 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/preview/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi1gAAARI"]
[Wed Jul 29 11:39:02.279175 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/preview/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi1gAAARI"]
[Wed Jul 29 11:39:02.336758 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/www/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi1wAAAQc"]
[Wed Jul 29 11:39:02.337757 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/www/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi1wAAAQc"]
[Wed Jul 29 11:39:02.338386 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/www/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi1wAAAQc"]
[Wed Jul 29 11:39:02.388760 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi2AAAARA"]
[Wed Jul 29 11:39:02.389788 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi2AAAARA"]
[Wed Jul 29 11:39:02.390420 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi2AAAARA"]
[Wed Jul 29 11:39:02.444847 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/public_html/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi2QAAARQ"]
[Wed Jul 29 11:39:02.445831 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/public_html/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi2QAAARQ"]
[Wed Jul 29 11:39:02.446427 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/public_html/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi2QAAARQ"]
[Wed Jul 29 11:39:02.493709 2026] [:error] [pid 32190:tid 139879040124672] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/site/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi2gAAAQk"]
[Wed Jul 29 11:39:02.494407 2026] [:error] [pid 32190:tid 139879040124672] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/site/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi2gAAAQk"]
[Wed Jul 29 11:39:02.494846 2026] [:error] [pid 32190:tid 139879040124672] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/site/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi2gAAAQk"]
[Wed Jul 29 11:39:02.544667 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/docs/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi2wAAAQ8"]
[Wed Jul 29 11:39:02.545497 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/docs/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi2wAAAQ8"]
[Wed Jul 29 11:39:02.546067 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/docs/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi2wAAAQ8"]
[Wed Jul 29 11:39:02.590289 2026] [:error] [pid 32190:tid 139879014946560] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi3AAAAQw"]
[Wed Jul 29 11:39:02.590955 2026] [:error] [pid 32190:tid 139879014946560] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi3AAAAQw"]
[Wed Jul 29 11:39:02.633658 2026] [:error] [pid 32190:tid 139879014946560] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi3AAAAQw"]
[Wed Jul 29 11:39:02.669964 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/administrator/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi3gAAAQU"]
[Wed Jul 29 11:39:02.670810 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/administrator/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi3gAAAQU"]
[Wed Jul 29 11:39:02.671391 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/administrator/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi3gAAAQU"]
[Wed Jul 29 11:39:02.734456 2026] [:error] [pid 32190:tid 139878972983040] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/core/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi3wAAARE"]
[Wed Jul 29 11:39:02.735367 2026] [:error] [pid 32190:tid 139878972983040] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/core/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi3wAAARE"]
[Wed Jul 29 11:39:02.735914 2026] [:error] [pid 32190:tid 139878972983040] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/core/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi3wAAARE"]
[Wed Jul 29 11:39:02.766242 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/includes/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi4AAAAQo"]
[Wed Jul 29 11:39:02.777094 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/includes/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi4AAAAQo"]
[Wed Jul 29 11:39:02.777355 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/includes/phpinfo.php"] [unique_id "amnKNqGf2ExAGdIXvjPi4AAAAQo"]
[Wed Jul 29 11:39:02.852279 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/service-account.json"] [unique_id "amnKNqGf2ExAGdIXvjPi4QAAARY"]
[Wed Jul 29 11:39:02.853499 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/service-account.json"] [unique_id "amnKNqGf2ExAGdIXvjPi4QAAARY"]
[Wed Jul 29 11:39:02.854088 2026] [:error] [pid 32190:tid 139878931019520] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/service-account.json"] [unique_id "amnKNqGf2ExAGdIXvjPi4QAAARY"]
[Wed Jul 29 11:39:02.888765 2026] [:error] [pid 32190:tid 139879082088192] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sa.json"] [unique_id "amnKNqGf2ExAGdIXvjPi4gAAAQQ"]
[Wed Jul 29 11:39:02.889713 2026] [:error] [pid 32190:tid 139879082088192] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sa.json"] [unique_id "amnKNqGf2ExAGdIXvjPi4gAAAQQ"]
[Wed Jul 29 11:39:02.890323 2026] [:error] [pid 32190:tid 139879082088192] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sa.json"] [unique_id "amnKNqGf2ExAGdIXvjPi4gAAAQQ"]
[Wed Jul 29 11:39:02.947717 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/gcp-key.json"] [unique_id "amnKNqGf2ExAGdIXvjPi4wAAARM"]
[Wed Jul 29 11:39:02.949873 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/gcp-key.json"] [unique_id "amnKNqGf2ExAGdIXvjPi4wAAARM"]
[Wed Jul 29 11:39:02.951789 2026] [:error] [pid 32190:tid 139878956197632] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/gcp-key.json"] [unique_id "amnKNqGf2ExAGdIXvjPi4wAAARM"]
[Wed Jul 29 11:39:02.985411 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/gcp-credentials.json"] [unique_id "amnKNqGf2ExAGdIXvjPi5AAAARI"]
[Wed Jul 29 11:39:02.987234 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/gcp-credentials.json"] [unique_id "amnKNqGf2ExAGdIXvjPi5AAAARI"]
[Wed Jul 29 11:39:02.988521 2026] [:error] [pid 32190:tid 139878964590336] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/gcp-credentials.json"] [unique_id "amnKNqGf2ExAGdIXvjPi5AAAARI"]
[Wed Jul 29 11:39:03.036116 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/gcp-sa.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi5QAAAQc"]
[Wed Jul 29 11:39:03.037791 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/gcp-sa.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi5QAAAQc"]
[Wed Jul 29 11:39:03.038638 2026] [:error] [pid 32190:tid 139879056910080] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/gcp-sa.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi5QAAAQc"]
[Wed Jul 29 11:39:03.073461 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/credentials.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi5gAAARA"]
[Wed Jul 29 11:39:03.074313 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/credentials.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi5gAAARA"]
[Wed Jul 29 11:39:03.074912 2026] [:error] [pid 32190:tid 139878981375744] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/credentials.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi5gAAARA"]
[Wed Jul 29 11:39:03.136914 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/google-credentials.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi5wAAARQ"]
[Wed Jul 29 11:39:03.138544 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/google-credentials.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi5wAAARQ"]
[Wed Jul 29 11:39:03.139673 2026] [:error] [pid 32190:tid 139878947804928] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/google-credentials.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi5wAAARQ"]
[Wed Jul 29 11:39:03.193104 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/google-key.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi6AAAAQM"]
[Wed Jul 29 11:39:03.194388 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/google-key.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi6AAAAQM"]
[Wed Jul 29 11:39:03.195160 2026] [:error] [pid 32190:tid 139879090480896] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/google-key.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi6AAAAQM"]
[Wed Jul 29 11:39:03.256661 2026] [:error] [pid 32190:tid 139879040124672] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/.config/gcloud/application_default_credentials.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi6QAAAQk"]
[Wed Jul 29 11:39:03.259190 2026] [:error] [pid 32190:tid 139879040124672] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/.config/gcloud/application_default_credentials.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi6QAAAQk"]
[Wed Jul 29 11:39:03.260469 2026] [:error] [pid 32190:tid 139879040124672] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/.config/gcloud/application_default_credentials.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi6QAAAQk"]
[Wed Jul 29 11:39:03.292465 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/application_default_credentials.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi6gAAAQ8"]
[Wed Jul 29 11:39:03.294101 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/application_default_credentials.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi6gAAAQ8"]
[Wed Jul 29 11:39:03.295324 2026] [:error] [pid 32190:tid 139878989768448] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/application_default_credentials.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi6gAAAQ8"]
[Wed Jul 29 11:39:03.345976 2026] [:error] [pid 32190:tid 139879014946560] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/key.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi6wAAAQw"]
[Wed Jul 29 11:39:03.347764 2026] [:error] [pid 32190:tid 139879014946560] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/key.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi6wAAAQw"]
[Wed Jul 29 11:39:03.348787 2026] [:error] [pid 32190:tid 139879014946560] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/key.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi6wAAAQw"]
[Wed Jul 29 11:39:03.378740 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/keyfile.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi7AAAAQU"]
[Wed Jul 29 11:39:03.379790 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/keyfile.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi7AAAAQU"]
[Wed Jul 29 11:39:03.380447 2026] [:error] [pid 32190:tid 139879073695488] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/keyfile.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi7AAAAQU"]
[Wed Jul 29 11:39:03.434422 2026] [:error] [pid 32190:tid 139878972983040] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/firebase-adminsdk.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi7QAAARE"]
[Wed Jul 29 11:39:03.435400 2026] [:error] [pid 32190:tid 139878972983040] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/firebase-adminsdk.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi7QAAARE"]
[Wed Jul 29 11:39:03.436053 2026] [:error] [pid 32190:tid 139878972983040] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/firebase-adminsdk.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi7QAAARE"]
[Wed Jul 29 11:39:03.478278 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/firebase-key.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi7gAAAQo"]
[Wed Jul 29 11:39:03.479224 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/firebase-key.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi7gAAAQo"]
[Wed Jul 29 11:39:03.480417 2026] [:error] [pid 32190:tid 139879031731968] [client 172.70.248.24:13056] [client 172.70.248.24] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/firebase-key.json"] [unique_id "amnKN6Gf2ExAGdIXvjPi7gAAAQo"]
[Wed Jul 29 11:41:30.951336 2026] [:error] [pid 32190:tid 139878989768448] [client 141.101.76.184:13941] [client 141.101.76.184] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amnKyqGf2ExAGdIXvjPj3gAAAQ8"]
[Wed Jul 29 11:41:30.952264 2026] [:error] [pid 32190:tid 139878989768448] [client 141.101.76.184:13941] [client 141.101.76.184] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amnKyqGf2ExAGdIXvjPj3gAAAQ8"]
[Wed Jul 29 11:41:30.952874 2026] [:error] [pid 32190:tid 139878989768448] [client 141.101.76.184:13941] [client 141.101.76.184] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/"] [unique_id "amnKyqGf2ExAGdIXvjPj3gAAAQ8"]
[Wed Jul 29 12:03:30.542687 2026] [:error] [pid 29816:tid 139878914234112] [client 188.114.111.226:12641] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnP8riIh7LJBqOi9DwdngAAABg"]
[Wed Jul 29 12:03:30.543813 2026] [:error] [pid 29816:tid 139878914234112] [client 188.114.111.226:12641] [client 188.114.111.226] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnP8riIh7LJBqOi9DwdngAAABg"]
[Wed Jul 29 12:03:30.544366 2026] [:error] [pid 29816:tid 139878914234112] [client 188.114.111.226:12641] [client 188.114.111.226] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amnP8riIh7LJBqOi9DwdngAAABg"]
[Wed Jul 29 12:31:11.243231 2026] [:error] [pid 12728:tid 139878981375744] [client 172.68.15.205:9263] [client 172.68.15.205] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amnWbzqdFZ1TNKvQdY3sKwAAAVA"]
[Wed Jul 29 12:31:11.243933 2026] [:error] [pid 12728:tid 139878981375744] [client 172.68.15.205:9263] [client 172.68.15.205] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amnWbzqdFZ1TNKvQdY3sKwAAAVA"]
[Wed Jul 29 12:31:11.244312 2026] [:error] [pid 12728:tid 139878981375744] [client 172.68.15.205:9263] [client 172.68.15.205] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amnWbzqdFZ1TNKvQdY3sKwAAAVA"]
[Wed Jul 29 12:42:30.934782 2026] [:error] [pid 29816:tid 139878964590336] [client 104.23.243.18:12249] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amnZFriIh7LJBqOi9DxMtAAAABI"]
[Wed Jul 29 12:42:30.953301 2026] [:error] [pid 29816:tid 139878964590336] [client 104.23.243.18:12249] [client 104.23.243.18] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amnZFriIh7LJBqOi9DxMtAAAABI"]
[Wed Jul 29 12:42:30.954835 2026] [:error] [pid 29816:tid 139878964590336] [client 104.23.243.18:12249] [client 104.23.243.18] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/robots.txt"] [unique_id "amnZFriIh7LJBqOi9DxMtAAAABI"]
[Wed Jul 29 12:42:31.435585 2026] [:error] [pid 29816:tid 139878981375744] [client 104.23.197.77:14235] [client 104.23.197.77] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amnZF7iIh7LJBqOi9DxMuwAAABA"]
[Wed Jul 29 12:42:31.436686 2026] [:error] [pid 29816:tid 139878981375744] [client 104.23.197.77:14235] [client 104.23.197.77] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amnZF7iIh7LJBqOi9DxMuwAAABA"]
[Wed Jul 29 12:42:31.437213 2026] [:error] [pid 29816:tid 139878981375744] [client 104.23.197.77:14235] [client 104.23.197.77] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "www.sbf-consultancy.com"] [uri "/sitemap.xml"] [unique_id "amnZF7iIh7LJBqOi9DxMuwAAABA"]
[Wed Jul 29 12:55:05.542050 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.216.197:13855] [client 162.158.216.197] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amncCYpuIafV02klyJJPpwAAAEc"]
[Wed Jul 29 12:55:05.543006 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.216.197:13855] [client 162.158.216.197] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amncCYpuIafV02klyJJPpwAAAEc"]
[Wed Jul 29 12:55:05.543622 2026] [:error] [pid 29817:tid 139879056910080] [client 162.158.216.197:13855] [client 162.158.216.197] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22http\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/install.php"] [unique_id "amncCYpuIafV02klyJJPpwAAAEc"]
[Wed Jul 29 13:00:11.192359 2026] [:error] [pid 29913:tid 139879090480896] [client 172.71.98.106:14023] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amndOwVDiGi-ktKYT-KMogAAAMM"]
[Wed Jul 29 13:00:11.193463 2026] [:error] [pid 29913:tid 139879090480896] [client 172.71.98.106:14023] [client 172.71.98.106] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amndOwVDiGi-ktKYT-KMogAAAMM"]
[Wed Jul 29 13:00:11.194048 2026] [:error] [pid 29913:tid 139879090480896] [client 172.71.98.106:14023] [client 172.71.98.106] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/"] [unique_id "amndOwVDiGi-ktKYT-KMogAAAMM"]
[Wed Jul 29 13:04:12.236374 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/--wp-lgj.php"] [unique_id "amneLKGf2ExAGdIXvjMDqgAAAQ0"]
[Wed Jul 29 13:04:12.237570 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/--wp-lgj.php"] [unique_id "amneLKGf2ExAGdIXvjMDqgAAAQ0"]
[Wed Jul 29 13:04:12.238339 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/--wp-lgj.php"] [unique_id "amneLKGf2ExAGdIXvjMDqgAAAQ0"]
[Wed Jul 29 13:04:12.238398 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/--wp-lgj.php"] [unique_id "amneLKGf2ExAGdIXvjMDqgAAAQ0"]
[Wed Jul 29 13:04:13.170529 2026] [:error] [pid 29816:tid 139878947804928] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/.well-known/"] [unique_id "amneLbiIh7LJBqOi9DxlywAAABQ"]
[Wed Jul 29 13:04:13.171748 2026] [:error] [pid 29816:tid 139878947804928] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/.well-known/"] [unique_id "amneLbiIh7LJBqOi9DxlywAAABQ"]
[Wed Jul 29 13:04:13.172671 2026] [:error] [pid 29816:tid 139878947804928] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/.well-known/"] [unique_id "amneLbiIh7LJBqOi9DxlywAAABQ"]
[Wed Jul 29 13:04:13.172724 2026] [:error] [pid 29816:tid 139878947804928] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/.well-known/"] [unique_id "amneLbiIh7LJBqOi9DxlywAAABQ"]
[Wed Jul 29 13:04:13.391502 2026] [:error] [pid 32190:tid 139878956197632] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amneLaGf2ExAGdIXvjMDrQAAARM"]
[Wed Jul 29 13:04:13.392259 2026] [:error] [pid 32190:tid 139878956197632] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amneLaGf2ExAGdIXvjMDrQAAARM"]
[Wed Jul 29 13:04:13.392885 2026] [:error] [pid 32190:tid 139878956197632] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amneLaGf2ExAGdIXvjMDrQAAARM"]
[Wed Jul 29 13:04:13.392962 2026] [:error] [pid 32190:tid 139878956197632] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amneLaGf2ExAGdIXvjMDrQAAARM"]
[Wed Jul 29 13:04:13.734107 2026] [:error] [pid 29816:tid 139879014946560] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/flower.php"] [unique_id "amneLbiIh7LJBqOi9DxlzwAAAAw"]
[Wed Jul 29 13:04:13.734927 2026] [:error] [pid 29816:tid 139879014946560] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/flower.php"] [unique_id "amneLbiIh7LJBqOi9DxlzwAAAAw"]
[Wed Jul 29 13:04:13.735665 2026] [:error] [pid 29816:tid 139879014946560] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/flower.php"] [unique_id "amneLbiIh7LJBqOi9DxlzwAAAAw"]
[Wed Jul 29 13:04:13.735738 2026] [:error] [pid 29816:tid 139879014946560] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/flower.php"] [unique_id "amneLbiIh7LJBqOi9DxlzwAAAAw"]
[Wed Jul 29 13:04:13.992162 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/xleet.php"] [unique_id "amneLaGf2ExAGdIXvjMDsQAAAQs"]
[Wed Jul 29 13:04:13.993197 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/xleet.php"] [unique_id "amneLaGf2ExAGdIXvjMDsQAAAQs"]
[Wed Jul 29 13:04:13.993959 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/xleet.php"] [unique_id "amneLaGf2ExAGdIXvjMDsQAAAQs"]
[Wed Jul 29 13:04:13.994008 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/xleet.php"] [unique_id "amneLaGf2ExAGdIXvjMDsQAAAQs"]
[Wed Jul 29 13:04:14.244337 2026] [:error] [pid 29816:tid 139878939412224] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amneLriIh7LJBqOi9Dxl1gAAABU"]
[Wed Jul 29 13:04:14.245231 2026] [:error] [pid 29816:tid 139878939412224] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amneLriIh7LJBqOi9Dxl1gAAABU"]
[Wed Jul 29 13:04:14.265728 2026] [:error] [pid 29816:tid 139878939412224] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amneLriIh7LJBqOi9Dxl1gAAABU"]
[Wed Jul 29 13:04:14.265831 2026] [:error] [pid 29816:tid 139878939412224] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amneLriIh7LJBqOi9Dxl1gAAABU"]
[Wed Jul 29 13:04:14.266997 2026] [:error] [pid 29816:tid 139878939412224] [client 104.23.254.53:10817] File does not exist: /usr/local/apache/autossl_tmp/.well-known/acme-challenge/flower.php
[Wed Jul 29 13:04:14.635797 2026] [:error] [pid 32190:tid 139879082088192] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amneLqGf2ExAGdIXvjMDtAAAAQQ"]
[Wed Jul 29 13:04:14.636755 2026] [:error] [pid 32190:tid 139879082088192] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amneLqGf2ExAGdIXvjMDtAAAAQQ"]
[Wed Jul 29 13:04:14.637510 2026] [:error] [pid 32190:tid 139879082088192] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amneLqGf2ExAGdIXvjMDtAAAAQQ"]
[Wed Jul 29 13:04:14.637577 2026] [:error] [pid 32190:tid 139879082088192] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amneLqGf2ExAGdIXvjMDtAAAAQQ"]
[Wed Jul 29 13:04:14.665764 2026] [:error] [pid 32190:tid 139879082088192] [client 104.23.254.19:11057] File does not exist: /usr/local/apache/autossl_tmp/.well-known/acme-challenge/xleet.php
[Wed Jul 29 13:04:14.989264 2026] [:error] [pid 29816:tid 139878947804928] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amneLriIh7LJBqOi9Dxl2gAAABQ"]
[Wed Jul 29 13:04:14.990161 2026] [:error] [pid 29816:tid 139878947804928] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amneLriIh7LJBqOi9Dxl2gAAABQ"]
[Wed Jul 29 13:04:14.990940 2026] [:error] [pid 29816:tid 139878947804928] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amneLriIh7LJBqOi9Dxl2gAAABQ"]
[Wed Jul 29 13:04:14.990997 2026] [:error] [pid 29816:tid 139878947804928] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amneLriIh7LJBqOi9Dxl2gAAABQ"]
[Wed Jul 29 13:04:14.992331 2026] [:error] [pid 29816:tid 139878947804928] [client 104.23.254.53:10817] File does not exist: /usr/local/apache/autossl_tmp/.well-known/acme-challenge/about.php
[Wed Jul 29 13:04:15.238303 2026] [:error] [pid 32190:tid 139879040124672] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amneL6Gf2ExAGdIXvjMDtwAAAQk"]
[Wed Jul 29 13:04:15.239137 2026] [:error] [pid 32190:tid 139879040124672] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amneL6Gf2ExAGdIXvjMDtwAAAQk"]
[Wed Jul 29 13:04:15.240209 2026] [:error] [pid 32190:tid 139879040124672] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amneL6Gf2ExAGdIXvjMDtwAAAQk"]
[Wed Jul 29 13:04:15.240308 2026] [:error] [pid 32190:tid 139879040124672] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amneL6Gf2ExAGdIXvjMDtwAAAQk"]
[Wed Jul 29 13:04:15.241698 2026] [:error] [pid 32190:tid 139879040124672] [client 104.23.254.19:11057] File does not exist: /usr/local/apache/autossl_tmp/.well-known/acme-challenge/autoload_classmap.php
[Wed Jul 29 13:04:15.446847 2026] [:error] [pid 29816:tid 139878914234112] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/configKZU/Jump/0-woodhous/Ven-C/Ven-US/0-upstartd/"] [unique_id "amneL7iIh7LJBqOi9Dxl3QAAABg"]
[Wed Jul 29 13:04:15.447477 2026] [:error] [pid 29816:tid 139878914234112] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/configKZU/Jump/0-woodhous/Ven-C/Ven-US/0-upstartd/"] [unique_id "amneL7iIh7LJBqOi9Dxl3QAAABg"]
[Wed Jul 29 13:04:15.448086 2026] [:error] [pid 29816:tid 139878914234112] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/configKZU/Jump/0-woodhous/Ven-C/Ven-US/0-upstartd/"] [unique_id "amneL7iIh7LJBqOi9Dxl3QAAABg"]
[Wed Jul 29 13:04:15.448143 2026] [:error] [pid 29816:tid 139878914234112] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/configKZU/Jump/0-woodhous/Ven-C/Ven-US/0-upstartd/"] [unique_id "amneL7iIh7LJBqOi9Dxl3QAAABg"]
[Wed Jul 29 13:04:15.662463 2026] [:error] [pid 29816:tid 139879006553856] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amneL7iIh7LJBqOi9Dxl3wAAAA0"]
[Wed Jul 29 13:04:15.663131 2026] [:error] [pid 29816:tid 139879006553856] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amneL7iIh7LJBqOi9Dxl3wAAAA0"]
[Wed Jul 29 13:04:15.663657 2026] [:error] [pid 29816:tid 139879006553856] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amneL7iIh7LJBqOi9Dxl3wAAAA0"]
[Wed Jul 29 13:04:15.663692 2026] [:error] [pid 29816:tid 139879006553856] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amneL7iIh7LJBqOi9Dxl3wAAAA0"]
[Wed Jul 29 13:04:15.664538 2026] [:error] [pid 29816:tid 139879006553856] [client 104.23.254.53:10817] File does not exist: /usr/local/apache/autossl_tmp/.well-known/acme-challenge/flower.php
[Wed Jul 29 13:04:15.936120 2026] [:error] [pid 32190:tid 139878998161152] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amneL6Gf2ExAGdIXvjMDugAAAQ4"]
[Wed Jul 29 13:04:15.936965 2026] [:error] [pid 32190:tid 139878998161152] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amneL6Gf2ExAGdIXvjMDugAAAQ4"]
[Wed Jul 29 13:04:15.937784 2026] [:error] [pid 32190:tid 139878998161152] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amneL6Gf2ExAGdIXvjMDugAAAQ4"]
[Wed Jul 29 13:04:15.937869 2026] [:error] [pid 32190:tid 139878998161152] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amneL6Gf2ExAGdIXvjMDugAAAQ4"]
[Wed Jul 29 13:04:15.939223 2026] [:error] [pid 32190:tid 139878998161152] [client 104.23.254.19:11057] File does not exist: /usr/local/apache/autossl_tmp/.well-known/acme-challenge/xleet.php
[Wed Jul 29 13:04:16.148212 2026] [:error] [pid 29816:tid 139878972983040] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amneMLiIh7LJBqOi9Dxl4AAAABE"]
[Wed Jul 29 13:04:16.148749 2026] [:error] [pid 29816:tid 139878972983040] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amneMLiIh7LJBqOi9Dxl4AAAABE"]
[Wed Jul 29 13:04:16.149229 2026] [:error] [pid 29816:tid 139878972983040] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amneMLiIh7LJBqOi9Dxl4AAAABE"]
[Wed Jul 29 13:04:16.149263 2026] [:error] [pid 29816:tid 139878972983040] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amneMLiIh7LJBqOi9Dxl4AAAABE"]
[Wed Jul 29 13:04:16.366828 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.wp-cli/flower.php"] [unique_id "amneMKGf2ExAGdIXvjMDvQAAARc"]
[Wed Jul 29 13:04:16.367753 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.wp-cli/flower.php"] [unique_id "amneMKGf2ExAGdIXvjMDvQAAARc"]
[Wed Jul 29 13:04:16.368502 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.wp-cli/flower.php"] [unique_id "amneMKGf2ExAGdIXvjMDvQAAARc"]
[Wed Jul 29 13:04:16.368578 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.wp-cli/flower.php"] [unique_id "amneMKGf2ExAGdIXvjMDvQAAARc"]
[Wed Jul 29 13:04:16.573724 2026] [:error] [pid 29816:tid 139879014946560] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amneMLiIh7LJBqOi9Dxl4gAAAAw"]
[Wed Jul 29 13:04:16.574389 2026] [:error] [pid 29816:tid 139879014946560] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amneMLiIh7LJBqOi9Dxl4gAAAAw"]
[Wed Jul 29 13:04:16.574924 2026] [:error] [pid 29816:tid 139879014946560] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amneMLiIh7LJBqOi9Dxl4gAAAAw"]
[Wed Jul 29 13:04:16.574995 2026] [:error] [pid 29816:tid 139879014946560] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amneMLiIh7LJBqOi9Dxl4gAAAAw"]
[Wed Jul 29 13:04:16.781909 2026] [:error] [pid 32190:tid 139878956197632] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amneMKGf2ExAGdIXvjMDvgAAARM"]
[Wed Jul 29 13:04:16.782835 2026] [:error] [pid 32190:tid 139878956197632] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amneMKGf2ExAGdIXvjMDvgAAARM"]
[Wed Jul 29 13:04:16.783530 2026] [:error] [pid 32190:tid 139878956197632] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amneMKGf2ExAGdIXvjMDvgAAARM"]
[Wed Jul 29 13:04:16.783613 2026] [:error] [pid 32190:tid 139878956197632] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amneMKGf2ExAGdIXvjMDvgAAARM"]
[Wed Jul 29 13:04:17.036142 2026] [:error] [pid 29816:tid 139879082088192] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amneMbiIh7LJBqOi9Dxl5gAAAAQ"]
[Wed Jul 29 13:04:17.037443 2026] [:error] [pid 29816:tid 139879082088192] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amneMbiIh7LJBqOi9Dxl5gAAAAQ"]
[Wed Jul 29 13:04:17.038532 2026] [:error] [pid 29816:tid 139879082088192] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amneMbiIh7LJBqOi9Dxl5gAAAAQ"]
[Wed Jul 29 13:04:17.038616 2026] [:error] [pid 29816:tid 139879082088192] [client 104.23.254.53:10817] [client 104.23.254.53] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amneMbiIh7LJBqOi9Dxl5gAAAAQ"]
[Wed Jul 29 13:04:17.279784 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amneMaGf2ExAGdIXvjMDvwAAARE"]
[Wed Jul 29 13:04:17.280457 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amneMaGf2ExAGdIXvjMDvwAAARE"]
[Wed Jul 29 13:04:17.280959 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amneMaGf2ExAGdIXvjMDvwAAARE"]
[Wed Jul 29 13:04:17.280993 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amneMaGf2ExAGdIXvjMDvwAAARE"]
[Wed Jul 29 13:04:17.486361 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/1.php"] [unique_id "amneMaGf2ExAGdIXvjMDwgAAAQU"]
[Wed Jul 29 13:04:17.487083 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/1.php"] [unique_id "amneMaGf2ExAGdIXvjMDwgAAAQU"]
[Wed Jul 29 13:04:17.487619 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/1.php"] [unique_id "amneMaGf2ExAGdIXvjMDwgAAAQU"]
[Wed Jul 29 13:04:17.487665 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/1.php"] [unique_id "amneMaGf2ExAGdIXvjMDwgAAAQU"]
[Wed Jul 29 13:04:17.695059 2026] [:error] [pid 32190:tid 139878931019520] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amneMaGf2ExAGdIXvjMDxAAAARY"]
[Wed Jul 29 13:04:17.696093 2026] [:error] [pid 32190:tid 139878931019520] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amneMaGf2ExAGdIXvjMDxAAAARY"]
[Wed Jul 29 13:04:17.696924 2026] [:error] [pid 32190:tid 139878931019520] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amneMaGf2ExAGdIXvjMDxAAAARY"]
[Wed Jul 29 13:04:17.696977 2026] [:error] [pid 32190:tid 139878931019520] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/admin.php"] [unique_id "amneMaGf2ExAGdIXvjMDxAAAARY"]
[Wed Jul 29 13:04:17.902826 2026] [:error] [pid 32190:tid 139879056910080] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/as.php"] [unique_id "amneMaGf2ExAGdIXvjMDxgAAAQc"]
[Wed Jul 29 13:04:17.935179 2026] [:error] [pid 32190:tid 139879056910080] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/as.php"] [unique_id "amneMaGf2ExAGdIXvjMDxgAAAQc"]
[Wed Jul 29 13:04:17.935962 2026] [:error] [pid 32190:tid 139879056910080] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/as.php"] [unique_id "amneMaGf2ExAGdIXvjMDxgAAAQc"]
[Wed Jul 29 13:04:17.936010 2026] [:error] [pid 32190:tid 139879056910080] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/as.php"] [unique_id "amneMaGf2ExAGdIXvjMDxgAAAQc"]
[Wed Jul 29 13:04:18.151070 2026] [:error] [pid 32190:tid 139879040124672] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/autoload_classmap.php"] [unique_id "amneMqGf2ExAGdIXvjMDxwAAAQk"]
[Wed Jul 29 13:04:18.151952 2026] [:error] [pid 32190:tid 139879040124672] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/autoload_classmap.php"] [unique_id "amneMqGf2ExAGdIXvjMDxwAAAQk"]
[Wed Jul 29 13:04:18.152445 2026] [:error] [pid 32190:tid 139879040124672] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/autoload_classmap.php"] [unique_id "amneMqGf2ExAGdIXvjMDxwAAAQk"]
[Wed Jul 29 13:04:18.152479 2026] [:error] [pid 32190:tid 139879040124672] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/autoload_classmap.php"] [unique_id "amneMqGf2ExAGdIXvjMDxwAAAQk"]
[Wed Jul 29 13:04:18.358696 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/back.php"] [unique_id "amneMqGf2ExAGdIXvjMDyAAAAQ8"]
[Wed Jul 29 13:04:18.359574 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/back.php"] [unique_id "amneMqGf2ExAGdIXvjMDyAAAAQ8"]
[Wed Jul 29 13:04:18.360298 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/back.php"] [unique_id "amneMqGf2ExAGdIXvjMDyAAAAQ8"]
[Wed Jul 29 13:04:18.360364 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/back.php"] [unique_id "amneMqGf2ExAGdIXvjMDyAAAAQ8"]
[Wed Jul 29 13:04:18.581305 2026] [:error] [pid 32190:tid 139879177004800] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/c/autoload_classmap.php"] [unique_id "amneMqGf2ExAGdIXvjMDygAAAQE"]
[Wed Jul 29 13:04:18.582039 2026] [:error] [pid 32190:tid 139879177004800] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/c/autoload_classmap.php"] [unique_id "amneMqGf2ExAGdIXvjMDygAAAQE"]
[Wed Jul 29 13:04:18.582572 2026] [:error] [pid 32190:tid 139879177004800] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/c/autoload_classmap.php"] [unique_id "amneMqGf2ExAGdIXvjMDygAAAQE"]
[Wed Jul 29 13:04:18.582607 2026] [:error] [pid 32190:tid 139879177004800] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/c/autoload_classmap.php"] [unique_id "amneMqGf2ExAGdIXvjMDygAAAQE"]
[Wed Jul 29 13:04:18.836736 2026] [:error] [pid 32190:tid 139879031731968] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/c/flower.php"] [unique_id "amneMqGf2ExAGdIXvjMDywAAAQo"]
[Wed Jul 29 13:04:18.837564 2026] [:error] [pid 32190:tid 139879031731968] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/c/flower.php"] [unique_id "amneMqGf2ExAGdIXvjMDywAAAQo"]
[Wed Jul 29 13:04:18.838255 2026] [:error] [pid 32190:tid 139879031731968] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/c/flower.php"] [unique_id "amneMqGf2ExAGdIXvjMDywAAAQo"]
[Wed Jul 29 13:04:18.838324 2026] [:error] [pid 32190:tid 139879031731968] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/c/flower.php"] [unique_id "amneMqGf2ExAGdIXvjMDywAAAQo"]
[Wed Jul 29 13:04:19.046170 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/c/xleet.php"] [unique_id "amneM6Gf2ExAGdIXvjMDzQAAARc"]
[Wed Jul 29 13:04:19.047183 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/c/xleet.php"] [unique_id "amneM6Gf2ExAGdIXvjMDzQAAARc"]
[Wed Jul 29 13:04:19.047978 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/c/xleet.php"] [unique_id "amneM6Gf2ExAGdIXvjMDzQAAARc"]
[Wed Jul 29 13:04:19.048035 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/c/xleet.php"] [unique_id "amneM6Gf2ExAGdIXvjMDzQAAARc"]
[Wed Jul 29 13:04:19.258794 2026] [:error] [pid 32190:tid 139878947804928] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/classwithtostring.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0AAAARQ"]
[Wed Jul 29 13:04:19.259708 2026] [:error] [pid 32190:tid 139878947804928] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/classwithtostring.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0AAAARQ"]
[Wed Jul 29 13:04:19.260376 2026] [:error] [pid 32190:tid 139878947804928] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/classwithtostring.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0AAAARQ"]
[Wed Jul 29 13:04:19.260416 2026] [:error] [pid 32190:tid 139878947804928] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/classwithtostring.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0AAAARQ"]
[Wed Jul 29 13:04:19.485633 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/content.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0QAAARE"]
[Wed Jul 29 13:04:19.486230 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/content.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0QAAARE"]
[Wed Jul 29 13:04:19.486729 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/content.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0QAAARE"]
[Wed Jul 29 13:04:19.486763 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/content.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0QAAARE"]
[Wed Jul 29 13:04:19.735069 2026] [:error] [pid 32190:tid 139879065302784] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/doc.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0gAAAQY"]
[Wed Jul 29 13:04:19.736026 2026] [:error] [pid 32190:tid 139879065302784] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/doc.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0gAAAQY"]
[Wed Jul 29 13:04:19.736710 2026] [:error] [pid 32190:tid 139879065302784] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/doc.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0gAAAQY"]
[Wed Jul 29 13:04:19.736748 2026] [:error] [pid 32190:tid 139879065302784] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/doc.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0gAAAQY"]
[Wed Jul 29 13:04:19.965488 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/dropdown.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0wAAAQs"]
[Wed Jul 29 13:04:19.966368 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/dropdown.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0wAAAQs"]
[Wed Jul 29 13:04:19.967126 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dropdown.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0wAAAQs"]
[Wed Jul 29 13:04:19.967185 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/dropdown.php"] [unique_id "amneM6Gf2ExAGdIXvjMD0wAAAQs"]
[Wed Jul 29 13:04:20.187826 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/ee.php"] [unique_id "amneNKGf2ExAGdIXvjMD1AAAAQU"]
[Wed Jul 29 13:04:20.188907 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/ee.php"] [unique_id "amneNKGf2ExAGdIXvjMD1AAAAQU"]
[Wed Jul 29 13:04:20.189773 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ee.php"] [unique_id "amneNKGf2ExAGdIXvjMD1AAAAQU"]
[Wed Jul 29 13:04:20.189836 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/ee.php"] [unique_id "amneNKGf2ExAGdIXvjMD1AAAAQU"]
[Wed Jul 29 13:04:20.400005 2026] [:error] [pid 32190:tid 139878939412224] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/flower.php"] [unique_id "amneNKGf2ExAGdIXvjMD1QAAARU"]
[Wed Jul 29 13:04:20.401124 2026] [:error] [pid 32190:tid 139878939412224] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/flower.php"] [unique_id "amneNKGf2ExAGdIXvjMD1QAAARU"]
[Wed Jul 29 13:04:20.401867 2026] [:error] [pid 32190:tid 139878939412224] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/flower.php"] [unique_id "amneNKGf2ExAGdIXvjMD1QAAARU"]
[Wed Jul 29 13:04:20.401945 2026] [:error] [pid 32190:tid 139878939412224] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/flower.php"] [unique_id "amneNKGf2ExAGdIXvjMD1QAAARU"]
[Wed Jul 29 13:04:20.665763 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/gecko-new.php"] [unique_id "amneNKGf2ExAGdIXvjMD2QAAAQ8"]
[Wed Jul 29 13:04:20.666595 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/gecko-new.php"] [unique_id "amneNKGf2ExAGdIXvjMD2QAAAQ8"]
[Wed Jul 29 13:04:20.667249 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gecko-new.php"] [unique_id "amneNKGf2ExAGdIXvjMD2QAAAQ8"]
[Wed Jul 29 13:04:20.667385 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/gecko-new.php"] [unique_id "amneNKGf2ExAGdIXvjMD2QAAAQ8"]
[Wed Jul 29 13:04:20.879713 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/m.php"] [unique_id "amneNKGf2ExAGdIXvjMD2gAAAQ0"]
[Wed Jul 29 13:04:20.880399 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/m.php"] [unique_id "amneNKGf2ExAGdIXvjMD2gAAAQ0"]
[Wed Jul 29 13:04:20.880998 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/m.php"] [unique_id "amneNKGf2ExAGdIXvjMD2gAAAQ0"]
[Wed Jul 29 13:04:20.881049 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/m.php"] [unique_id "amneNKGf2ExAGdIXvjMD2gAAAQ0"]
[Wed Jul 29 13:04:21.086066 2026] [:error] [pid 32190:tid 139879185397504] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amneNaGf2ExAGdIXvjMD2wAAAQA"]
[Wed Jul 29 13:04:21.087006 2026] [:error] [pid 32190:tid 139879185397504] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amneNaGf2ExAGdIXvjMD2wAAAQA"]
[Wed Jul 29 13:04:21.087766 2026] [:error] [pid 32190:tid 139879185397504] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amneNaGf2ExAGdIXvjMD2wAAAQA"]
[Wed Jul 29 13:04:21.087822 2026] [:error] [pid 32190:tid 139879185397504] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amneNaGf2ExAGdIXvjMD2wAAAQA"]
[Wed Jul 29 13:04:21.295395 2026] [:error] [pid 32190:tid 139879177004800] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mah/flower.php"] [unique_id "amneNaGf2ExAGdIXvjMD3AAAAQE"]
[Wed Jul 29 13:04:21.295991 2026] [:error] [pid 32190:tid 139879177004800] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mah/flower.php"] [unique_id "amneNaGf2ExAGdIXvjMD3AAAAQE"]
[Wed Jul 29 13:04:21.296502 2026] [:error] [pid 32190:tid 139879177004800] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mah/flower.php"] [unique_id "amneNaGf2ExAGdIXvjMD3AAAAQE"]
[Wed Jul 29 13:04:21.296575 2026] [:error] [pid 32190:tid 139879177004800] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mah/flower.php"] [unique_id "amneNaGf2ExAGdIXvjMD3AAAAQE"]
[Wed Jul 29 13:04:21.535032 2026] [:error] [pid 32190:tid 139879014946560] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mah/xleet.php"] [unique_id "amneNaGf2ExAGdIXvjMD3QAAAQw"]
[Wed Jul 29 13:04:21.535964 2026] [:error] [pid 32190:tid 139879014946560] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mah/xleet.php"] [unique_id "amneNaGf2ExAGdIXvjMD3QAAAQw"]
[Wed Jul 29 13:04:21.536677 2026] [:error] [pid 32190:tid 139879014946560] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mah/xleet.php"] [unique_id "amneNaGf2ExAGdIXvjMD3QAAAQw"]
[Wed Jul 29 13:04:21.536734 2026] [:error] [pid 32190:tid 139879014946560] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mah/xleet.php"] [unique_id "amneNaGf2ExAGdIXvjMD3QAAAQw"]
[Wed Jul 29 13:04:21.745250 2026] [:error] [pid 32190:tid 139878998161152] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/mini.php"] [unique_id "amneNaGf2ExAGdIXvjMD3gAAAQ4"]
[Wed Jul 29 13:04:21.746212 2026] [:error] [pid 32190:tid 139878998161152] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/mini.php"] [unique_id "amneNaGf2ExAGdIXvjMD3gAAAQ4"]
[Wed Jul 29 13:04:21.748040 2026] [:error] [pid 32190:tid 139878998161152] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mini.php"] [unique_id "amneNaGf2ExAGdIXvjMD3gAAAQ4"]
[Wed Jul 29 13:04:21.748114 2026] [:error] [pid 32190:tid 139878998161152] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/mini.php"] [unique_id "amneNaGf2ExAGdIXvjMD3gAAAQ4"]
[Wed Jul 29 13:04:21.962633 2026] [:error] [pid 32190:tid 139879098873600] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/moon.php"] [unique_id "amneNaGf2ExAGdIXvjMD4AAAAQI"]
[Wed Jul 29 13:04:21.963438 2026] [:error] [pid 32190:tid 139879098873600] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/moon.php"] [unique_id "amneNaGf2ExAGdIXvjMD4AAAAQI"]
[Wed Jul 29 13:04:21.963999 2026] [:error] [pid 32190:tid 139879098873600] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/moon.php"] [unique_id "amneNaGf2ExAGdIXvjMD4AAAAQI"]
[Wed Jul 29 13:04:21.964034 2026] [:error] [pid 32190:tid 139879098873600] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/moon.php"] [unique_id "amneNaGf2ExAGdIXvjMD4AAAAQI"]
[Wed Jul 29 13:04:22.177286 2026] [:error] [pid 32190:tid 139879082088192] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/new.php"] [unique_id "amneNqGf2ExAGdIXvjMD4gAAAQQ"]
[Wed Jul 29 13:04:22.178378 2026] [:error] [pid 32190:tid 139879082088192] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/new.php"] [unique_id "amneNqGf2ExAGdIXvjMD4gAAAQQ"]
[Wed Jul 29 13:04:22.179166 2026] [:error] [pid 32190:tid 139879082088192] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/new.php"] [unique_id "amneNqGf2ExAGdIXvjMD4gAAAQQ"]
[Wed Jul 29 13:04:22.179246 2026] [:error] [pid 32190:tid 139879082088192] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/new.php"] [unique_id "amneNqGf2ExAGdIXvjMD4gAAAQQ"]
[Wed Jul 29 13:04:22.442613 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/radio.php"] [unique_id "amneNqGf2ExAGdIXvjMD4wAAARc"]
[Wed Jul 29 13:04:22.443436 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/radio.php"] [unique_id "amneNqGf2ExAGdIXvjMD4wAAARc"]
[Wed Jul 29 13:04:22.444065 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/radio.php"] [unique_id "amneNqGf2ExAGdIXvjMD4wAAARc"]
[Wed Jul 29 13:04:22.444105 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/radio.php"] [unique_id "amneNqGf2ExAGdIXvjMD4wAAARc"]
[Wed Jul 29 13:04:22.652306 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/s.php"] [unique_id "amneNqGf2ExAGdIXvjMD5QAAARE"]
[Wed Jul 29 13:04:22.653169 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/s.php"] [unique_id "amneNqGf2ExAGdIXvjMD5QAAARE"]
[Wed Jul 29 13:04:22.654343 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/s.php"] [unique_id "amneNqGf2ExAGdIXvjMD5QAAARE"]
[Wed Jul 29 13:04:22.654392 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/s.php"] [unique_id "amneNqGf2ExAGdIXvjMD5QAAARE"]
[Wed Jul 29 13:04:22.867666 2026] [:error] [pid 32190:tid 139879065302784] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/sim.php"] [unique_id "amneNqGf2ExAGdIXvjMD5gAAAQY"]
[Wed Jul 29 13:04:22.868681 2026] [:error] [pid 32190:tid 139879065302784] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/sim.php"] [unique_id "amneNqGf2ExAGdIXvjMD5gAAAQY"]
[Wed Jul 29 13:04:22.869372 2026] [:error] [pid 32190:tid 139879065302784] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sim.php"] [unique_id "amneNqGf2ExAGdIXvjMD5gAAAQY"]
[Wed Jul 29 13:04:22.869425 2026] [:error] [pid 32190:tid 139879065302784] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/sim.php"] [unique_id "amneNqGf2ExAGdIXvjMD5gAAAQY"]
[Wed Jul 29 13:04:23.087609 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/text.php"] [unique_id "amneN6Gf2ExAGdIXvjMD5wAAAQs"]
[Wed Jul 29 13:04:23.088531 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/text.php"] [unique_id "amneN6Gf2ExAGdIXvjMD5wAAAQs"]
[Wed Jul 29 13:04:23.089223 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/text.php"] [unique_id "amneN6Gf2ExAGdIXvjMD5wAAAQs"]
[Wed Jul 29 13:04:23.089313 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/text.php"] [unique_id "amneN6Gf2ExAGdIXvjMD5wAAAQs"]
[Wed Jul 29 13:04:23.296049 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/user.php"] [unique_id "amneN6Gf2ExAGdIXvjMD6AAAAQU"]
[Wed Jul 29 13:04:23.377060 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/user.php"] [unique_id "amneN6Gf2ExAGdIXvjMD6AAAAQU"]
[Wed Jul 29 13:04:23.377670 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/user.php"] [unique_id "amneN6Gf2ExAGdIXvjMD6AAAAQU"]
[Wed Jul 29 13:04:23.377708 2026] [:error] [pid 32190:tid 139879073695488] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/user.php"] [unique_id "amneN6Gf2ExAGdIXvjMD6AAAAQU"]
[Wed Jul 29 13:04:23.594650 2026] [:error] [pid 32190:tid 139878956197632] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/webadmin.php"] [unique_id "amneN6Gf2ExAGdIXvjMD6QAAARM"]
[Wed Jul 29 13:04:23.595505 2026] [:error] [pid 32190:tid 139878956197632] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/webadmin.php"] [unique_id "amneN6Gf2ExAGdIXvjMD6QAAARM"]
[Wed Jul 29 13:04:23.596178 2026] [:error] [pid 32190:tid 139878956197632] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/webadmin.php"] [unique_id "amneN6Gf2ExAGdIXvjMD6QAAARM"]
[Wed Jul 29 13:04:23.596234 2026] [:error] [pid 32190:tid 139878956197632] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/webadmin.php"] [unique_id "amneN6Gf2ExAGdIXvjMD6QAAARM"]
[Wed Jul 29 13:04:23.891617 2026] [:error] [pid 32190:tid 139878964590336] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amneN6Gf2ExAGdIXvjMD6gAAARI"]
[Wed Jul 29 13:04:23.892547 2026] [:error] [pid 32190:tid 139878964590336] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amneN6Gf2ExAGdIXvjMD6gAAARI"]
[Wed Jul 29 13:04:23.893329 2026] [:error] [pid 32190:tid 139878964590336] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amneN6Gf2ExAGdIXvjMD6gAAARI"]
[Wed Jul 29 13:04:23.893386 2026] [:error] [pid 32190:tid 139878964590336] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amneN6Gf2ExAGdIXvjMD6gAAARI"]
[Wed Jul 29 13:04:24.136359 2026] [:error] [pid 32190:tid 139878939412224] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amneOKGf2ExAGdIXvjMD6wAAARU"]
[Wed Jul 29 13:04:24.137259 2026] [:error] [pid 32190:tid 139878939412224] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amneOKGf2ExAGdIXvjMD6wAAARU"]
[Wed Jul 29 13:04:24.137974 2026] [:error] [pid 32190:tid 139878939412224] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amneOKGf2ExAGdIXvjMD6wAAARU"]
[Wed Jul 29 13:04:24.138024 2026] [:error] [pid 32190:tid 139878939412224] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amneOKGf2ExAGdIXvjMD6wAAARU"]
[Wed Jul 29 13:04:24.343612 2026] [:error] [pid 32190:tid 139879090480896] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amneOKGf2ExAGdIXvjMD7AAAAQM"]
[Wed Jul 29 13:04:24.344694 2026] [:error] [pid 32190:tid 139879090480896] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amneOKGf2ExAGdIXvjMD7AAAAQM"]
[Wed Jul 29 13:04:24.346857 2026] [:error] [pid 32190:tid 139879090480896] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amneOKGf2ExAGdIXvjMD7AAAAQM"]
[Wed Jul 29 13:04:24.346945 2026] [:error] [pid 32190:tid 139879090480896] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amneOKGf2ExAGdIXvjMD7AAAAQM"]
[Wed Jul 29 13:04:24.576738 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amneOKGf2ExAGdIXvjMD7QAAAQ8"]
[Wed Jul 29 13:04:24.577681 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amneOKGf2ExAGdIXvjMD7QAAAQ8"]
[Wed Jul 29 13:04:24.578390 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amneOKGf2ExAGdIXvjMD7QAAAQ8"]
[Wed Jul 29 13:04:24.578442 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amneOKGf2ExAGdIXvjMD7QAAAQ8"]
[Wed Jul 29 13:04:24.790771 2026] [:error] [pid 32190:tid 139879185397504] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amneOKGf2ExAGdIXvjMD7gAAAQA"]
[Wed Jul 29 13:04:24.791539 2026] [:error] [pid 32190:tid 139879185397504] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amneOKGf2ExAGdIXvjMD7gAAAQA"]
[Wed Jul 29 13:04:24.792212 2026] [:error] [pid 32190:tid 139879185397504] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amneOKGf2ExAGdIXvjMD7gAAAQA"]
[Wed Jul 29 13:04:24.792262 2026] [:error] [pid 32190:tid 139879185397504] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amneOKGf2ExAGdIXvjMD7gAAAQA"]
[Wed Jul 29 13:04:25.035485 2026] [:error] [pid 32190:tid 139879014946560] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amneOaGf2ExAGdIXvjMD7wAAAQw"]
[Wed Jul 29 13:04:25.036259 2026] [:error] [pid 32190:tid 139879014946560] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amneOaGf2ExAGdIXvjMD7wAAAQw"]
[Wed Jul 29 13:04:25.036949 2026] [:error] [pid 32190:tid 139879014946560] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amneOaGf2ExAGdIXvjMD7wAAAQw"]
[Wed Jul 29 13:04:25.037010 2026] [:error] [pid 32190:tid 139879014946560] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amneOaGf2ExAGdIXvjMD7wAAAQw"]
[Wed Jul 29 13:04:25.245347 2026] [:error] [pid 32190:tid 139878931019520] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amneOaGf2ExAGdIXvjMD8QAAARY"]
[Wed Jul 29 13:04:25.246090 2026] [:error] [pid 32190:tid 139878931019520] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amneOaGf2ExAGdIXvjMD8QAAARY"]
[Wed Jul 29 13:04:25.246709 2026] [:error] [pid 32190:tid 139878931019520] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amneOaGf2ExAGdIXvjMD8QAAARY"]
[Wed Jul 29 13:04:25.246759 2026] [:error] [pid 32190:tid 139878931019520] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amneOaGf2ExAGdIXvjMD8QAAARY"]
[Wed Jul 29 13:04:25.452754 2026] [:error] [pid 32190:tid 139879098873600] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amneOaGf2ExAGdIXvjMD9AAAAQI"]
[Wed Jul 29 13:04:25.453590 2026] [:error] [pid 32190:tid 139879098873600] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amneOaGf2ExAGdIXvjMD9AAAAQI"]
[Wed Jul 29 13:04:25.454154 2026] [:error] [pid 32190:tid 139879098873600] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amneOaGf2ExAGdIXvjMD9AAAAQI"]
[Wed Jul 29 13:04:25.454189 2026] [:error] [pid 32190:tid 139879098873600] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amneOaGf2ExAGdIXvjMD9AAAAQI"]
[Wed Jul 29 13:04:25.658796 2026] [:error] [pid 32190:tid 139879082088192] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amneOaGf2ExAGdIXvjMD9QAAAQQ"]
[Wed Jul 29 13:04:25.659509 2026] [:error] [pid 32190:tid 139879082088192] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amneOaGf2ExAGdIXvjMD9QAAAQQ"]
[Wed Jul 29 13:04:25.660135 2026] [:error] [pid 32190:tid 139879082088192] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amneOaGf2ExAGdIXvjMD9QAAAQQ"]
[Wed Jul 29 13:04:25.660179 2026] [:error] [pid 32190:tid 139879082088192] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amneOaGf2ExAGdIXvjMD9QAAAQQ"]
[Wed Jul 29 13:04:25.865572 2026] [:error] [pid 32190:tid 139879040124672] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amneOaGf2ExAGdIXvjMD9gAAAQk"]
[Wed Jul 29 13:04:25.866315 2026] [:error] [pid 32190:tid 139879040124672] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amneOaGf2ExAGdIXvjMD9gAAAQk"]
[Wed Jul 29 13:04:25.866813 2026] [:error] [pid 32190:tid 139879040124672] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amneOaGf2ExAGdIXvjMD9gAAAQk"]
[Wed Jul 29 13:04:25.866851 2026] [:error] [pid 32190:tid 139879040124672] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amneOaGf2ExAGdIXvjMD9gAAAQk"]
[Wed Jul 29 13:04:26.071325 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/flower.php"] [unique_id "amneOqGf2ExAGdIXvjMD9wAAARc"]
[Wed Jul 29 13:04:26.071936 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/flower.php"] [unique_id "amneOqGf2ExAGdIXvjMD9wAAARc"]
[Wed Jul 29 13:04:26.072440 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/flower.php"] [unique_id "amneOqGf2ExAGdIXvjMD9wAAARc"]
[Wed Jul 29 13:04:26.072486 2026] [:error] [pid 32190:tid 139878922626816] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/flower.php"] [unique_id "amneOqGf2ExAGdIXvjMD9wAAARc"]
[Wed Jul 29 13:04:26.278606 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amneOqGf2ExAGdIXvjMD-AAAARE"]
[Wed Jul 29 13:04:26.279525 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amneOqGf2ExAGdIXvjMD-AAAARE"]
[Wed Jul 29 13:04:26.280260 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amneOqGf2ExAGdIXvjMD-AAAARE"]
[Wed Jul 29 13:04:26.280347 2026] [:error] [pid 32190:tid 139878972983040] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amneOqGf2ExAGdIXvjMD-AAAARE"]
[Wed Jul 29 13:04:26.485217 2026] [:error] [pid 32190:tid 139879065302784] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amneOqGf2ExAGdIXvjMD-QAAAQY"]
[Wed Jul 29 13:04:26.486107 2026] [:error] [pid 32190:tid 139879065302784] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amneOqGf2ExAGdIXvjMD-QAAAQY"]
[Wed Jul 29 13:04:26.486842 2026] [:error] [pid 32190:tid 139879065302784] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amneOqGf2ExAGdIXvjMD-QAAAQY"]
[Wed Jul 29 13:04:26.487715 2026] [:error] [pid 32190:tid 139879065302784] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amneOqGf2ExAGdIXvjMD-QAAAQY"]
[Wed Jul 29 13:04:26.695795 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amneOqGf2ExAGdIXvjMD-gAAAQs"]
[Wed Jul 29 13:04:26.696748 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amneOqGf2ExAGdIXvjMD-gAAAQs"]
[Wed Jul 29 13:04:26.697504 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amneOqGf2ExAGdIXvjMD-gAAAQs"]
[Wed Jul 29 13:04:26.697579 2026] [:error] [pid 32190:tid 139879023339264] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amneOqGf2ExAGdIXvjMD-gAAAQs"]
[Wed Jul 29 13:04:26.987861 2026] [:error] [pid 32190:tid 139878939412224] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amneOqGf2ExAGdIXvjMD_QAAARU"]
[Wed Jul 29 13:04:26.988851 2026] [:error] [pid 32190:tid 139878939412224] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amneOqGf2ExAGdIXvjMD_QAAARU"]
[Wed Jul 29 13:04:26.989635 2026] [:error] [pid 32190:tid 139878939412224] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amneOqGf2ExAGdIXvjMD_QAAARU"]
[Wed Jul 29 13:04:26.989689 2026] [:error] [pid 32190:tid 139878939412224] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amneOqGf2ExAGdIXvjMD_QAAARU"]
[Wed Jul 29 13:04:27.235702 2026] [:error] [pid 32190:tid 139879048517376] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amneO6Gf2ExAGdIXvjMD_gAAAQg"]
[Wed Jul 29 13:04:27.236634 2026] [:error] [pid 32190:tid 139879048517376] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amneO6Gf2ExAGdIXvjMD_gAAAQg"]
[Wed Jul 29 13:04:27.237300 2026] [:error] [pid 32190:tid 139879048517376] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amneO6Gf2ExAGdIXvjMD_gAAAQg"]
[Wed Jul 29 13:04:27.237397 2026] [:error] [pid 32190:tid 139879048517376] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amneO6Gf2ExAGdIXvjMD_gAAAQg"]
[Wed Jul 29 13:04:27.458952 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amneO6Gf2ExAGdIXvjMEAAAAAQ8"]
[Wed Jul 29 13:04:27.459951 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amneO6Gf2ExAGdIXvjMEAAAAAQ8"]
[Wed Jul 29 13:04:27.460632 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amneO6Gf2ExAGdIXvjMEAAAAAQ8"]
[Wed Jul 29 13:04:27.460670 2026] [:error] [pid 32190:tid 139878989768448] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amneO6Gf2ExAGdIXvjMEAAAAAQ8"]
[Wed Jul 29 13:04:27.674595 2026] [:error] [pid 32190:tid 139879031731968] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amneO6Gf2ExAGdIXvjMEAQAAAQo"]
[Wed Jul 29 13:04:27.675236 2026] [:error] [pid 32190:tid 139879031731968] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amneO6Gf2ExAGdIXvjMEAQAAAQo"]
[Wed Jul 29 13:04:27.675888 2026] [:error] [pid 32190:tid 139879031731968] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amneO6Gf2ExAGdIXvjMEAQAAAQo"]
[Wed Jul 29 13:04:27.675940 2026] [:error] [pid 32190:tid 139879031731968] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amneO6Gf2ExAGdIXvjMEAQAAAQo"]
[Wed Jul 29 13:04:27.886324 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amneO6Gf2ExAGdIXvjMEAgAAAQ0"]
[Wed Jul 29 13:04:27.886957 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amneO6Gf2ExAGdIXvjMEAgAAAQ0"]
[Wed Jul 29 13:04:27.887427 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amneO6Gf2ExAGdIXvjMEAgAAAQ0"]
[Wed Jul 29 13:04:27.887459 2026] [:error] [pid 32190:tid 139879006553856] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amneO6Gf2ExAGdIXvjMEAgAAAQ0"]
[Wed Jul 29 13:04:28.103877 2026] [:error] [pid 32190:tid 139879185397504] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amnePKGf2ExAGdIXvjMEAwAAAQA"]
[Wed Jul 29 13:04:28.104768 2026] [:error] [pid 32190:tid 139879185397504] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amnePKGf2ExAGdIXvjMEAwAAAQA"]
[Wed Jul 29 13:04:28.105515 2026] [:error] [pid 32190:tid 139879185397504] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amnePKGf2ExAGdIXvjMEAwAAAQA"]
[Wed Jul 29 13:04:28.105592 2026] [:error] [pid 32190:tid 139879185397504] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amnePKGf2ExAGdIXvjMEAwAAAQA"]
[Wed Jul 29 13:04:28.345907 2026] [:error] [pid 32190:tid 139879014946560] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/xleet.php"] [unique_id "amnePKGf2ExAGdIXvjMEBAAAAQw"]
[Wed Jul 29 13:04:28.346821 2026] [:error] [pid 32190:tid 139879014946560] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/xleet.php"] [unique_id "amnePKGf2ExAGdIXvjMEBAAAAQw"]
[Wed Jul 29 13:04:28.347539 2026] [:error] [pid 32190:tid 139879014946560] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/xleet.php"] [unique_id "amnePKGf2ExAGdIXvjMEBAAAAQw"]
[Wed Jul 29 13:04:28.347637 2026] [:error] [pid 32190:tid 139879014946560] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-admin/xleet.php"] [unique_id "amnePKGf2ExAGdIXvjMEBAAAAQw"]
[Wed Jul 29 13:04:28.555437 2026] [:error] [pid 32190:tid 139879098873600] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_http_versions}" against "REQUEST_PROTOCOL" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1010"] [id "920430"] [msg "HTTP protocol version is not allowed by policy"] [data "HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "sbf-consultancy.com"] [uri "/wp-config-sample.php"] [unique_id "amnePKGf2ExAGdIXvjMEBgAAAQI"]
[Wed Jul 29 13:04:28.556479 2026] [:error] [pid 32190:tid 139879098873600] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "43"] [id "911100"] [msg "Method is not allowed by policy"] [data "GET"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "sbf-consultancy.com"] [uri "/wp-config-sample.php"] [unique_id "amnePKGf2ExAGdIXvjMEBgAAAQI"]
[Wed Jul 29 13:04:28.557302 2026] [:error] [pid 32190:tid 139879098873600] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 1 byte(s) in REQUEST_HEADERS:Sec-CH-UA-Mobile outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:Sec-CH-UA-Mobile=?0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-config-sample.php"] [unique_id "amnePKGf2ExAGdIXvjMEBgAAAQI"]
[Wed Jul 29 13:04:28.557360 2026] [:error] [pid 32190:tid 139879098873600] [client 104.23.254.19:11057] [client 104.23.254.19] ModSecurity: Warning. Found 2 byte(s) in REQUEST_HEADERS:CF-Visitor outside range: 32,34,38,42-59,61,65-90,95,97-122. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1522"] [id "920274"] [msg "Invalid character in request headers (outside of very strict set)"] [data "REQUEST_HEADERS:CF-Visitor={\\x22scheme\\x22:\\x22https\\x22}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "paranoia-level/4"] [hostname "sbf-consultancy.com"] [uri "/wp-config-sample.php"] [unique_id "amnePKGf2ExAGdIXvjMEBgAAAQI"]